Insights · Offices
How to spot phishing emails before they cost you
Why it matters
Most break-ins at small businesses don't start with clever hacking. They start with someone clicking a link or typing a password into a fake page. The good news: a few habits stop most of it.
Common tricks to watch for
- Fake invoices from a vendor you know, with a link or attachment you weren't expecting.
- "Your password expires today" emails that lead to a look-alike login page.
- Payment-change requests — "we have new bank details, please update."
- Urgent requests from the boss asking for gift cards or a quick wire transfer.
Simple habits that work
- Check the sender's actual email address, not just the name.
- Never change payment details based on an email alone — call the person using a number you already have.
- Turn on two-step sign-in for email and banking.
- If something feels off, forward it to whoever handles your IT before clicking.
Clicked something already?
Don't panic and don't hide it. Change the password you entered, and call your IT provider right away. Fast reporting turns most incidents into a non-event.
How we help
Managed clients get email filtering, two-step sign-in set up, and a person to ask. Learn more on our Offices page or check current scams in the Threat Center.
Quick answers
What should I do if I clicked a phishing link?
Change the password you entered, turn on two-step sign-in, and contact your IT provider right away.
Does Solstice Technology offer email security in Alaska?
Yes. Solstice Technology provides managed email and endpoint security for businesses in Anchorage and statewide.