
A stranger could access many of your team's logins in under two minutes with one email to the right inbox on an ordinary afternoon. I didn't have a real number until a fake HubSpot support message showed up in mine, dressed up well enough that I almost didn't read past the subject line before clicking through. Phishing survives because it's built to look exactly like the ninety other tool notifications already sitting in a marketing inbox, and marketing ops, drowning in vendor emails and integration alerts, might be the easiest department in the building to catch off guard. Password hygiene sounds like something you fix once and move on from, right up until a domain name off by a single character nearly proves you wrong.
The Phishing Email That Almost Got Me
Back in 2022 I was buried in a CRM cleanup, chasing duplicate contact records, when the email landed. The subject line referenced a security check on our HubSpot account, the logo was correct, the button was the right shade of orange, and the urgency was pitched just high enough to short-circuit the part of my brain that usually asks questions. Before I clicked the blue Confirm Account button, habit made me hover over it first, more out of boredom than caution, and the status bar at the bottom of my browser showed a domain that didn't quite match: hubsp0t.com, with a zero standing in for the o. My stomach dropped somewhere around my shoes.
That near miss stuck with me for weeks. It wasn't just my own account on the line, it was roughly 142 marketing logins spread across the department, most of them living in a shared spreadsheet nobody had bothered to lock down. A single zero, one pixel off from a lowercase o, was the only thing standing between a stranger and our entire lead database.
The scare is also the reason I still keep a dedicated laptop just for trying vault apps, wiped clean between rounds of testing so nothing carries over from one trial to the next. When the drive needed clearing before this year's round of testing, I spent an evening figuring out how to find lost software product keys on a test laptop so I could reinstall everything from scratch instead of buying a new one.
This is the part people get wrong about phishing, treating it like a spelling problem. It isn't. What's called typosquatting works because certain characters are nearly identical at normal font sizes, a zero for an o, a lowercase L for a capital I, an rn that reads as an m if you're scrolling fast on a phone. Scammers register these lookalike domains cheaply, sometimes years in advance, and let them sit dormant until a campaign is ready to run. The email itself can sail past every spam filter a company owns, because the sending server is technically legitimate, it's just not the company you think it is. Checking the visible sender name tells you nothing anymore. The only thing that matters is the actual domain string, character by character, which is exactly the kind of tedious checking most of us stopped doing around the time we started trusting our inboxes to sort themselves out. If you want the fuller picture, typosquatting has its own history that goes back well before phishing emails existed, mostly as a way to catch traffic from people who mistype a URL directly into a browser.

The Shared Inbox Fix That Backfired
Our first fix after the scare was almost worse than the problem. IT's compromise was routing every password reset and account-recovery email through a shared marketing@company.com inbox, the idea being that a second set of eyes would catch anything fake before someone panicked and clicked. For a while it looked like progress. Then a contractor who'd already rolled off a project still had access to that inbox, a reset link for one of our ad platforms sat unread because everyone assumed someone else was handling it, and I realized we'd built a bigger single point of failure than the one we started with. A shared inbox is not a security control, it's a waiting room with the door propped open. Whatever visibility it bought us wasn't worth what it cost in accountability, and once I could show that plainly, nobody argued to keep it.

