On this page
The most convincing phishing emails don’t come from a stranger. They come from a brand you already trust and do business with — your email provider, your bank, your domain registrar, your cloud host. When the logo looks right and the message references a service you actually use, your guard drops. That’s exactly what the attacker is counting on.
According to the FBI’s 2024 Internet Crime Report, phishing was the single most-reported type of cybercrime that year. Reported losses across all cybercrime reached a record $16.6 billion, with business email compromise alone accounting for $2.77 billion. For a small business in Northern Ontario, you don’t need to be the target of a sophisticated nation-state operation to get hurt. One convincing email and one rushed click is enough.
A Real-World Example
Vendor impersonation is so common that some providers now publish their own catalogues of it. Hetzner, a major European cloud and hosting company, maintains a public collection of phishing emails sent in their name — fake “renew your service,” “accept the new policy,” and “your account will be locked” messages designed to harvest logins and credit card details.
We point to it because it’s a clear, honest look at how these scams are built — and because the same playbook gets used against the services your business relies on every day, especially Microsoft 365. The brand on the email changes; the tactics don’t.
The Red Flags
Whether the email claims to be from a hosting company, Microsoft, or your bank, the warning signs are the same:
- Manufactured urgency. Subject lines engineered to make you act before you think: “Last reminder: accept the new policy,” “Urgent: renew now or your account will be locked,” “Your contract ends soon.” Legitimate vendors rarely threaten you on a countdown.
- A sender that’s almost right. The display name might say the company’s name perfectly — but the actual email address doesn’t match the real domain, or uses a lookalike (an extra letter, a
.netinstead of.com, a subtle misspelling). Always check the real address, not just the friendly name. - Links to a login page that looks real. The link text and the landing page can be near-perfect copies of the genuine sign-in screen. The moment you type your username, password, or card number, it’s captured. Hover over links (don’t click) to see where they actually go.
- Requests for credentials or payment details that a real provider would never make over email.
What To Do If One Lands in Your Inbox
- Don’t click anything. Don’t open attachments, don’t follow links. If you’re unsure whether a message is real, go to the service directly by typing its known web address into your browser — never through the email’s links.
- Verify out-of-band. If “your account” supposedly has a problem, log in the normal way you always do, or contact the vendor through a number or address you already have on file — not the contact details in the suspicious email.
- Delete it once you’ve confirmed it’s fake.
If You’ve Already Entered Your Details
Move fast — the window between a stolen password and a misused one is short.
- Change that password immediately on the real site, and change it anywhere else you reused it.
- Turn on multi-factor authentication (MFA). Even if an attacker has your password, MFA is the single most effective barrier standing between them and your account. Every account that supports it should have it on.
- Tell your IT team. Early notice means we can check for unauthorized logins, force a sign-out of active sessions, and watch for follow-on activity before it becomes a breach.
How We Help Our Clients Stay Ahead of This
For the businesses we manage across Thunder Bay and Northern Ontario, this isn’t something we leave to individual judgment on a busy Monday morning. DVG Systems builds the safety net in:
- MFA enforced across Microsoft 365 and critical accounts, so a stolen password isn’t enough on its own.
- Advanced email filtering and identity threat detection that catches and blocks malicious campaigns — often before a single one of our clients sees the email.
- Ongoing security-awareness training so your team can recognize these lures, because technology and trained people together are far stronger than either alone.
- A real person to call when something looks off — no countdown, no guessing.
Phishing works by exploiting trust and time pressure. The fix is the opposite: slow down, verify, and have the right protections already in place. For Ontario businesses, getting this right is also increasingly tied to cyber-insurance eligibility and client trust.
Not sure whether your business is covered against email-based attacks? Start with a free security assessment and we’ll show you exactly where the gaps are — or reach us directly at solutions@dvgsystems.com.