Common phishing email mistakes and fixes

Business IT — By Gethyn Jones

We spot the typical phishing pitfalls in small businesses and give you quick fixes to stay safe.

What is the biggest mistake people make with phishing emails? We assume they’re harmless because they look official. We see this a lot: an email with a familiar logo, a polite greeting and a link that looks like it belongs to a bank or a supplier. The instinct is to click, thinking it’s just another routine request. The reality is that most of these messages are crafted to look authentic and the moment you click, you may hand over credentials or install malware. How to stop treating every email like a safe delivery? Fix: Treat every unsolicited request for information or login details as suspicious until proven otherwise. Hover over every link, check the real URL, and compare the sender address with previous legitimate communications. Mistake: Relying on the email subject line alone to gauge safety. We’ve heard customers say, “The subject looked normal, so I opened it.” Spam filters can’t always catch cleverly worded subjects, and the subject alone gives no security clues. Fix: Open emails in the preview pane or use the “Mark as unread” trick until you verify the sender. If the subject mentions urgency – “Your account will be closed” – that’s a classic red flag. Mistake: Using the same password for work and personal accounts. When a phishing email steals your work credentials, it often leads to a cascade of breaches because the same password is reused on personal services. Fix: Adopt a unique, strong password for every account and store them in a reputable password manager. O

For expert IT support, contact CefniTech — friendly, local IT support for homes and businesses across the UK.