Six Vaults, One Card, and a Lot of Cancellation Emails
Determined not to feel that particular kind of dread again, I spent months trying nearly every consumer vault on the market, paying for each one on my own card so I could see exactly how billing and cancellation actually worked, not just how the marketing page described them. LastPass was my breaking point early on: I wanted to like it because half my network still used it, but the interface felt cluttered in a way that made simple tasks take longer than they should, and their track record with past incidents made me uneasy every time I typed my master password in. That password, by the way, is the one credential doing all the real work, since a vault built on zero-knowledge encryption means the company itself never sees it, which also means there's no support line that can reset it for you if you forget it. I started treating mine less like a password and more like a sentence I'd actually remember, long, a little strange, and nothing close to anything I'd used before.
Somewhere in that testing stretch I also got serious about two-factor authentication and passkeys across every account that offered them, not just the vault itself, because a strong master password guarding a login with no second factor is still a login one leaked credential away from trouble. Breach monitoring turned out to be the feature I underestimated most, the kind of alert that quietly flags a reused password against a known leak before you ever hear about the breach on the news. And when it came to sharing logins with the rest of my team, I learned fast that shared-vault permissions, where you control exactly who sees which folder, are a different animal entirely from a spreadsheet tab everyone can edit.
Why Did Logging Into a New Laptop Take Ninety Seconds Flat?
I found out at a company offsite in Denver, unboxing a brand-new work laptop in a hotel conference room with spotty WiFi and half the marketing team waiting on me to pull up a shared deck. I signed into the vault, and every credential I needed, roughly 140 logins, synced into place in about ninety seconds flat. No spreadsheet to hunt through, no IT ticket, no calling someone back at the office to ask which folder held the ad account passwords. That's vault portability doing the quiet, unglamorous work nobody thinks about until they're stranded with a dead laptop and a deadline.
By the fourth week of running everything through that setup, reaching for a password without opening the vault first started to feel backwards, like dialing a number I used to know by heart. I've also started toggling travel mode before conferences since then, which temporarily hides vaults I don't need on the road, mostly because a lost or inspected laptop shouldn't double as a backstage pass to every account I own.
My Manager Didn't Want a Feature List, She Wanted a Renewal Date
Getting the department switched over wasn't just an IT conversation, it went through my manager, Soledad Whitaker, who approved the budget. She didn't want a breakdown of encryption standards or a pros-and-cons chart, she wanted the per-seat cost and the exact renewal date circled on a calendar, because that's the lens she runs every tool through. After a couple of rounds of back-and-forth, she agreed to fund half the team plan out of the ops budget, which as far as I know was the first time a password manager showed up as its own line item in that department's spreadsheet rather than getting buried under software, miscellaneous. IT still rolled their eyes at what they call my security audits, and I've made peace with being the person who nags about login hygiene in the breakroom. Getting budget approved took patience more than persuasion, and it helped enormously to walk in with renewal dates already lined up instead of asking Soledad to care about features she was never going to compare herself.
A Reader in Phoenix Wrote In With Her Own Near-Miss
Not long after I started writing about all this, an account manager named Cressida Fowler emailed me a genuinely long note about her own phishing scare, the kind of email that clearly took her a while to write. Her company had mandated RoboForm company-wide, a choice she disagreed with, and she'd gone looking for other opinions when she found her way here. What stuck with me most was how little she trusted browser-native password storage after a syncing incident had exposed saved logins on a device she didn't expect them to show up on. That's the trade-off nobody explains upfront: a browser's built-in save-password feature is convenient exactly because it lives everywhere you're logged in, which is also why it's a weaker boundary than a dedicated vault built for exactly one job. Cressida still reads every post, and she's part of the reason I now assume at least one reader has already lived through the thing I'm describing before I finish writing about it.
So What Do You Actually Check Before You Click?
In practice, a few habits do almost all the work. If a vault stays quiet on a login page it usually recognizes instantly, that silence is the signal, not a glitch to dismiss and click past anyway. Urgency is the next tell: real companies give you weeks of increasingly annoying banners and reminder emails before locking anything down, so a message demanding action within the hour deserves more suspicion, not less. Hovering over a button before clicking, the way I wish I'd done automatically back in 2022, shows the real destination in the browser's status bar, and if that string of characters doesn't match the brand exactly, letter for letter, the email goes straight to trash. And if an email asks you to re-verify security settings through an embedded link, close it and type the site's address in yourself instead.
None of that matters much, though, if your own personal information is easy to find in the first place, which is part of why I started using Incogni to remove my personal data from data broker sites, since a phishing email aimed at someone whose employer, phone number, and job title are all public record is going to be far more convincing than one blasted out blind. I also make sure everyone on the team knows how to set up a 1Password emergency kit, so a lost device or a forgotten master password doesn't turn into its own multi-day crisis.

The One Habit That Actually Stuck
If I had to boil every trial subscription and one very bad afternoon down to a single rule, it's this: treat your vault's silence as information, not an inconvenience. Every other check, the urgency audits, the hovering, the careful reading of a sender's domain, still depends on you being alert enough to remember to do it at the end of a long day. A vault that simply declines to fill in a login it usually knows doesn't get tired, doesn't skim, and doesn't have ninety other tabs open. None of this is exotic security tips territory, just noticing when something that should happen automatically doesn't, and stopping right there instead of clicking through out of habit. I still get the occasional phishing attempt dressed up better than the one that almost got me, cleaner design, copy that reads like it was written by an actual person on a real support team, but the habit that survived every vault I've cycled through isn't cleverness. It's just refusing to be the tired eyes a scammer is counting on.