Before you type a password or send a payment, you can check if a website is safe in about ten seconds, and you do not need anybody technical to do it. Read the address slowly, arrive at the site the way you normally would rather than through a link somebody sent you, and pay attention to what the page is asking for. Those three habits catch the large majority of fake pages.
The reason this matters more than it used to is simple. Copying a real company website is cheap and fast, and the copy is usually indistinguishable from the original by eye. The logo, the colors and the wording all come across intact, so anything you judge by appearance has already been handled by the person who built the fake.
What a fake page is usually trying to get
Most fake pages want one of three things. They want the password to your email or your bank, they want a payment sent to an account that is not your supplier account, or they want enough personal detail to open something in your name later.
That narrows the moments where this matters. A page that asks you to read an article deserves very little suspicion. A page that asks you to sign in, confirm bank details or approve a payment deserves ten seconds, every single time, including on the pages you use every week.
How to check if a website is safe in about ten seconds
- Read the address from the end of the name backwards. The real owner of the site is the part immediately before the .com, and immediately before the first single slash. In a fake address, the familiar name is usually pushed further left, where it looks right at a glance and means nothing.
- Look for the small changes. A letter doubled, a letter swapped for a number, a hyphen inserted, or the name of your state added at the end. Read it as carefully as you would read the amount on a check.
- Ask yourself how you arrived. A link in an email, a text message or a search advertisement is worth more suspicion than a bookmark you saved yourself.
- Type the address yourself when money or a password is involved. Typing it yourself defeats even a perfect copy, because a fake page sitting at the wrong address never gets loaded in the first place.
- Notice what the page asks for. A page that wants your password and also your card number and also your date of birth is asking for more than any of your suppliers needs.
What the padlock in the address bar actually tells you
The small padlock means the connection between your computer and the site is private, so nobody in between can read what you type. It says nothing at all about who owns the site or whether they are honest.
Criminals obtain that padlock for their fake pages the same way everybody else does, usually for free and in minutes. Treating the padlock as proof of legitimacy is one of the most common reasons careful people still get caught, and it is worth saying out loud to your team, because most of them were taught the opposite ten years ago.
The number that shows where this sits in the real world
Impersonation is the most reported category of internet crime in the United States. The FBI 2025 Internet Crime Report recorded 1,008,597 complaints in total, and phishing and spoofing accounted for roughly 191,500 of them, which is about two reports in every ten.
For an owner, the useful part is what that category actually contains: somebody pretending to be a business the victim already trusted. Your suppliers, your bank and your own company are the raw material, which is why the check belongs in the moments where you are least suspicious.
Read this number honestly
Those complaints come from anyone who chose to file, including individuals and retirees, so this is not a measurement of American companies. It also only counts the people who reported, and most fraud is never reported at all.
What transfers to your business is the ranking rather than the total. Out of everything reported to the FBI last year, being fooled by something that looked familiar came first, ahead of extortion and ahead of investment fraud.
If somebody already typed something in
Once information has been entered, the ten-second check is behind you and the clock starts. Change that password from a different device, and change it anywhere else the same password was used, because reuse across a bank, an email account and a supplier portal is common and normal in companies of every size.
Then tell your IT provider what was typed and at what time, including the guesses. People are embarrassed and tend to describe the page instead of the fields they filled in, and the fields are what determine whether this is an afternoon of caution or a phone call to the bank.
If a card number or a bank detail was involved, the bank comes first and everything else waits. Money reported within hours is often recoverable, and money reported at the end of the week rarely is.
Call the supplier on the number you already had
When bank details change, somebody in your company calls the supplier on the number you held before the request arrived. Not the number in the email, not the number on the new invoice, and not the number on the page you have just been sent to.
That habit stops the most expensive version of this problem, which rarely involves anyone typing a password. It involves a real invoice, a real supplier and a real relationship, with one line quietly altered. If your industry has rules about how you handle payment and client data, having that habit written down is also the sort of thing an auditor likes to see.
The same applies inside your own company. A request to change where the payroll goes, arriving by email from an employee address, deserves a phone call to a number you already had on file. These requests look ordinary because they are copied from ordinary ones.
The questions to ask your IT provider
- If somebody in my company types a password into a fake page, would either of us know about it?
- Do you block known fake sites before they load on our computers, and what happens when a brand-new one appears?
- Can you tell me whether a lookalike version of our own web address has been registered by somebody else?
- Who checks that our email filtering is still catching these, and how often is that reviewed?
- If a supplier bank detail changes tomorrow, what does your process expect us to do?
Checking a web address is a habit rather than a skill. Ten seconds before a password, ten seconds before a payment, and the same ten seconds on the site you have used a hundred times, because familiarity is exactly what the copy is built to borrow.
We are always glad to look at how your team handles these moments today. Our frequently asked questions cover the ones owners raise most.

