Business Email Scams Are Targeting Contractors More Than Ever
Business email scams increasingly target contractors. Learn practical ways Vancouver and Portland businesses can protect payments, email, and company data.
Okay, let’s paint this familiar picture.
A small contractor gets an email late Friday afternoon. It appears to be from a regular supplier and references an outstanding invoice. It says their banking information has changed. Suspecting everything is ‘business-as-usual,’ the office manager updates the payment information and sends $8,700 to the new account.
And on Monday, the real supplier calls asking about the overdue invoice.
Uh-oh.
Yeah, unfortunately, scenarios like this are becoming increasingly common. Business email scams are especially dangerous for contractors because construction and service businesses routinely exchange invoices, estimates, payment instructions, schedules, and documents by email. Further, routinely paying these suppliers and clearing that email from an inbox is the everyday, routine behavior of an AP Manager or office manager — they’re almost working on autopilot — and criminals know that, and they’re keen to take advantage of it.
Why Contractors Make Attractive Targets
Contractors often have money moving in several directions at once. Customers pay deposits. Subcontractors submit invoices. Vendors want payment. Office staff may be coordinating all of it while answering phones and scheduling crews.
An attacker doesn’t necessarily need to hack your accounting system. They don’t even need a lot of sophisticated spyware to figure out your bank accounts. They simply need to impersonate someone your staff already trusts. They just have to appear as routine.
A convincing email might claim to come from the owner asking for an urgent payment, a vendor announcing new banking information, or a customer requesting a refund to a different account. And the hacker is taking advantage of all of that chaos.
How to Protect Your Business
Verify payment changes another way. If a vendor emails new banking or payment instructions, call them using a phone number you already have. Never rely on the phone number included in the suspicious email.
Require a second set of eyes. Consider requiring two people to approve payments above a certain dollar amount. This simple procedure can stop an expensive mistake before money leaves the bank.
Protect your email accounts. Every employee should use multi-factor authentication, particularly anyone handling invoices, payroll, banking, or administrative work. A stolen password should not be enough to access your company email.
Teach employees to recognize unusual requests. Staff don't need extensive cybersecurity training or a degree in information systems security. They do need permission to question an email that feels unusual, rushed, or financially sensitive—even when it appears to come from the boss.
Good Email Security Protects More Than Email
Preventing business email scams isn't just about avoiding fraudulent payments. A compromised mailbox can expose customer information, contracts, employee records, invoices, and years of correspondence.
For a small contractor, one successful scam can mean thousands of dollars lost, damaged vendor relationships, and days spent figuring out what happened.
That hypothetical contractor who lost $8,700 could have stopped the entire incident with one phone call.
The goal isn't to make your business harder to operate. It's to put a few sensible safeguards between a convincing email and your bank account.
If you operate a small business or contracting company in Vancouver, WA or Portland, OR, Mickler & Associates, Inc. can help review your email security, Microsoft 365 environment, cybersecurity practices, cloud services, and overall IT setup. Contact us when you'd like a practical second opinion.
R
Five Signs It's Time to Hire an IT Company Instead of Calling Your "Computer Guy"
Is your computer guy no longer enough? Learn five signs your Vancouver or Portland small business may need professional managed IT support.
I met a small business owner who described their IT support arrangement this way:
“Yeah, we have a computer guy. He’s a fella from my church. We call him when something breaks.”
That arrangement worked fine when the company had four employees, a couple of PCs, and most of their files lived on one computer.
Years later, the business had grown to more than a dozen employees. Their application portfolio consisted of Microsoft 365, SharePoint and OneDrive, and 3rd party cloud applications. They had remote workers, shared files, and hosted critical customer data, but IT was still being handled by the church friend one emergency at a time. Turns out that guy had a full-time job and would have to get to the problem at nights, imposing delays on company operations.
In my experience, that’s usually when the “I’ve got a computer guy” support model starts showing its limits.
For a growing small business, it may be time to hire an IT company when technology has become important enough that preventing problems matters more than simply fixing them.
