The Most Preventable Security Incident I Ever Watched Unfold in an Office
This article tells the slow, true story of a six-day office phishing incident at a thirty-person design firm, and uses it to point at the four specific links in the chain where a habit — not a tool — would have changed the outcome. It walks through the Friday click, the Monday warning nobody said out loud, the Tuesday wire instruction change, and the Wednesday morning call from the bank, and ends with a four-habit list any small office can adopt as its first real office phishing prevention tips.
The worst security incidents I have ever seen were not the ones that arrived with flashing lights. They were the ones that arrived on a Friday, looked ordinary for three days, and then became unfixable on a Wednesday. I want to walk you through one of them in detail, not because it was dramatic, but because it is the kind of slow-moving office phishing incident that almost any small business could experience, and because every single link in its chain was breakable with a habit that costs nothing. Office phishing prevention tips usually start with technology. This one starts with the people who saw the warning signs and did not yet have a habit for what to do with them.
The Friday Before Anything Was Wrong
It started, as these things often do, with a person. A long-time bookkeeper at a thirty-person design firm in the Midwest had been with the company for eleven years. She was trusted, careful with her work, and not the kind of person you would expect to be the center of a security incident. On a Friday afternoon, she received an email that looked like a routine Microsoft 365 password-expiration notice. The address was one character off from the real Microsoft domain, and the link inside the email pointed to a page that looked, in every visible respect, like the real Microsoft 365 login. She clicked. She typed her work email and her password. She saw a "session expired, please try again" message, and she figured the system was just being slow. She closed the tab, finished her day, drove home, and did not mention it to anyone.
That is the entire moment the incident was decided. Every other choice that mattered over the following six days was downstream of that single Friday click. The technical reality of how the attackers used her mailbox is not the heart of the story. The heart of the story is that the office phishing prevention tips everyone in the firm had heard — "if something looks odd, tell someone" — never quite landed with the bookkeeper, because nothing about that Friday looked odd to her. The phishing page was convincing. The email was within the noise of a normal work day. And because there was no habit for reporting near-misses, the click that mattered was also the click nobody knew had happened.

Monday Morning: How the First Sign Was Missed
By Monday, the attackers were inside the mailbox. They did not do anything dramatic. That is the second thing to understand about office phishing: the most common attacker behavior is to wait, to read, and to learn the rhythm of the office before making a move. Over the weekend they read two months of email. They identified the firm's biggest client, the managing partner's travel schedule, and the format of the wire-transfer instructions the firm used. On Monday morning, the only visible sign was a small one: a new mail-forwarding rule on the bookkeeper's mailbox, quietly routing messages matching the words "invoice" and "payment" to an external address. Nobody noticed the rule. Nobody had a habit of checking for it.
The first real warning was the bookkeeper's own feeling, in a standup meeting that Monday, that "something about my email feels off." She did not say the sentence out loud. She thought it, noted it, and moved on with the standup, because the work in front of her was concrete and the feeling was vague. That is the second link in the chain that could have been broken with a habit instead of a tool. A team that has a low-friction way to say "my email feels off, can someone look?" is a team that catches the moment when the inbox is being read by a stranger. A team that does not have that habit lets the warning die in the meeting room.
The second warning was the help-desk ticket she opened at 2 p.m. that same day, reporting that her mailbox was "running slowly." Slow mailboxes are not security events; they are inbox irritations. The ticket was routed to the office's outside IT vendor, who followed the slow-mailbox playbook and ran the standard cleanup. Nobody asked the slow-mailbox question that mattered, which was "is anything else in this account changing besides the speed?" The help desk did not ask because the help desk was not trained to ask. The training the help desk had was about how to make a slow mailbox fast, not about how to spot an attacker inside one.
The Slow Cascade Through Tuesday and Wednesday
By Tuesday morning, the attackers were ready. They sent an email from the managing partner's real email address — which they had access to through the bookkeeper's account — to the firm's accounts-payable lead, asking for a one-time change to the wire instructions for the firm's largest client. The email had the partner's real signature, the partner's real writing style, and a plausible explanation: "I'm traveling this week and the bank is being slow, can we get this through before close?" Accounts payable flagged the request for confirmation, which was the right instinct. The confirmation was answered, in seconds, by the partner's real account, in the partner's real voice, with the partner's real signature. The reply was convincing because it was the partner.
