The email that's about to trick your bookkeeper

The email that's about to trick your bookkeeper

Five red flags that unmask almost every phishing scam. Forward this to whoever pays your invoices.


Hey there,

Welcome back. Last week we checked whether your doors were locked. This week we're talking about the con artist who knocks politely and asks you to open one.

It's called phishing, and it's not a technology problem, it's a trust problem. Somebody pretends to be your bank, your software, or your boss, and talks you into handing over a password, a payment, or a way into your computer. No firewall gets breached. You just get asked nicely, while you're busy, and you say yes.

Here's how to say no.


THIS WEEK: The five red flags

Nearly every phishing attempt trips at least one of these. Learn them once and you'll spot them for life:

  1. Urgency. "Within 24 hours." "Immediately." "Your account will be suspended." Real companies are almost never in that big a hurry. Panic is the whole scam. A panicked person doesn't stop to check.
  2. A sender address that's slightly wrong. The name says "Chase Bank." The actual email is some word salad at a domain Chase has never used. Tap or hover on the sender to see the real address.
  3. A link that wants your password. Real companies don't email you a link to go type your login into. When in doubt, don't click. Open the site yourself, the normal way.
  4. Money moving in a new way. New bank details for a vendor. A surprise wire. Gift cards (yes, still). Any change to how money moves gets a phone call first.
  5. Something that's just... off. A weird greeting, a tone that isn't quite the person. Scams are well-written now, so don't rely on typos, but do trust your gut.

The scam built specifically for businesses your size is called business email compromise: a fake email "from the owner" (that's you) telling whoever handles the money to send an urgent wire. It costs companies billions a year. Billions, with a B.


THE ONE RULE THAT BEATS IT

Make this sacred in your business: any request to move money or change bank details gets confirmed by phone, on a number you already have, not one from the email. And tell your team, out loud, that they will never be in trouble for double-checking something that looks like it came from you. The whole scam runs on people being too polite to question the boss.


TOOL OF THE WEEK

Your phone. Seriously. The single most powerful anti-phishing tool you own is a 30-second phone call to confirm anything involving money. No app required.


If someone at your shop already clicked something they shouldn't have: change that password now, turn on multi-factor authentication, and if money moved, call your bank today. They can sometimes claw back a wire if you move within hours. Then breathe. This happens to sharp people every single day.

Forward this to whoever pays your invoices. They're the number one target in your whole company, and they'll thank you.

Stay secure,
Savvy CISO