Who this is for: everyone. Five minutes of reading here prevents the most expensive kind of incident a small business has.
The short answer
Check the sender's actual address, not the display name. Hover over links before clicking. Be suspicious of urgency. And if a message asks you to move money or change payment details, verify it by phone using a number you already have — never a number in the email.
The four checks
1. The real sender address
Display names are free to fake. On a phone, tap the sender name to expand it; on a computer, hover over it. Look at the part after the @ symbol. Watch for:
- Lookalike domains: rnicrosoft.com, yourcompany-inc.com, outlook-support.net.
- A well-known brand sending from a free mailbox like gmail.com.
- A coworker's name attached to an address you don't recognize.
2. The real link
Hover over a link and read the address that appears in the corner of the window. On a phone, press and hold to preview. The visible text and the destination can be completely different. If the message wants you to sign in, don't use the link at all — open the site yourself from a bookmark.
3. The pressure
Phishing works by rushing you past your own judgment. "Your account will be closed today." "The wire has to go out before the bank cuts off." "I'm in a meeting, can you handle this quickly?" A legitimate request survives a delay. Any message insisting it can't is telling you something.
4. The ask
Be most careful when a message wants you to sign in, open an attachment you didn't expect, buy gift cards, change bank details on an invoice, or approve an MFA prompt. That last one matters: never approve a sign-in prompt you didn't personally trigger.
The one that costs the most
Business email compromise doesn't look like phishing. It's a normal-sounding email from a real vendor's real account, saying their banking details have changed and attaching an updated invoice. The account was compromised weeks earlier and the attacker has been reading the thread.
The only reliable defense is procedural: any change to payment details is verified by a phone call to a number you already had on file, before the payment goes out. Make that an office rule, not a judgment call.
What to do with a suspicious message
- Don't delete it. We need it to check whether anyone else received it.
- In Outlook, use Report → Report phishing. If that button isn't there, forward the message to us as an attachment (drag it into a new message) rather than forwarding normally, which strips the headers.
- Tell a coworker out loud. Phishing arrives in waves.
If someone already clicked
Speed matters far more than blame. Nobody at Middle Out is going to make you feel bad about it.
- Change the password on that account immediately, from a different device if you can.
- Contact Us. Say what was entered and roughly when.
- If banking or payment information was involved, call the bank now, in parallel.
- Don't wipe or "clean up" the computer first — that destroys what we need to see how far it went.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article