← Field notes

How a Phishing Email Actually Takes Down a Small Business

Jon DelcaroMarch 15, 20242 min read

The email that works is not the one full of spelling mistakes. It is the one that arrives about a job you are already worried about.

The phishing email that works is not the one full of spelling mistakes. It is the one that arrives about a job you are already worried about.

Here is the sequence, in the order it happens.

Step 1: the message fits the day

An email arrives about a delayed shipment. It carries the courier's logo, correct branding, and clean writing. Your business is waiting on a delivery, so nothing about it seems strange.

Attackers do not need to know your business. Shipping problems, invoice queries, and password expiry notices are common enough to land somewhere every time.

Step 2: it creates a deadline

The message says the shipment is held and needs confirmation today.

Urgency is the actual weapon. It removes the pause in which somebody would normally check.

Step 3: an employee helps a customer

A staff member clicks, because a customer is waiting. The page is an exact copy of the courier's login screen. They enter the account details.

Nothing appears wrong. Often the page then forwards to the real site, so the visit looks like a glitch.

Step 4: the damage is not where you look

By the time customers report unauthorised charges and the real account locks you out, the credentials are already in use. If that password is reused anywhere else, and it usually is, the attacker moves through the other accounts within the hour.

What stops it

Two-factor authentication. The stolen password stops being enough. This single control defeats most of these attacks outright.

A password manager. It fills logins only on the exact address it saved. On a copied page it stays silent, and that silence is the warning your eyes will miss.

One rule for your team. Never sign in through a link in an email. Open the site yourself, from a bookmark. Say it that plainly, because a rule with exceptions will get exceptions.

Permission to slow down. Staff click because they are trying to be helpful. Tell them clearly that checking with you costs the business nothing, and that no customer is lost by a fifteen minute delay.

Write the response plan now

If it happens: change the password on that account and on every account sharing it, from a different device. Turn on two-factor. Call the bank. Tell the service provider. Tell anyone whose information was exposed.

Decide these steps while nothing is on fire. They are impossible to think through at the time.

I run this training for small teams and set up the controls behind it. Email jon@delcaromedia.com.

Want this done properly on your site?

Ready to take your business to the next level with a custom digital solution?

Request a free consultation