How a Phishing Email Actually Takes Down a Small Business
The email that works is not the one full of spelling mistakes. It is the one that arrives about a job you are already worried about.
The phishing email that works is not the one full of spelling mistakes. It is the one that arrives about a job you are already worried about.
Here is the sequence, in the order it happens.
Step 1: the message fits the day
An email arrives about a delayed shipment. It carries the courier's logo, correct branding, and clean writing. Your business is waiting on a delivery, so nothing about it seems strange.
Attackers do not need to know your business. Shipping problems, invoice queries, and password expiry notices are common enough to land somewhere every time.
Step 2: it creates a deadline
The message says the shipment is held and needs confirmation today.
Urgency is the actual weapon. It removes the pause in which somebody would normally check.
Step 3: an employee helps a customer
A staff member clicks, because a customer is waiting. The page is an exact copy of the courier's login screen. They enter the account details.
Nothing appears wrong. Often the page then forwards to the real site, so the visit looks like a glitch.
Step 4: the damage is not where you look
By the time customers report unauthorised charges and the real account locks you out, the credentials are already in use. If that password is reused anywhere else, and it usually is, the attacker moves through the other accounts within the hour.
What stops it
Two-factor authentication. The stolen password stops being enough. This single control defeats most of these attacks outright.
A password manager. It fills logins only on the exact address it saved. On a copied page it stays silent, and that silence is the warning your eyes will miss.
One rule for your team. Never sign in through a link in an email. Open the site yourself, from a bookmark. Say it that plainly, because a rule with exceptions will get exceptions.
Permission to slow down. Staff click because they are trying to be helpful. Tell them clearly that checking with you costs the business nothing, and that no customer is lost by a fifteen minute delay.
Write the response plan now
If it happens: change the password on that account and on every account sharing it, from a different device. Turn on two-factor. Call the bank. Tell the service provider. Tell anyone whose information was exposed.
Decide these steps while nothing is on fire. They are impossible to think through at the time.
I run this training for small teams and set up the controls behind it. Email jon@delcaromedia.com.