1. You're Calling for Help Too Often
Occasional computer problems happen, but if someone is regularly calling for help with email, printers, passwords, Wi-Fi, Microsoft 365, or slow computers, those problems are costing more than the repair bill.
Employees lose productive time while someone waits for the problem to be diagnosed and fixed. Professional IT support should look for recurring problems and eliminate them instead of repeatedly treating the symptoms.
2. Nobody Is Watching Your Cybersecurity
Who monitors your computers for malware? Who makes sure security updates are installed? Who checks that former employees no longer have access to company accounts?
If the answer is “nobody,” that's a warning sign.
Small businesses don't necessarily need complicated cybersecurity systems, but they do need someone taking responsibility for basics such as updates, account security, backups, antivirus protection, and employee access.
3. Your Backup Plan Is Mostly Hope
“We back everything up” should be followed by another question: Can you restore it? I think that question gets even more complicated by adding, “Can the church guy restore it when he’s available?”
A backup that hasn't been checked may not be much of a backup. An IT company can monitor backups, address failures, and periodically verify that important business information can actually be recovered.
4. One Person Knows How Everything Works
Your Wi-Fi password, Microsoft 365 administrator account, domain registration, backup system, and network configuration shouldn't exist solely inside someone's head.
Good IT support includes documentation. If your computer person became unavailable tomorrow, another qualified technician should be able to understand your systems and keep the business running.
5. Technology Problems Are Becoming Business Problems
Yikes. This is probably the biggest sign.
When an email outage prevents customers from reaching you, a failed computer stops someone from billing, or a security incident threatens confidential information, you're no longer dealing with a computer problem. You're dealing with a business problem.
For companies with 2–50 employees, managed IT services can provide something the break-fix model generally doesn't: ongoing responsibility for keeping technology reliable, secure, and recoverable.
If your business is reaching that point, Mickler & Associates, Inc. provides professional IT support for small businesses throughout Vancouver, WA and Portland, OR, including cybersecurity, Microsoft 365, cloud services, and managed IT. Contact us and let's talk about what your business actually needs — without making IT more complicated than it has to be.
R
Top Cybersecurity Risks to Small Businesses: How They Impact Operations, Employees, and Consumers
Cyberattacks are a growing threat to small businesses, disrupting operations, stressing employees, and shaking consumer trust. Stay vigilant!
Cybersecurity threats are a growing concern for small businesses. Here are the top risks and their potential impacts:
Phishing Attacks: Phishing emails are one of the most common threats. They trick employees into providing sensitive information or clicking on malicious links. According to a 2023 report by Verizon, 36% of data breaches involved phishing. This can lead to unauthorized access to company data, financial losses, and damaged reputation.
Ransomware: Ransomware attacks can cripple business operations by encrypting essential data and demanding a ransom for its release. The FBI reported a 62% increase in ransomware incidents in 2022. This can halt business activities, leading to significant downtime and financial losses.
Insider Threats: Whether malicious or accidental, insider threats pose a serious risk. Employees with access to sensitive data can leak or misuse information. This can result in legal repercussions and loss of customer trust.
Weak Passwords: Using weak or reused passwords can make it easy for cybercriminals to gain access to systems. A study by NordPass found that 73% of passwords are duplicates. This can compromise the security of multiple accounts and sensitive information.
Software Vulnerabilities: Failing to update software regularly can leave systems vulnerable to attacks. Cybercriminals exploit outdated software to infiltrate networks. Regular updates and patches are crucial to maintaining security.
Impact on Business Operations: Cyberattacks can disrupt daily operations, cause financial losses, and damage the business's reputation. Recovery can be time-consuming and costly.
Impact on Employees: Employees may face stress and uncertainty during and after an attack. They may also be targeted directly, leading to a loss of productivity and morale.
Impact on Consumer Behavior: Customers may lose trust in a business that has experienced a data breach. This can lead to decreased sales and a tarnished reputation.
Stay Vigilant: Implementing strong cybersecurity measures, educating employees, and staying updated on the latest threats are essential steps to protect your small business.
R