Most cyber attacks on nurseries and small businesses do not start with someone breaking through a firewall. They start with a message that tricks a person into clicking, typing a password or sending money. That is phishing, and it is the most common way organisations like yours get compromised. The good news is that it can be beaten, once your team knows what to look for and what to do when something slips through.
Why nurseries get targeted
Phishing emails are sent out in huge numbers to see who bites, and nurseries bite more often than they should. That is not because staff are careless. It is because of how the working day runs.
- Staff are busy and constantly interrupted. Email gets checked on a phone between nappy changes and snack time, which is exactly when a quick, unthinking click happens.
- Fake messages are easy to believe. Nurseries deal with supplier invoices, parent messages and requests from managers all day, so one more invoice or one more urgent request does not stand out.
- There is rarely anyone to ask. Most settings have no IT person on site to check a suspicious message with, so people make the call on their own.
The same is true of most small businesses. If your team works on the move and handles money and personal data, you are a target.
The giveaways
Email filtering catches a lot. We use Proofpoint for this, and it stops most of the obvious rubbish before it reaches anyone. Some messages will always get through, so these are the signs your team should check for.
- The address behind the name. The display name can say anything, including your manager's name or your bank's. Tap or hover over the sender to see the real email address. If it does not match who it claims to be, stop.
- Urgency and threats. "Your account will be closed today." "Pay now or we take action." Pressure is there to make you act before you think.
- A link that is not what it says. Hover over a link on a computer, or press and hold it on a phone, to see where it really goes. If the destination looks wrong, do not click.
- A surprise login page. If you click a link in an email and are asked to sign in, treat that as a major warning sign. Close it and go to the site yourself, by typing the address or using a bookmark.
- Details that are slightly off. A blurry logo, odd wording, "Dear Customer" instead of your name, or a tone that does not sound like the person it claims to be from.
- The unexpected attachment. An invoice you were not expecting, a delivery note for something you did not order, or a document that asks you to "enable content". These are common ways to deliver malware.
The two that hit nurseries hardest
The fake supplier
An email arrives that looks like it is from a supplier you really use. It says their bank details have changed and asks you to pay the next invoice to the new account. Sometimes it comes from the supplier's genuine email account, because that has been hacked.
Our rule: never change payment details because of an email. Phone the supplier on a number you already hold, not one in the message, and confirm the change with someone you know.
The boss who is not the boss
A message appears to come from the owner or manager. It is urgent, they are "in a meeting" and they need you to buy gift cards, make a transfer or send over staff details right now.
Our rule: any request for money, gift cards or personal data gets confirmed by voice or in person before anyone acts on it. A good manager will never mind being checked.
AI has made this harder
The old advice was to look for bad spelling and clumsy English. That no longer works. Attackers now use AI to write fluent, polished emails in perfect English, tailored to your sector and sometimes to you by name.
Voice is no longer proof either. AI voice cloning means a phone call that sounds exactly like someone you know may not be them.
So we focus on the checks that still hold up:
- Look at the real sender address, not the display name.
- Check where a link actually goes before clicking.
- Treat any login page reached from an email link with suspicion.
- Confirm any request for money or data through a separate channel you already trust, such as a number you already have.
Stronger sign-ins help too. With two-factor authentication on Microsoft 365, a stolen password alone is not enough to get into an account. Passkeys go further, because there is no password for a fake page to steal in the first place.
What to do when one lands
If nobody clicked
Do not reply, click or forward it to colleagues to "have a look". Report it instead, so others are warned and the sender can be dealt with.
- In Microsoft 365, use the built-in Report button in Outlook to report it as phishing. Ask your IT provider to make sure it is switched on and that staff know where it is. If we look after your Microsoft 365, we can set this up for you.
- Forward it to report@phishing.gov.uk. This is the National Cyber Security Centre's Suspicious Email Reporting Service. The NCSC can investigate and take down scam websites and email addresses.
- Scam texts go to 7726. Forwarding a suspicious text to 7726 is free on most UK networks and reports it to your mobile provider.
Then delete it.
If someone clicked or entered a password
Act quickly. Minutes matter.
- Change the password straight away, and anywhere else that password was used.
- Tell whoever looks after your IT, so they can check the account, sign out other sessions and look for anything that has been changed, such as new email forwarding rules.
- Keep an eye on the account for unusual activity over the following days.
- If money was sent or bank details were entered, phone your bank immediately.
Our guide on what to do if you've been hacked walks through the next steps in more detail.
Make it safe to own up
This is the part that makes the biggest difference. If staff are worried about getting into trouble, they will keep quiet, and silence is what turns one click into a crisis. Make it clear that reporting a mistake quickly will be met with thanks, not blame. A fast report means a password change and a quiet afternoon. A hidden one can mean weeks of clear-up.
The one thing to take away
Phishing works by catching busy people off guard, and you can no longer rely on the wording to give it away. Stick to the checks that still work: look at the real sender address, distrust any login page you reached from a link, and confirm any request for money or data through a separate channel you already trust. Most of all, make sure every member of your team knows that reporting a click quickly will be thanked, never blamed.
If you would like help training your team or a second opinion on a suspicious message, our cyber security page explains how we can help, and our jargon buster covers any of the terms above.