"I Noticed a Few Bugs on Your Website": How to Spot Scam and Phishing Emails
If you run a business with a website, chances are this email has landed in your inbox. Here's how to recognise it, along with the other scam emails targeting UK small businesses every day.

"Hi, I was looking at your website and noticed a few bugs. Would you like me to send over the details?"
Sound familiar? This is one of the most widely circulated cold email templates in the world, sent to thousands of business owners every day. We see it regularly, and so do our clients. Sometimes it's a pushy sales tactic for overpriced web design or SEO services. Sometimes it's the opening move of something more dangerous.
Either way, there's one detail that gives it away every time: they never tell you what the bugs are. Someone who had genuinely found a problem with your website would simply tell you. The vagueness is deliberate. It's the hook designed to get you to reply.
Why Small Businesses Receive So Many of These
Scam and nuisance emails are a numbers game. Criminals and aggressive marketers harvest email addresses from websites, business directories and previous data breaches, then send the same template to enormous lists. They don't need many replies to make it worthwhile.
According to the UK Government's Cyber Security Breaches Survey, phishing remains by far the most common form of attack, experienced by 85% of businesses that reported a breach. The most frequent variations we see landing in small business inboxes include:
- "I noticed bugs / errors / issues on your website"
- "Your website isn't ranking on Google, we can fix that"
- "Your invoice is attached" (from a company you've never dealt with)
- "Your Microsoft 365 password is about to expire, click here"
- "Your domain name is due for renewal" (from the wrong registrar)
- "We tried to deliver your parcel" with a link to reschedule
- A "voicemail" or "e-fax" attachment that is really malware
- An urgent request from "the director" to buy vouchers or make a payment
The Warning Signs to Look For
You don't need to be technical to spot most scam emails. A quick check against these warning signs catches the vast majority:
- 1Vague claims with no specifics: real feedback names the actual problem
- 2A sense of urgency or pressure: "act now", "final notice", "account will be suspended"
- 3A sender address that doesn't match the company name when you look closely
- 4Generic greetings such as "Dear Sir/Madam" or just your email address
- 5Unexpected attachments or links, especially ones asking you to log in
- 6Requests to move the conversation to WhatsApp or a personal email address
- 7Poor spelling and odd phrasing, though AI has made many scams read perfectly, so good English is no longer proof of legitimacy
The golden rule: if an email asks you to click, download, pay or reply urgently, slow down. Legitimate organisations will never punish you for taking five minutes to verify.
What to Do When One Arrives
- Don't reply: even a polite "no thanks" confirms your address is live and invites more
- Don't click links or open attachments
- Report it: in Outlook, use the "Report phishing" button, which also helps train Microsoft's filters for everyone
- Delete it and move on
- If you're unsure whether something is genuine, contact the organisation directly using details from their official website, never the contact details in the email itself
- If you've already clicked or replied, change your password, enable Multi-Factor Authentication and tell your IT provider straight away, as speed matters
Suspicious emails can also be forwarded to the National Cyber Security Centre's Suspicious Email Reporting Service at report@phishing.gov.uk. The NCSC has removed millions of scam web pages as a result of these reports.
When "Annoying" Becomes Dangerous
Most of these emails are simply a nuisance. The danger is that the same techniques (a plausible pretext, a little pressure, a link or attachment) are exactly how serious attacks begin. Business Email Compromise, where a criminal quietly takes over a mailbox and later diverts a genuine payment, almost always starts with a single successful phishing email.
And it only takes one. A business can delete a hundred scam emails correctly, but if the hundred-and-first catches a busy member of staff on a bad day, the consequences can include stolen funds, exposed client data, downtime and lasting damage to trust.
Your Staff Are Your First Line of Defence, But They Shouldn't Be Your Only One
Knowing the warning signs helps enormously, but relying on every member of staff to get it right every time is not a strategy. Modern protection layers several defences so that a single mistake doesn't become a crisis:
Advanced Email Filtering
The best scam email is the one that never reaches the inbox. Advanced filtering blocks known scams, spoofed senders and malicious links before staff ever see them.
Multi-Factor Authentication (MFA)
If someone does hand over a password, MFA makes it far harder for the criminal to actually get in.
Security Awareness Training
Regular, practical training, including simulated phishing tests, keeps the warning signs fresh and turns staff from a weakness into an asset.
Endpoint Protection and Monitoring
If a malicious attachment does get opened, monitored devices mean the incident is spotted and contained quickly rather than discovered weeks later.
How Konnetix Helps
This layered approach is exactly what Complete 365 delivers. It combines Microsoft 365, advanced email security, cyber protection, staff awareness training, device management and support into a single managed service, so businesses can:
- Stop the vast majority of scam and phishing emails before they reach staff
- Prevent account takeover even when a password is compromised
- Train staff to recognise and report suspicious emails with confidence
- Detect and contain incidents quickly if something does get through
- Meet GDPR and cyber security obligations
- Get straight answers from a dedicated team when something looks suspicious
And if you're ever unsure about an email, our clients simply forward it to us and ask. A thirty-second check is always cheaper than a cleanup.
The Next One Is Already on Its Way
Scam emails aren't going to stop. If anything, AI is making them more convincing and easier to send at scale. The question every business should ask is simple: if the next convincing scam email lands on your busiest employee's worst day, what's standing between that click and your bank account?
If the answer is "not much", it may be time to put proper protection in place.
Discover Complete 365
Complete 365 is Konnetix's fully managed Microsoft 365 solution combining email security, staff training, device protection and expert support in one service. Get in touch today to arrange a consultation.
Book a Free Security Review