A short security brief for the people who actually run things: the small business, the church office, the school, the nonprofit. Each one takes a real threat, explains it in plain language, and gives you one thing you can do today. No fear, no jargon, no sales pitch.
The wire-transfer scam hitting small businesses and churches
Last year, American businesses wired more than three billion dollars straight to criminals. Nobody broke in. It was handed over, on purpose, by good people who believed they were paying a real bill. Here is how the scam works, who it targets, and the one habit that stops it.
Watch the briefMake one rule in your office. Any request to send a wire, pay a new invoice, or change where a payment goes gets verified by calling that person back on a number you already have. Never the number in the email. Never by hitting reply. Speed is the scammer's only weapon, and a ten-minute pause takes it away.
Full transcript
Punctuation added for reading. No words changed.
Last year, American businesses wired more than $3 billion straight to criminals. Nobody broke in to take it. It was handed over on purpose by good people who believed they were paying a real bill. If there's anyone in your shop who can move money, a bookkeeper, an office manager, you, this is a scam built to beat you. Here's how it works, and the 10 seconds that shuts it down.
So here's the deal. The industry calls this one "business email compromise," which is a fancy way of saying, "Somebody asked you for your money politely and you said yes." What it actually is, is a con artist sends an email that looks like it came from someone you already trust. Your boss, a vendor you pay every month, the contractor who just wrapped a job. The message is calm and ordinary. Pay this invoice, or we changed banks, here's the new account number, send the next payment there.
Nothing about it screams danger, and this is the whole point. It's built to look boring. So you pay it. And because it went out as a wire or an electronic transfer, the money is gone in hours, not days. There is usually no getting it back. The FBI calls this, quote, "one of the most financially damaging online crimes," end quote. $3 billion last year, and those are just the people who reported it.
Now who gets caught? Not the big corporations with a fraud department down the hall. It is the 20 person company, the church office, the dental practice, the nonprofit running on three volunteers and a lot of trust. Places where one person handles the money, and a request from the boss or a familiar vendor gets paid without a second look.
One small nonprofit lost $10,000 on a single fake invoice. They were not careless. Well, let me rephrase that. They were exactly as careless as every one of us is at 4:30 on a Friday afternoon. It looked like the real thing, so they treated it like the real thing.
And it is getting harder to catch, because now they use AI to clone a voice. You get a call that sounds like your boss saying, "Yeah, I sent that over. Go ahead and pay it." The voice is fake. The invoice is fake. The only real thing in this entire transaction is your money. So even hearing a familiar voice on the phone is not proof anymore. That is not science fiction. It is happening right now.
Here is what stops almost all of it, and it costs you nothing. Make one rule in your office. Anytime someone asks you to send a wire, pay an invoice, or change where payment goes, you verify it by calling that person back on a number you already have. Not the number in the email. Not by hitting reply. A number you had before any of this started.
Two things make that rule stick. Write it down as an actual policy, so a new hire knows it is the rule and nobody feels rude about double checking the boss. And on anything big enough to hurt, make it two people who sign off, not one. Speed is the only real weapon these people have. A 10 minute pause takes it away from them.
And in the back of the brief: the most expensive email your business ever gets will not look like a threat. It will look like a favor.
And that's your CyberDefense Brief for today. I'm Chris Hilton. I run CyberDefense Consulting, and we help small businesses and community organizations handle exactly this, in plain English, without the fear. If this keeps one person from wiring money to a stranger, it did its job. Send it to whoever signs the checks where you work. God willing, I'll see you at the next one.
New briefs land as the threats worth covering do, not on a schedule. Want the next one? Ask and we will send it to you directly.
Not sure your organization would catch this?
Every engagement starts with a free Security Risk Consultation. Thirty minutes, no obligation, and you walk away with at least one thing you can act on today.
Book Your Free Consultation