When you think of a cyberattack, you picture a hooded figure in a basement trying to break into a bank. The reality is much more boring — and much more effective.
The people running these scams don't target banks. They target businesses like yours: 10 people or fewer, no dedicated IT staff, one person juggling the books, the inbox, and the schedule. You're not a hard target. You're the perfect target.
Here are the three scams that actually get small businesses — and the fix for each.
Scam #1: The Fake Invoice (Business Email Compromise)
A vendor you actually work with emails you an invoice. It looks right. The amount looks right. The only difference is the bank account number on the payment instructions.
That's business email compromise (BEC). The attacker got into the vendor's email — or just guessed your relationship — and is quietly rerouting payments to their own account. It's one of the most common ways small businesses lose real money, and it often isn't caught until the real vendor asks why they haven't been paid.
The fix: Never pay an invoice on the email alone. If the payment details changed, or the amount is unusual, pick up the phone and call the number you have on file — not the number in the email. A 60-second phone call stops the single most expensive scam in small business.
Scam #2: The Email That Looks Like It's From You
An employee gets an email that appears to come from you: "I'm in a meeting, need you to buy $500 in gift cards for a client, here's the card number to send the codes to." Or a login page that looks exactly like your bank's — but it's not.
These are phishing attacks. They work because they don't try to be clever. They try to be urgent. Urgency is what makes people bypass their better judgment.
The fix: Turn on multi-factor authentication (MFA) everywhere — email, banking, payroll, anything that touches money or client data. MFA is the single highest-impact security change a small business can make, and it stops the vast majority of these attacks cold. Even if someone hands over their password, the attacker can't get in without the second factor. And make a simple rule: no money moves based on an email or text alone. Ever.
Scam #3: The "Free" Tool That Isn't Free
A pop-up says your computer is infected. A "tech support" agent calls and says there's a problem with your Microsoft license. A free PDF reader you downloaded is quietly logging your keystrokes.
Fake tech support and malicious downloads are how attackers get a foothold on your actual machine — not just your inbox. Once they're in, they can hold your files for ransom, watch your screen, or steal every password you type.
The fix: Real companies don't call you out of the blue about a problem you never reported. Hang up. Download software only from official sites. And keep an eye on the one thing that catches most of this: if your computer starts acting slow or doing things on its own, get it looked at before it becomes a bigger problem.
Why It's Always a Small Business
Large companies have security teams and insurance requirements. You have a business to run. Attackers know that — which is why they aim at you, not at the bank.
The good news: you don't need a security team to stop most of it. You need three habits — verify payment changes by phone, MFA on everything, and skepticism toward anything urgent or unsolicited. Those three habits stop the overwhelming majority of attacks that actually succeed.
Worried your business might already be exposed? Let's talk. I'll take a look at how your business handles email, payments, and passwords, show you exactly where the risk is, and fix it — before someone finds it for you. No jargon, no fear-mongering. Just the honest picture of where you stand.
Ben is the owner of Spruce IT, a technology support and advisory service for small businesses and individuals in the Harleysville, PA area.