Small businesses receive targeted messages that reference real suppliers, real invoices, and real domain renewals. The defence is not spotting a badly written email, since many are now well written. It is a habit: verifying any request that changes where money goes, through a channel the message did not supply.

The ones aimed specifically at businesses

Changed banking details

An email appearing to be from a supplier you use, saying their bank details have changed and attaching an updated invoice. Frequently accurate about the amount and the project.

This is the most costly variant and the most convincing, because the sender knows enough to be plausible. Payment goes to the fraudster and the real supplier is still owed.

Domain renewal notices

A notice that your domain expires shortly, from a company that is not your registrar. Some are outright fraud and some are technically legal solicitations designed to look like invoices.

The tell is the sender. Compare it against where your domain is actually registered, which is why knowing that matters.

Listing and directory invoices

Bills for business listings you never bought, frequently referencing your real business details and sometimes formatted to look like a renewal of something free.

The urgent request from the owner

A message appearing to come from the owner or a director, to someone who handles payments, asking for an urgent transfer and explaining they are unreachable by phone.

The unreachability is the mechanism. It removes the obvious verification step.

Account warnings

Your hosting, email, or payment account requires attention, with a link to a convincing sign-in page. What is captured is the password, and increasingly the second-factor code as well if you enter it.

Why spotting them is getting harder

The old advice was to look for poor spelling and awkward phrasing. That advice is now unreliable, since generating fluent text is trivial.

Targeted messages also draw on information that is genuinely public: your suppliers from a project you posted about, your staff names from your website, and your domain details from a registry lookup. A message referencing real specifics is far more convincing than a generic one.

So detection based on how the message reads is a weak defence. What still works is verification based on what the message asks for.

The habit that defeats most of it

Any request that changes where money goes gets verified by phone, on a number you already had, before anything is paid.

Not the number in the email. Not by replying to the email. A number from your own records, or from the supplier's website that you navigated to yourself.

That single rule defeats changed banking details, the urgent transfer request, and most invoice fraud, because all of them depend on the verification happening through a channel the fraudster controls.

It is worth stating as a policy rather than an intention, since the person who receives such a message may not be the owner and may be reluctant to question an apparently urgent instruction.

The other checks

What reduces the exposure

Two-factor authentication on the accounts that matter, since a captured password alone then achieves nothing.

Mail authentication records configured properly, which makes it harder for someone to send messages appearing to come from your own domain to your customers, and reduces the chance of your business being the one impersonated.

And a payment process where changes to banking details require a second person or a phone verification, which is the control that actually stops the expensive version.

If somebody clicked

Speed matters more than blame, and the person who clicked needs to feel able to say so immediately.

Change the password on that account and anything sharing it, from a different device. Check for forwarding rules added to the mailbox, which is a common follow-up step and quietly copies your mail. Check for new administrator accounts. And if payment details were entered, contact the bank straight away.

Where money has actually moved, the bank should be told within hours rather than days, since recovery becomes considerably harder with time.

The point worth making internally

These messages work because they exploit ordinary helpfulness under time pressure, not because anyone was careless.

A business where reporting a mistake is uncomfortable will find out later than one where it is routine, and later is what makes it expensive. The account protection half of the same problem is covered in two-factor authentication on the accounts that matter.


Frequently asked questions

What phishing targets small businesses specifically?

Changed supplier banking details, fake domain renewal notices, invoices for listings never purchased, urgent transfer requests appearing to come from the owner, and account warnings with convincing sign-in pages.

Can I still spot phishing by poor writing?

Not reliably. Generating fluent text is trivial now, and targeted messages draw on genuinely public information about your suppliers, staff, and domain to sound plausible.

What is the single best defence?

Verify any request that changes where money goes by phone, on a number you already had, before paying. Not the number in the email and not by replying to it.

Why do these messages always sound urgent?

Urgency removes the verification step. The variant claiming the owner is unreachable by phone is specifically designed to prevent the check that would expose it.

How do I recognise a fake domain renewal notice?

Compare the sender against where your domain is actually registered. Some are fraud and some are technically legal solicitations formatted to look like invoices.

What should happen if someone clicks?

Change the password from a different device, check the mailbox for forwarding rules added afterwards, check for new administrator accounts, and contact the bank within hours if payment details were entered.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Not sure your team would spot a changed invoice?

We help set the verification rule and lock down the accounts these messages are actually after.

Start a Conversation