(940) 536-3643
← Blog

How Business Impersonation Scams Actually Work

The Friday of 4th of July weekend, a local business owner called us in a panic. Someone was calling his own customers, using his office manager's real phone number on the caller ID, and telling them to send payments to a new bank account. At the same time, fake emails were going out from his own company address asking for the same thing.

He'd even paid for extra email security. It didn't stop any of it.

Below is what happened, why it worked, and the steps that would have prevented it.

This kind of attack is called Business Email Compromise, or BEC for short. It's one of the most expensive threats facing small businesses right now, and it usually plays out in stages.

Stage 1: Quiet entry

Someone got into a single company mailbox, most likely with a password stolen from a phishing email or a fake login page.

Stage 2: Covering their tracks

They created hidden rules inside the mailbox that quietly moved or deleted certain replies, so the owner stopped seeing responses and had no idea anything was wrong.

Stage 3: The payout attempt

Using the real, trusted email account, they messaged the company's customers with new banking details and asked them to send payments there.

Stage 4: Moving to the phone

They started calling customers directly, faking the caller ID so it showed a real employee's number, and repeated the same fake payment request out loud.

By the time anyone noticed, a customer had already called in, confused and upset, asking why the company wanted money sent to an account they didn't recognize.


Why it worked

A few gaps let this attack succeed. Every one of them is common, and every one is fixable with ongoing effort.

The extra email security wasn't account security

The owner had bought an email add-on and figured he was covered. That product was really just a spam filter. It checks incoming mail for junk, but it does nothing once someone logs in with a real, stolen password. Screening your mail and protecting your account are two different jobs, and he only had one of them handled.

There was no multi-factor authentication

Multi-factor authentication asks for a second confirmation, like a code or a tap on your phone, before anyone can log in. Without it, one stolen password is enough to get in. With it, that same password is almost useless on its own.

The domain wasn't set up to block spoofing

There are a few email settings, known as SPF, DKIM, and DMARC, that tell the rest of the internet which sources are actually allowed to send mail under your name. His weren't fully in place, so fraudulent messages had a much easier time looking real.

The email ran through a third-party reseller instead of directly with Microsoft

This one matters more than most owners realize. His business used Microsoft 365, but it was sold and managed through a domain reseller rather than set up directly. That put a middleman between him and the core security controls. When we went in to lock things down, some of the deeper admin tools we needed weren't available to us at all, because on that kind of plan the reseller holds that level of access.

Plenty of new business owners buy their email this way. It's convenient, it comes bundled with the domain, and nobody warns them about the trade-off. What they usually don't know is that there's a better option: a properly managed Microsoft 365 setup that gives you full control and full protection.


The warning signs to watch for

If any of these are happening, treat it as a red flag, not a glitch:

  • Email you're expecting never shows up, or messages disappear from your inbox.
  • Customers reply to conversations you don't remember starting.
  • A customer or vendor mentions a payment or banking change you never asked for.
  • You notice logins or security alerts from places you've never been.
  • People get strange emails or calls "from you" that you didn't send.

The part that caught everyone off guard was the phone calls. Caller ID can be faked. Anyone can make a call show a number they don't own, and it does not mean your phone was hacked. The attacker had pulled the employee's number and the customer list out of the mailbox, then spoofed the number using an outside service. There's no switch on your end that turns this off, which is exactly why the customer rule further down matters so much.


How to protect your business

Stopping an active attack is only half the job. Keeping the next one from landing takes a few protections working together.

  • Multi-factor authentication (MFA) — Keeps a stolen password from turning into a stolen account. This is the one to do first.
  • Unique passwords and a password manager — Makes sure one cracked password can't open everything else you own.
  • Account and email monitoring (ITDR) — Spots account takeovers, hidden inbox rules, and shady app access, and warns you in real time instead of weeks later.
  • Managed endpoint protection — Catches the password-stealing malware that kicks off a lot of these attacks.
  • Email authentication (SPF, DKIM, DMARC) — Makes it much harder for anyone to send fraudulent email using your name.
  • Team awareness — Most of these start with one person clicking one convincing email. A team that knows what to look for is real protection.

The one rule to give your customers today

This costs nothing, it's one sentence, and on its own it stops most payment fraud. Tell your customers, and put it on your invoices:

"We will never call or email you to change payment or wiring instructions. If you ever get that request, don't act on it. Call us directly at the number you already have on file."

A caller can fake your number. An email can look completely real. But a customer who picks up the phone and checks with you on a number they already trust will catch the fraud every time.

If your business runs on cell phones, you can lock your SIM cards down to prevent unauthorized porting and nefarious acts. Research "how to lock SIM cards on [your carrier]. You can usually do it through their website within a couple clicks. Finding the setting is the hard part!


How we help our clients stay ahead of this

At NTPC, none of the protections above are extras we try to sell you after something breaks. They're the standard we build in from the start, using the same enterprise-grade tools the big companies rely on, priced for small and mid-sized businesses. We're Texas-based and staffed with local people, so when something goes wrong, you're talking to a real human who knows your setup, not an overseas call center or a bot.

We also work with solo business owners, the one-person operations that most IT companies overlook. If you're running the whole thing yourself, you're often the most exposed and the least likely to have anyone watching your back. We help there too, including the compliance requirements a lot of solo operators don't realize apply to them until it becomes a problem.

If you're not sure where your business stands right now, that's exactly the kind of thing we're glad to walk through with you.

Want a clear look at where your business stands? Get in touch, and we'll go through it with you.

Ready to Stop Fighting Your Technology?

Book a free one-hour consultation. We'll assess where you are, where you want to go, and exactly what it takes to get there.

← More from the Blog