The wire went out late Tuesday afternoon. The bank called Wednesday morning to confirm a transfer that, in their words, "did not match the pattern" of how the firm usually moved money. The managing partner, freshly back from travel, learned of the transfer at 9:14 a.m. on Wednesday. By then, the funds were already moving through intermediary accounts, and the firm's cyber insurance carrier was answering a very different kind of phone call. The week that had begun with a single click ended with a wire fraud loss in the high six figures and a forensic investigation that ran for months. The incident was not technically complex. It was, in every way, the most preventable kind of security incident I have ever watched unfold in an office.

Where the Chain Could Have Been Broken
When I walk a small office through this story, I do not use it to scare anyone. I use it to point at the four specific links in the chain where a habit — not a tool, not a vendor — would have changed the outcome. The four links below are also the four office phishing prevention tips that I think matter more than any software purchase.
Link in the chain | What a good habit would have looked like | What it would have prevented |
|---|---|---|
The Friday click on a fake login | A two-second "this looks off, let me confirm the URL" pause, or a quick message to IT | The credential exposure at the very start of the chain |
The bookkeeper's Monday feeling | A team norm of saying "my email feels odd" out loud, even without proof | The attacker reading the mailbox undetected for three more days |
The Tuesday wire instruction change | A callback rule: any wire instruction change requires a phone call on a number already on file, not the number in the email | The actual transfer of funds |
The help-desk ticket about a slow mailbox | A help desk trained to ask "is anything else in this account changing?" | The full week of attacker access |
Notice that none of the four habits require a budget. They require a five-minute conversation, a written rule, a phone call, and a small change to the help desk's script. That is the part of the story that matters most. The bookkeeper did not need to be smarter. The accounts-payable lead did not need to be more suspicious of the partner. The help desk did not need a better tool. They each needed a habit that was already part of how the office worked.
What I Tell Small Offices After They Hear This Story
When I finish telling the story to a small office, I usually ask them to do one exercise. We list, on a single page, every person in the office who has access to money — directly or indirectly — and we write, next to each name, the one habit that would have stopped the wire from going out in this story. For an owner, it is "any wire change gets a phone call, period." For an office manager, it is "any vendor instruction change comes to me before it goes to AP." For an AP lead, it is "I confirm any new payment instructions by a phone number I already have, not a number from the email." The list, in plain English, becomes the firm's first real office phishing prevention tips, and the same list works for a great deal more than phishing.
The other thing I tell them is that the goal is not to catch every attacker. The goal is to break the chain early enough that one bad habit does not become a six-figure loss. In this story, the chain had four breakable links. The bookkeeper would have broken the first, the team norm would have broken the second, the callback rule would have broken the third, and the help desk's training would have broken the fourth. The firm only needed one of them to work. Security gets easier when the rules make sense, and the rule here is simple: write down the four habits, post them where money moves, and trust that a five-minute habit will do more than another software purchase.
Below is the short list I leave on the conference room whiteboard when I finish the conversation. It is not a policy document, and it does not need to be. It is a one-page reminder that any office team can read in thirty seconds and apply before the next wire instruction lands in an inbox.
For the owner or partner: any wire or payment instruction change gets a phone call on a number already on file, not a number from the email.
For the office manager: any vendor instruction change comes to me before it goes to accounts payable, even if the email looks internal.
For the accounts-payable lead: I confirm new payment instructions on a phone number I already have, and I save the confirmation note in the vendor file.
For the help desk or IT contact: a slow mailbox ticket always includes one extra question — is anything else in this account changing? — before I close the ticket.
For everyone on the team: if a login page or a wire request feels off, I say it out loud to one named person, and there is no penalty for saying it.
Why This Site Exists: Office Security Advice for People Who Still Have to Run the Business
Leave a comment
No comments yet.