Tap to Pay Scams: What Small Businesses Should Know
Tap-to-pay is fast and generally secure, but scammers can exploit rushed or unclear transactions. Learn five practical ways to protect company funds, help employees recognize tap-to-pay scams, and respond quickly when a charge looks suspicious.
The other day I was speaking to a project manager at a small Vancouver, WA. He’d stopped at a community fundraiser after work. A volunteer asked for a $20 donation by tap-to-pay, then offered to “help” when the payment seemed slow. The manager handed over the phone and later discovered a $200 charge.
Tap-to-pay is generally a secure way to make purchases. The real danger is often not the payment technology itself, but a scammer using urgency, distraction, or trust to hide the amount being charged. As USA Today reported, a few simple habits can protect your money.
Why Tap-to-Pay Scams Matter to Businesses
Small companies make payments constantly: fuel, materials, meals, travel, office supplies, and vendor charges. If several employees carry company cards or use mobile wallets, one careless transaction can become an accounting headache, or a significant financial loss. These scams can also affect businesses that accept contactless payments. Customers expect a clear total, a recognizable business name, and a receipt. A sloppy payment process may look suspicious even when it is legitimate.
How to Use Tap-to-Pay Safely
Confirm the amount before tapping
Never approve a payment until the amount and merchant name are visible. A legitimate seller should have no problem showing you the full transaction before asking for payment. Pay special attention when making donations, buying from temporary vendors, or paying someone who is using a phone instead of a familiar checkout terminal. A scammer may enter $200 instead of $20 and hope you do not notice. If the screen is hidden, the amount changes unexpectedly, or someone tries to rush you, stop the transaction and use another payment method.
Keep control of your phone and card
Do not hand an unlocked phone or company card to a stranger. Once someone has your device, even briefly, they may be able to change the charge, approve another action, or view information that was not intended for them. Employees should hold their own phones and bring them to the payment reader themselves. If the terminal is difficult to reach, ask the seller to move it closer or cancel the purchase. The same rule applies to company cards: keep the card in sight and do not let someone take it into another room or vehicle to process a payment.
Turn on transaction alerts
Configure company cards and banking apps to send an immediate notification for every purchase. Do not limit alerts only to large transactions, because scammers sometimes begin with a small test charge to see whether an account is active. Employees should know who to contact if an alert does not match the purchase they just made. A quick phone call to the office manager or card issuer can prevent additional charges. Alerts also make expense reporting easier because employees can confirm the merchant and amount while the transaction is still fresh.
Use company cards carefully
Give payment access only to employees who genuinely need it. Set spending limits that reflect each employee’s normal responsibilities rather than providing everyone with the same purchasing authority. Create a short written policy explaining where company cards may be used, whether mobile wallets are allowed, and which receipts must be retained. Review charges frequently instead of waiting for the monthly statement. These controls are not about distrusting employees; they help honest staff recognize unusual activity and respond consistently.
Act quickly after a suspicious charge
Contact the card issuer immediately if a tap-to-pay transaction looks wrong. Ask the issuer to lock or cancel the affected card, dispute the charge, and check for other recent activity. Save the receipt, transaction alert, merchant information, location, and approximate time of the incident. If a company phone may have been accessed, change relevant passwords and ask your IT provider to check the device. Fast reporting can limit further losses and gives the bank, police, or other investigators better information to work with.
Small Habits Prevent Expensive Problems
That Vancouver project manager could not undo the awkward encounter, but the company changed its payment policy afterward. Employees at the firm now confirm every total, keep their phones in hand, and receive instant purchase alerts.
Good security practices usually look like this: clear expectations, simple safeguards, and employees who feel comfortable stopping when something seems off.
If your business is in Vancouver, WA, or Portland, OR, Mickler & Associates, Inc. can help strengthen its cybersecurity, Microsoft 365 environment, cloud services, and everyday IT practices. Contact us for a friendly conversation about making technology safer and easier to manage.
R
The Hidden Cost of Replacing Computers Too Late
Waiting too long to replace aging computers can cost your business far more than the equipment itself. Learn how a planned computer replacement cycle reduces downtime, improves security, and keeps technology expenses predictable.
Okay, here’s a good example.
A small accounting office in Vancouver had one computer everyone called “the broken one.” It took forever to start, froze during video calls, and occasionally required a reboot before it would print. Because it still technically worked, replacing it never became a priority. Then it failed during tax season. The emergency replacement, rushed setup, and lost work cost far more than a planned upgrade would have, especially in this day and age of memory shortages, constraints on international trade, and surprise tariffs.
Waiting Too Long Costs More Than a New Computer
The hidden cost of an aging computer is rarely the machine itself. It is the time employees lose waiting for programs to open, recovering from crashes, and calling for help. An employee losing just 15 minutes each day wastes more than 60 hours a year. Add missed deadlines, frustrated clients, and emergency repair costs, and keeping an old computer can become surprisingly expensive. Older computers may also stop receiving important security updates or struggle to run current business software. That increases the chance of downtime, data loss, and cybersecurity problems.
