Cybersecurity

How to Spot and Stop Phishing Attacks At Your Business

A practical COMNEXIA guide to How to Spot and Stop Phishing Attacks At Your Business: what it means for your business, how it works, and the steps to get it right.

By COMNEXIA
#Cybersecurity#Automotive#Dealership IT

Phishing remains one of the most common entry points for successful cyberattacks, and the emails landing in your inbox today are far more convincing than the obvious “Nigerian prince” scams of a decade ago. Here is how to recognize them, block them, and build a response process before one gets through.

Red Flags You Can Spot Without Any Tools

Train every person in your organization to look for these specific signals before clicking a link or downloading an attachment.

Lookalike and typosquatted domains. Attackers register domains like cornexia.com, comnexla.com, or support-microsoft.com and send email from them. The display name in your inbox might read “Microsoft Support,” but the actual sending address tells the real story. Always expand the sender field and read the full email address, not just the name.

Display-name spoofing. An email can show “Jane Smith, CFO” as the sender while the actual address is jane.smith@gmail-invoices.net. This is extremely common in business email compromise (BEC) and ACH-redirect fraud. If a request to change a vendor’s bank account arrives by email, that alone is a red flag regardless of how legitimate the sender looks.

Urgency and secrecy. Phrases like “wire this today before close,” “do not discuss with anyone else,” or “your account will be suspended in 24 hours” are pressure tactics designed to bypass your judgment. Legitimate vendors, banks, and internal departments do not require secrecy or demand same-day wire transfers without prior agreement.

Generic greetings and mismatched branding. “Dear Customer” instead of your name, logo images that look slightly off, and footer addresses that do not match the company’s real location are consistent indicators of phishing templates.

Unexpected attachments or credential prompts. A PDF that asks you to “click here to view” and then loads a Microsoft login page is not a PDF. It is a credential-harvesting page. Any login prompt that appears after opening a document or clicking an email link should be treated as suspicious.

Technical Controls That Stop Phishing Before It Reaches the Inbox

Individual awareness matters, but layered technical controls catch what humans miss.

  • SPF (Sender Policy Framework): A DNS record that specifies which mail servers are authorized to send email for your domain. Emails sent from unauthorized servers fail SPF checks.
  • DKIM (DomainKeys Identified Mail): Adds a cryptographic signature to outgoing messages so receiving servers can verify the email has not been tampered with in transit.
  • DMARC (Domain-based Message Authentication, Reporting, and Conformance): Builds on SPF and DKIM to tell receiving mail servers what to do with messages that fail authentication: quarantine them or reject them outright. A DMARC policy at p=reject is the strongest setting and prevents spoofed emails using your domain from reaching anyone.
  • Email filtering with sandboxing: Enterprise email security platforms (such as Microsoft Defender for Office 365 or Proofpoint) detonate suspicious attachments in an isolated environment before they reach users.
  • MFA/2FA on every account: Multi-factor authentication means a stolen password alone is not enough for an attacker to log in. Enable MFA on email, VPN, accounting platforms, and any system that handles customer data or financial transactions.
  • EDR/MDR on endpoints: Endpoint detection and response tools monitor for malicious behavior after a user does click something, catching malware execution and lateral movement before it spreads.

A Real-World Example: Phishing at Auto Dealerships

Auto dealerships are a consistent target because they process large transactions daily, handle financing paperwork, and have staff across sales, F&I, and service who all use email. A common attack involves a spoofed email appearing to come from a bank or floorplan lender, asking the controller to update ACH routing information. The amounts involved can reach hundreds of thousands of dollars.

The defense is a written policy requiring any ACH or wire change request to be verified by a phone call to a number pulled from your existing records, not from the email itself. Pair that with DMARC enforcement on your domain and security awareness training that includes this exact scenario, and you close the gap significantly.

How to Report and Respond When You Suspect Phishing

  1. Do not click any links or download attachments.
  2. Do not reply to the email or call any number listed in the message.
  3. Forward the email as an attachment (not inline) to your IT team or MSP so they can examine headers without risk.
  4. Report it using your email platform’s built-in phishing report button (available in Outlook and Gmail) so the provider can update filters.
  5. If you believe credentials were already entered on a suspicious page, change that password immediately and notify IT so they can check for unauthorized access.
  6. If money moved, contact your bank’s fraud line within hours. Many banks can recall wires initiated the same day.

Security Awareness Training Is Not Optional

One-time training does not stick. Effective programs run simulated phishing campaigns on a monthly or quarterly basis, track who clicks, and follow up with targeted education for those users. This is not about punishing employees. It is about building muscle memory so the right instinct kicks in under pressure.

Get Help from COMNEXIA

COMNEXIA has spent 35 years helping businesses in the Atlanta area and beyond lock down their IT environments against exactly these threats. Our cybersecurity services include email authentication setup, security awareness training, and MDR, and our managed IT services keep your entire environment monitored and patched. Call us at (877) 600-6550 or contact us to talk through where your current defenses stand.

Need Expert Technology Guidance?

Don't navigate complex technology decisions alone. Our consulting team provides the strategic guidance you need to make informed technology investments.