Regular phishing is volume. Spear phishing is aim. The sender has your name, your title, who you pay, and who approves wires. The message reads like it came from inside the building.
That is why it works. And it is why “tell people to be careful” is not a program.
They are not guessing
LinkedIn is an org chart. The website lists leadership. Job posts advertise which software you run. Press and local news fill in the rest. Tools can assemble that into a custom email in minutes.
The office manager should not be expected to out-research a targeted message on a busy Thursday. Your IT company should already be reducing how easy you are to impersonate and how far one click can go.
What it looks like in a real office
The common version is business email compromise. Someone learns who handles payables and who the controller is. They register a lookalike domain. Then they send: process this wire, I am in a meeting, I will explain later.
No malware. No ugly link. Just urgency and a name everyone knows.
The vendor version is the same trick from the other direction: “our bank account changed, please update.” Everything in the email is right except the account number. By the time the real vendor asks where the payment is, the money is gone.
What we do We treat this as a systems problem. Email authentication, lookalike watching, and a hard rule that payment changes never happen from email alone. We help put that rule in with you. We do not leave it as a poster in the break room.
Why the old advice fails
Bad grammar is gone. Many of these messages have no link to hover. The from address is close enough that a glance loses.
So the defense cannot be “read more carefully.” It has to be controls that work when a good person is in a hurry:
- Payment and bank-change verification that your IT company helped design and will back you on
- SPF, DKIM, and DMARC actually enforced, not sitting in monitor mode
- Someone watching for domains that look like yours
- Training on this scenario, not a generic phishing cartoon
If your provider has not brought those up, they are hoping your staff will catch what the systems should stop.
The only question that matters
Ask them what they have in place for impersonation and vendor-payment fraud. If the answer is awareness training, you are the control.
If you want a straight read on how exposed the office is, reach out. We will walk the current defenses and say where the holes are.