Create a Predictable Computer Replacement Cycle
Most business computers should be evaluated after three to five years. Anything beyond five years of manufacture is typically considered obsolete in the microcomputer world. Their useful life depends on how they are used, but waiting until they fail is rarely the least expensive option. A practical computer replacement cycle lets you budget ahead and replace equipment when it is convenient—not during payroll, a client presentation, or your busiest season.
Watch for Everyday Warning Signs
Slow startup times, frequent freezing, battery problems, noisy fans, and repeated repairs are signs that a computer may be nearing retirement. Listen to employees. If someone regularly complains that their computer prevents them from working efficiently, investigate the cause instead of treating the slowdown as normal.
Replace Computers in Stages
Small businesses do not need to replace every computer at once. Keep an inventory showing each computer’s age, warranty status, user, and expected replacement date. Replacing a few machines each quarter or year spreads out expenses and makes setup easier. It also gives your IT provider time to transfer files, configure security, and test business applications properly.
Include Setup and Security in the Plan
A replacement is more than buying a laptop from a store. Business applications, email, Microsoft 365, backups, security settings, printers, and access permissions all need attention. Planning these details before the new computer arrives helps employees return to work quickly and reduces the chance that important information gets missed.
Planned Upgrades Protect Productivity
The Vancouver accounting office eventually adopted a scheduled replacement plan. Computer expenses became predictable, emergency calls dropped, and employees stopped losing time to failing equipment.
If your business in Vancouver, WA, or Portland, OR has computers that may be overdue for replacement, Mickler & Associates, Inc. can help you review their condition and build a sensible plan. We also provide professional IT support, cybersecurity, Microsoft 365, cloud services, and managed IT—without pushing equipment you do not need.
R
Business Email Scams Are Targeting Contractors More Than Ever
Business email scams increasingly target contractors. Learn practical ways Vancouver and Portland businesses can protect payments, email, and company data.
Okay, let’s paint this familiar picture.
A small contractor gets an email late Friday afternoon. It appears to be from a regular supplier and references an outstanding invoice. It says their banking information has changed. Suspecting everything is ‘business-as-usual,’ the office manager updates the payment information and sends $8,700 to the new account.
And on Monday, the real supplier calls asking about the overdue invoice.
Uh-oh.
Yeah, unfortunately, scenarios like this are becoming increasingly common. Business email scams are especially dangerous for contractors because construction and service businesses routinely exchange invoices, estimates, payment instructions, schedules, and documents by email. Further, routinely paying these suppliers and clearing that email from an inbox is the everyday, routine behavior of an AP Manager or office manager — they’re almost working on autopilot — and criminals know that, and they’re keen to take advantage of it.
Why Contractors Make Attractive Targets
Contractors often have money moving in several directions at once. Customers pay deposits. Subcontractors submit invoices. Vendors want payment. Office staff may be coordinating all of it while answering phones and scheduling crews.
An attacker doesn’t necessarily need to hack your accounting system. They don’t even need a lot of sophisticated spyware to figure out your bank accounts. They simply need to impersonate someone your staff already trusts. They just have to appear as routine.
A convincing email might claim to come from the owner asking for an urgent payment, a vendor announcing new banking information, or a customer requesting a refund to a different account. And the hacker is taking advantage of all of that chaos.
How to Protect Your Business
Verify payment changes another way. If a vendor emails new banking or payment instructions, call them using a phone number you already have. Never rely on the phone number included in the suspicious email.
Require a second set of eyes. Consider requiring two people to approve payments above a certain dollar amount. This simple procedure can stop an expensive mistake before money leaves the bank.
Protect your email accounts. Every employee should use multi-factor authentication, particularly anyone handling invoices, payroll, banking, or administrative work. A stolen password should not be enough to access your company email.
Teach employees to recognize unusual requests. Staff don't need extensive cybersecurity training or a degree in information systems security. They do need permission to question an email that feels unusual, rushed, or financially sensitive—even when it appears to come from the boss.
Good Email Security Protects More Than Email
Preventing business email scams isn't just about avoiding fraudulent payments. A compromised mailbox can expose customer information, contracts, employee records, invoices, and years of correspondence.
For a small contractor, one successful scam can mean thousands of dollars lost, damaged vendor relationships, and days spent figuring out what happened.
That hypothetical contractor who lost $8,700 could have stopped the entire incident with one phone call.
The goal isn't to make your business harder to operate. It's to put a few sensible safeguards between a convincing email and your bank account.
If you operate a small business or contracting company in Vancouver, WA or Portland, OR, Mickler & Associates, Inc. can help review your email security, Microsoft 365 environment, cybersecurity practices, cloud services, and overall IT setup. Contact us when you'd like a practical second opinion.
R