Why email scams still win at small companies

You do not need a sophisticated hacker to lose money. You need one rushed invoice approval, one fake “update your password” page, or one Outlook rule that quietly forwards mail to a stranger. Small companies in Henderson and across the Southwest get hit because email is how work moves—quotes, W‑9s, wires, payroll changes—and because attackers copy the look of real vendors and real bosses.

Stopping most email scams is not about becoming a security expert. It is about a short list of habits and settings: safer Microsoft 365 / Outlook setup, MFA, fewer shared logins, filters that catch junk, and a money-move rule that no surprise email can override. This article is the owner version.

The scams you will actually see

The patterns repeat:

  • Fake invoice or “updated banking details.” Looks like a known vendor. New routing numbers. Urgency.
  • Boss or owner impersonation. “I’m in a meeting—send a gift card / wire now.” Often from a lookalike address.
  • Password theft. Link to a fake Microsoft login. Attacker then reads mail, resets passwords, or creates forwarding rules.
  • Payroll diversion. “Change my direct deposit” from a compromised or spoofed employee.
  • Malware attachments. Unexpected zip or invoice PDF that installs junk or ransomware.

Most of these fail when people slow down and when email accounts are harder to take over. Technology helps. Process helps more than a poster in the break room.

Lock down Microsoft 365 / Outlook first

If your company runs on Microsoft 365, that is ground zero. Shared mailboxes with shared passwords, no MFA, and former staff who still have access are open doors. Before you buy another filter product, fix ownership of the tenant:

  • Every person has their own account
  • MFA is required for email and admin roles
  • Leavers lose access the day they leave
  • Only a few people can change domains, billing, and user permissions
  • Someone reviews unusual sign-in alerts

PrimeTech’s overview of Microsoft 365 security covers the practical setup owners should expect. Pair that with day-to-day managed IT so the settings do not drift when a new hire starts or a laptop dies.

Turn on the boring email protections

Microsoft 365 includes spam and phishing protections. They only help if they are configured and not turned off because someone found them annoying. Ask your IT person—in plain English:

  • Is junk and phishing filtering on for the whole company?
  • Are dangerous attachments blocked or opened in a safer way?
  • Do we warn people when mail comes from outside the company?
  • Can staff easily report a suspicious message?

You are not aiming for zero junk mail. You are aiming to make the dangerous stuff harder and the suspicious stuff more obvious.

Make money moves follow a rule, not an email

Write one rule and train to it: no wire, ACH change, gift card purchase, or payroll deposit change based only on email. Call a known number. Confirm in person. Use a second channel you already trust. Attackers rely on urgency and politeness. Your rule gives people permission to pause.

Post the rule where AP and office managers work. Practice it once. The first time someone “tests” the rule with a fake request, thank them publicly—culture beats a PDF policy.

Watch for hijacked mailboxes

When an account is taken over, attackers often create an inbox rule that deletes or hides alerts, or forwards mail to an outside address. Staff may notice odd sent items, password prompts that feel wrong, or colleagues asking “did you email me this?”

Have a simple response plan:

  • Call your IT provider immediately
  • Reset the password and revoke sessions
  • Check MFA and remove unknown methods
  • Search for forwarding rules and strange mailbox delegates
  • Warn customers or vendors if fraudulent mail went out

Speed matters more than blame. Waiting until Monday is how a Friday compromise becomes a Monday fraud claim.

Phishing “training” that does not waste everyone’s time

Short, regular reminders beat annual lectures. Show real examples: lookalike domains, urgent wires, fake Microsoft pages. Teach people to hover on links, to distrust surprise password resets, and to use your money-move rule. If you use simulated phishing, keep it educational—not a gotcha contest that shames the front desk.

Wi‑Fi, shared computers, and the side doors

Email scams hitch rides on weak office habits: shared front-desk logins, guest Wi‑Fi mixed with business Wi‑Fi, and computers without current protection. A stolen laptop with a saved Outlook password is as bad as a clever phishing page. Keep guest Wi‑Fi separate, require MFA, and keep protection and updates current on each machine. That is ordinary hygiene under managed cybersecurity for shops without a security hire.

What “good enough” looks like for a 10–50 person shop

Picture a contractor, clinic office, professional firm, or small manufacturer on Microsoft 365:

  • MFA on; no shared owner password for email
  • Filtering on; external mail is labeled
  • Money moves need a call-back
  • IT can lock a mailbox the same day
  • Staff know who to call when something feels off

That stops most of what hits local businesses. It will not stop every determined attacker. It will stop the cheap, high-volume scams that drain accounts while everyone is busy.

How to start this week

Turn on MFA for all email if it is not already. Kill shared passwords. Write the money-move rule. Ask IT to confirm filtering and to show you how to check for forwarding rules. Schedule fifteen minutes with staff. If you need a partner to do the setup and keep it current, contact PrimeTech—we support Southwest owners in plain English, not acronym bingo.

FAQ

Is Microsoft 365 enough to stop scams by itself?

It is a strong foundation when MFA, filtering, and admin hygiene are set correctly. It is not automatic. Defaults and neglect leave gaps. Someone has to own the settings.

Should we ban links in email?

Usually no—business needs links. Teach caution, label external mail, and verify money and password changes out-of-band. Blocking every link tends to create workarounds that are worse.

What if a scam already got through?

Contain first: lock accounts, reset passwords, check rules, call the bank if money moved, and document what happened for insurance. Then fix the gap that allowed it. Shame is optional; speed is not.

Do we need a special “email security” product?

Maybe later. First use what you already pay for in Microsoft 365, plus MFA and process. Extra tools help some shops; they do not replace ownership and call-backs on wires.

How does this relate to cyber insurance?

Carriers often ask about MFA, phishing awareness, and email controls. Clean answers come from a real setup, not last-minute guesswork. See our guide on the cyber insurance checklist for small business.

Want email that is harder to hijack?

PrimeTech helps local companies harden Microsoft 365 / Outlook, turn on MFA, and put simple money-move rules in place—from Henderson across the Southwest.

Book a 15-Minute Call →  Microsoft 365 Security  Managed IT  Managed Cybersecurity