When people picture a cyberattack, they picture someone breaking into a server. What actually happens to small businesses is much more boring: an email arrives, it looks like it came from someone you know, and somebody pays it.
This is called business email compromise, and it costs small businesses more money every year than website hacking does. It's also one of the easier problems to shut down, because the fixes are procedural rather than technical.
How the Scam Actually Runs
The pattern is consistent enough that once you've seen it you can spot it:
- They get into one mailbox. Usually through a reused password from an unrelated breach, or a fake login page. No malware, no technical exploit.
- They read quietly for a few weeks. They learn who pays the bills, which vendors you use, how your bookkeeper phrases things, when you're traveling.
- They wait for a real invoice. Then they send a follow-up from a lookalike address saying the bank details have changed.
- You pay the new account. Wire transfers are effectively final. By the time the real vendor asks where their money is, it's gone.
The variant that hits smallest businesses is simpler: an email that appears to be from the owner, sent to whoever handles money, asking urgently for a payment or gift cards while the owner is "in a meeting."
The Four Things That Actually Stop It
1. Multi-factor authentication on email, first
If you do one thing from this article, do this one. MFA means a stolen password alone is useless. Turn it on for every email account in the business, not just yours. The bookkeeper's mailbox is the valuable one.
Use an authenticator app rather than SMS codes where you have the choice. SIM swapping is real, though for most small businesses SMS is still enormously better than nothing.
2. A password manager, and no reuse
The initial break-in almost always traces back to a password reused somewhere that got breached. A password manager makes unique passwords the path of least resistance instead of a discipline problem. The business plans run a few dollars per user per month, which is cheap next to a single fraudulent wire.
3. A verbal rule for money
This is the one that stops the loss even when everything else fails. Write it down and tell your staff:
Any change to payment details, and any payment request over a set amount, gets confirmed by phone using a number we already have on file. Never a number from the email.
No exceptions for urgency. Urgency is the tell, not the reason to skip the step.
4. Check the actual sending address
The display name is trivially faked. The address underneath is where the tell lives: a swapped letter, a .co instead of .com, or a completely different domain hiding behind a familiar name. Train whoever handles invoices to expand the sender before acting on anything involving money.
What to Do in the First Hour After a Click
If someone entered credentials into a fake page:
- Change that password immediately, and any account sharing it.
- Turn on MFA on that account now, if it wasn't already.
- Check mailbox rules. Attackers add a rule that auto-forwards or auto-deletes messages so you don't see the vendor asking questions. This step gets skipped constantly and it's how people get hit twice.
- Tell your bank if any payment went out. Fast reporting occasionally recovers a wire. Slow reporting never does.
- Tell your staff what happened. The same email usually went to several people.
If the compromise touched your website or its hosting account rather than just email, the sequence is different and I've written it out separately in what to do if your website gets hacked.
The Part You Cannot Buy
There's no product that fixes this. Spam filters catch a lot, and you should have one, but a lookalike domain sending a plausible message from a clean IP address is not going to get flagged reliably. The control that works is the phone call.
That's genuinely good news for a small business. You don't need an IT department to implement "we call to confirm bank changes." You need one rule and the discipline to keep it when someone sounds impatient.
The Bottom Line
Website security and email security are different problems. Locking down your site, which I've covered in the website security checklist, does nothing about a fraudulent invoice, and the invoice is the one more likely to cost you real money.
Turn on MFA everywhere this week. Get a password manager. Write down the phone-confirmation rule and tell your team it applies to you too, because the message asking them to skip it will claim to be from you.
Want a second opinion on how your business technology is set up? Get a free audit and I'll flag the gaps I see, including the ones that have nothing to do with your website.
Want help applying this to your business?
Get a free website audit and a personalized action plan. No pressure, no sales pitch.
Get a Free AuditKeep reading
Small Business IT Support: What You Actually Need (and What You Don't)
Jul 16, 2026 · 6 min read
IT & SecurityWhat to Do If Your Website Gets Hacked: A Step-by-Step Recovery Guide
Jun 26, 2026 · 7 min read
IT & SecuritySmall Business Website Security Checklist: 10 Things to Do Right Now
Jun 9, 2026 · 7 min read
