The email is from a client you have worked with for six years. It lands in a thread you were already having. The signature is right, the reply history is underneath, the tone is close enough. But it asks you to open a shared document you were not expecting, or mentions that their banking details have changed and could you update them before the next invoice.

This is not a stranger pretending to be someone. Their account is genuinely compromised, and somebody else is now sitting inside a business relationship you spent years building. Handling it well means protecting your own company, warning them through a channel that is not the one under someone else’s control, and doing it without embarrassing a good customer. Most people get at least one part of that wrong.

How to Tell It Is a Real Account and Not a Stranger

A lookalike email is usually catchable on the address alone. The FBI’s Internet Crime Complaint Center advises verifying that the sender’s address matches who the message claims to be from, watching for hyperlinks with misspellings of a real domain, and making sure computer settings show full email extensions.

A compromised account passes all of those checks, because it is the real address. So you have to read for different signals:

  • The ask does not match the conversation. A routine thread about scheduling suddenly contains a document link or a payment instruction.
  • Banking or remittance details change. The single highest-value warning sign in business email. It deserves a hard stop every time, regardless of who appears to be asking.
  • The reply to your question is oddly generic. Whoever is answering has read the thread but does not know the details you and your contact both know.
  • The timing is strange. Messages at 3 a.m. their time, or a burst of activity from someone who normally answers once a day.
  • Several people get similar messages at once. If two of your staff get an unexpected link from the same contact on the same morning, treat it as confirmed until proven otherwise.

The scale here is not small. In a September 2024 public service announcement, the FBI’s Internet Crime Complaint Center reported more than $55 billion in exposed losses from business email compromise across 305,033 domestic and international incidents reported between October 2013 and December 2023, spanning all 50 states and 186 countries. Most of those started exactly like this: a real account, a real relationship, a slightly wrong request.

Why Replying in the Thread Is the Wrong Move

The instinct is to hit reply and ask “is this really you?” Do not.

Whoever has that mailbox reads your reply, and they will answer yes. Worse, they now know you are alert, which usually makes the next attempt better. There is a mechanical problem too: mailboxes taken over this way often have rules quietly filing certain messages away, so the real owner may never see your question. You could email that account for a week and be talking only to the intruder.

The FBI’s guidance on this is short and worth memorizing: “Use secondary channels and/or two-factor authentication to verify requests for changes in account information.” Secondary channel is the operative phrase. The FTC says the same thing more plainly in its small business guidance: “Pick up the phone and call the vendor, colleague, or client who sent the email.”

Reaching Them on a Channel That Is Not Compromised

The critical detail: use a phone number you already had, from your own records, a signed contract, or their main website. Do not use the number in the signature block of the suspicious email, or one provided in any recent message from that account. Signature blocks are editable, and that is a well-worn trick.

If you cannot reach your usual contact, call their main office line and ask for someone else. Text a mobile number you have had for years. If they are local, a five minute drive settles it. Reaching a different person is often faster than reaching the affected one, and the news lands with someone who can act on it.

Protecting Your Side in the First Hour

  1. Do not open the attachment or click the link. Not to check what it is, not in a preview window. Leave it alone.
  2. Find out whether anyone already did. Ask directly and without blame. This determines whether you have an inconvenience or an incident, and people answer honestly only where reporting is safe.
  3. Freeze anything involving money. Any payment, wire, or change of banking details connected to that contact stops until verified by voice with a person you know. No exceptions for urgency, because urgency is the tool being used on you.
  4. Tell your IT provider immediately. Even if nobody clicked. Knowing which messages arrived, and to whom, is far easier in the first hour than the following week.
  5. Check your own mailbox rules and sign-in activity. If someone did enter credentials, unexpected forwarding rules and logins from unfamiliar places are the earliest signs.
  6. Watch for the follow-up. After a compromised contact is cleaned up, the next message often comes from a lookalike domain continuing the same conversation. Tell your finance staff to expect it.

Telling Them With Grace

Remember that you are calling to help someone having a bad day. A few things make that call go well.

Lead with specific evidence, not a diagnosis. “I got a message from your address at 4:12 this morning asking me to update your bank details, and I wanted to check with you directly” is useful. “You have been hacked” is an accusation. Offer to forward exactly what you received, since it may be the clearest artifact they have. Keep it between the two of you, and assume they may already know and be dealing with it.

One more thing, and we will be candid about our own industry. Do not turn this into a sales opportunity. We have watched IT providers use a client’s compromised partner as an opening for a pitch, and it is a bad look people remember. Help first. If they ask who handles your security, answer honestly then. Being the company that called before anything went wrong is the point, and it is part of what makes incidents at one company ripple through everyone connected to it.

What of Yours Do They Hold?

Once the scramble is over, ask a question most businesses never ask: what does this partner actually have of ours?

Look for guest accounts they hold in your Microsoft 365 or Google Workspace tenant, shared folders and document links you granted them, portal logins on their system, contracts and banking information exchanged over email, and any shared credential the two companies pass back and forth. The FTC advises confirming a partner has fixed the problem before restoring access, investigating your own network to be sure nobody got in through the relationship, and notifying anyone whose data may have been exposed.

Rotate any shared credential. Remove guest access nobody has used in months. The FTC also points businesses to report incidents to the FBI at IC3.gov and to the FTC at ReportFraud.ftc.gov.

The Bottom Line

When a partner’s account is compromised, three things carry the day. Verify on a channel the attacker does not control, using contact details you already had. Freeze money movement until a human voice confirms it. Tell them privately, early, and without a lecture.

The businesses that come through this cleanly are not the ones with the best filtering. They are the ones where a bookkeeper feels comfortable saying “this looks off, I stopped the payment,” and nobody treats it as an overreaction. Build that, and most of the rest handles itself.

We help businesses across Denton County build the verification habits that stop this before money moves. If you want a second set of eyes on a suspicious message, or on how your team handles payment changes, Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).