The pattern is consistent enough to teach. Urgency, so you act quickly. An authority you would not question, such as your bank, a supplier, or a platform you use. And a single requested action, which is almost always clicking a link, opening an attachment, or changing where money goes. Any message combining those three deserves a pause regardless of how legitimate it looks.

Two variants specifically target small businesses. An invoice arrives from a real supplier with updated bank details, and the payment goes to an attacker. And a message appearing to come from the owner asks somebody to buy gift cards or make an urgent transfer, usually while the owner is known to be travelling. Both work because they exploit normal business behaviour rather than a technical weakness.

The defence that works is a rule rather than vigilance. Any change to payment details is verified by calling the supplier on a number you already had, never a number in the message. Any unexpected payment request is confirmed by voice, however awkward that feels. Those two rules stop nearly all of the financially damaging cases.

Beyond that, two factor authentication limits the damage when somebody does enter a password on a fake page, and a hardware key prevents it entirely because it checks the domain before responding. Tell anybody who works with you that reporting a mistake immediately is expected and will not be met with blame, because the cost of somebody hiding a click for a day is far higher than the click.

Knowing what to do after somebody clicks matters more than the prevention, because prevention eventually fails and the damage depends almost entirely on the first hour. If credentials were entered, change that password immediately and then check whether the account has been altered rather than assuming the reset ended it. Attackers commonly add a forwarding rule or a recovery address so they retain access after the password changes, and that rule survives the reset and quietly copies every message afterward. Check forwarding, filters, recovery details, and any connected applications, then sign out all sessions.

If money moved, speed determines whether any of it returns. Contact your bank immediately rather than waiting to establish what happened, because a transfer can sometimes be recalled within hours and almost never after a day. Report it to the authorities as well, since some recovery mechanisms require a report to exist. Then work out how it happened, because a fraudulent payment instruction usually means either a mailbox was being read or a supplier was compromised, and both mean the next request will look equally convincing. Treating a single incident as resolved without answering that question is how businesses get hit twice.