Phishing: How Small Firms Actually Get Caught — Herarx Blog

Phishing: How Small Firms Actually Get Caught

Small firms are caught by ordinary-looking emails, not dramatic hacks. The five scenarios that work, the signs worth teaching, and the habits that stop them.

May 14, 2024
Phishing: How Small Firms Actually Get Caught
Back to blog

Small firms rarely fall for the obvious phishing emails full of spelling mistakes. They get caught by messages that look exactly like normal work: a shared document, a supplier's updated bank details, a client asking for a quick favour. Attackers target small firms because they handle money and sensitive documents without a security team watching. Here is how it actually happens and what stops it.

The five scenarios that work

  1. The fake sign-in page. An email says a document has been shared or a mailbox is full, with a link to a page that looks like your email provider. You enter your password; the attacker now has your mailbox. This is the most common route in.
  2. Changed bank details. A supplier, contractor or client appears to write saying their bank details have changed. Sometimes the email really does come from their account, because their mailbox was compromised first. The next payment goes to the attacker.
  3. The urgent request from the boss. A message that seems to come from a senior colleague asks for an urgent payment, gift cards or a document, often while they are known to be travelling.
  4. The attachment that asks for permission. A document opens and asks you to enable content or install something to view it.
  5. The reply in an existing thread. Once a mailbox is compromised, attackers reply inside real conversations, so the message appears in a thread you trust.

What happens next

With access to one mailbox, an attacker reads correspondence to learn who pays whom and when, sets up rules to hide replies, and waits for the right moment to send a convincing request. Firms that use email as a filing system lose more, because years of documents sit in the compromised account; see the hidden cost of using email as a filing system.

Signs worth teaching

  • A request to change payment details, however ordinary it looks.
  • Urgency, secrecy, or pressure to skip a normal step.
  • A sign-in page reached from an email link rather than from your own bookmark.
  • A sender address that is close to, but not exactly, the usual one.
  • A tone that is slightly off for the person it claims to be from.

Habits that stop it

  • Verify payment changes by phone on a number you already have, never one in the email. Make this a rule with no exceptions, including for senior staff.
  • Two-factor authentication on every mailbox. A stolen password alone is then not enough. Authenticator apps and hardware keys resist phishing better than text codes.
  • Sign in from bookmarks, not links in emails.
  • Two people for payments above a threshold, or to new payees.
  • Check mailbox rules and forwarding regularly for anything you did not create.
  • Make reporting easy and blame-free. The person who says "I think I clicked something" within five minutes saves you; the one who is afraid to say it costs you.

If someone clicks

Change the password immediately, sign out all sessions, check for forwarding rules and connected apps, and warn anyone the account may have emailed. Record what happened, when, and what was accessed; you may need it for insurers, clients or regulators. Strong, unique passwords make recovery simpler, see password hygiene for small offices.