What Is Phishing? How to Spot a Scam Before Your Business Pays for It

9/1/2026

What Is Phishing? How to Spot a Scam Before Your Business Pays for It

The invoice looks familiar. The payment instructions do not.

An email arrives from a supplier you work with every week. The invoice looks right, but there is one change: a new bank account for payment.

Do you pay it or pick up the phone?

That is the kind of decision behind the question, what is phishing? Phishing is a deceptive message designed to get someone to reveal information, open a harmful file, visit a fake website, or take another action that benefits a criminal.

For a Central Illinois business, it may look like an ordinary part of the workday. A delivery notice. A shared document. A message from the owner asking for a quick favor.

What is phishing, and what does it look like at work?

Phishing can arrive through email, text messages, or other communication tools. It often borrows a familiar name and adds a reason to act quickly.

Watch for messages that ask you to:

  • Sign in to keep an account from being closed.
  • Open an unexpected invoice or shared file.
  • Send payroll records or employee information.
  • Approve a login you did not initiate.
  • Change payment details or send money urgently.

Poor spelling can be a clue, but a polished message is not proof that it is legitimate. Use a known contact method to verify an unexpected request. The FTC explains phishing and other small-business threats.

A familiar email address is not enough

Some criminals use an address that looks almost right. Others gain access to a real email account and insert themselves into an existing conversation.

That second situation can support business email compromise, a scam that often aims to redirect money. Phishing may help an attacker gain access, but a fraudulent payment request does not always contain a suspicious link.

Consider this hypothetical example: A Bloomington business receives a vendor invoice during a busy afternoon. The sender requests payment to a different account. The employee calls the vendor using the number already in the accounting records and learns the change was not authorized.

The protection was a verification step built into the payment process. The FBI explains how business email compromise works.

Give employees a clear way to check

“Be careful” is not a complete procedure. Make the expected action specific:

  1. Verify payment changes independently. Call a trusted number already on file, not one supplied in the questionable message.
  2. Use a second approval for sensitive transactions. Decide which payments, account changes, and information requests need another person’s review.
  3. Open accounts directly. Use a saved bookmark or known website instead of a login link in an unexpected message.
  4. Make reporting easy. Give employees one clear place to send concerns and encourage quick reporting without blame.

Add multifactor authentication, or MFA, to important accounts. It adds a verification step beyond a password. Ask your IT provider about phishing-resistant options, and remind employees not to approve unexpected login prompts.

What if someone already clicked?

Tell IT or your security contact immediately and explain what happened: opening a link, entering a password, downloading a file, or approving a prompt require different responses. Do not assume that clicking always means a breach, or that nothing happened because the screen looks normal.

If money was sent, contact your bank immediately and report the incident to the FBI’s Internet Crime Complaint Center. Fast action may help recovery efforts, but recovery is not guaranteed.

Does cyber insurance cover phishing?

The word “phishing” alone does not determine coverage. The resulting loss matters.

A stolen password that leads to exposed customer records raises different coverage questions from a payment sent to a criminal. Fraudulent transfers may require social engineering coverage, funds transfer fraud coverage, or protection under a crime policy. Separate limits and verification requirements may apply. Travelers’ coverage materials illustrate these separate agreements.

Ask TROXELL to review how your policies address both data-related losses and stolen money. A practical question to start with: “If an employee follows fake payment instructions, what coverage would we have?”