How to Spot Phishing Emails Targeting Trades Businesses
Fake invoices, supplier impersonation, and urgent payment requests are hitting trades businesses harder than ever. Here's exactly how to recognize a phishing email before it costs you.
Why Trades Businesses Are Prime Targets
HVAC companies, plumbers, electricians, and roofers are being targeted by phishing scammers at an increasing rate. The reason is simple: trades businesses often have multiple suppliers, process many invoices, and have owners who are too busy on job sites to carefully vet every email. Scammers exploit exactly this.
Phishing attacks against small trades businesses have increased by over 60% in the past two years. The average loss per incident is over $8,000. Understanding how these attacks work is the first line of defense.
The 5 Most Common Phishing Attacks on Trades Businesses
- Fake supplier invoices: An email that looks like it's from your regular parts supplier, asking you to pay an invoice to a new bank account. The email address is slightly wrong — for example, hvac-supplies.net instead of hvac-supplies.com.
- Urgent payment requests: Emails claiming you owe money for a past order and threatening service suspension if you don't pay within 24 hours. The urgency is designed to make you act before thinking.
- Google Business impersonation: Emails claiming your Google Business listing will be suspended unless you click a link and verify your account. Google never sends these.
- New customer deposit scams: A "customer" emails requesting a large job and asks to pay by cheque — then sends an overpayment and asks you to refund the difference before the cheque clears.
- Software renewal scams: Fake renewal notices for QuickBooks, antivirus, or other software you use, with a link to renew via a fake payment page.
How to Spot a Phishing Email
Look for these red flags in every email:
- The sender's email address doesn't match the company name. Always check the full email address, not just the display name. "John from Home Depot" can be sent from any email.
- Urgency and pressure. Legitimate suppliers and partners don't demand payment within hours or threaten account suspension without warning.
- A request to change bank details. If a supplier emails asking you to send future payments to a new account, call them directly on a number you already have — never on a number from the email.
- Spelling and grammar errors. Not always present in modern phishing emails, but still a common sign.
- Links that don't match the company domain. Hover over any link before clicking. If the URL doesn't match the company's official website, do not click it.
What to Do If You Receive a Suspicious Email
Do not click any links or download attachments. If the email claims to be from a supplier you use, call them directly using a phone number from your records — not a number in the email. Forward the email to your IT contact or cybersecurity provider. Delete the original.
If you believe you have already fallen victim to a phishing attack, contact your bank immediately, change your email password, and report the incident to the FTC at reportfraud.ftc.gov (USA) or the Canadian Anti-Fraud Centre.
Protecting Your Business Going Forward
Use a business email address with two-factor authentication enabled. Educate any office staff on these red flags. Set up a policy that any change to payment details must be confirmed by a phone call. Consider a cybersecurity awareness training session for your team annually.
TBS Tech Services builds websites and digital systems for any business. If you have questions about securing your online presence, contact us for a free consultation.