Phishing
Vishing
Smishing
Invoice scams
Most people can spot a clumsy scam email. But when attackers compromise an account or get hold of internal data, whether through a past breach, an insider, or scraped information, their attacks stop being "spray and pray" and become highly targeted and personal. Security professionals call this spear phishing (or whaling when it targets executives).
These attacks are dangerous precisely because they remove the usual red flag: the message has context. It references real projects, real coworkers, real invoices. This guide shows you what that looks like for each attack type, and the one habit that defeats all of them.
The golden rule: if a request involves money, credentials, or sensitive data, verify the requester's identity through a separate, pre-established channel. Never trust the channel the request arrived on. Accurate insider details are not proof of legitimacy. In fact, they can be the strongest sign of a sophisticated compromise.
1. Phishing (email)
Standard phishing casts a wide net. Advanced phishing uses stolen data to impersonate a trusted colleague or vendor.
What it looks like with insider knowledge
- Real context: the email references a project you're actually working on, a meeting that happened yesterday, or an internal tool you use.
- Convincing sender: the "From" address looks identical to a real colleague, or the attacker has compromised the colleague's actual account, making the headers genuinely authentic.
- Urgency grounded in reality: "As discussed in the 2 PM strategy call about the Q3 budget…" The attacker knows the meeting happened because they can see the calendar.
How to protect yourself
- Verify the channel, not the content. Even if the message reads perfectly, confirm the request over a second channel such as Slack, Teams, or a phone call to a number you already know.
- Check the headers. The display name can lie; the Return-Path and Received-From fields are harder to fake. An external IP or free email domain is suspicious no matter how good the content is.
- Beware the "too perfect" email. If a note from your boss or IT packs in internal jargon and project codes that wouldn't normally appear in that kind of message, pause.
- Hover, don't click. Hover over links to see the real destination. Watch for lookalike domains like company-portal-login.com instead of portal.company.com.
- Distrust urgency. Panic and deadlines exist to short-circuit your critical thinking. A real colleague can wait five minutes while you verify.
2. Vishing (phone calls)
Vishing uses voice and psychological pressure. With insider knowledge, the caller sounds like they belong.
What it looks like with insider knowledge
- Pre-shared context: "Hi, it's Sam from Accounting. I'm trying to fix that invoice issue from yesterday on the Meridian project."
- Knows the org chart: they know who you report to and how your department's approvals work.
- Spoofed caller ID: the call can appear to come from a real internal extension.
How to protect yourself
- Use the callback protocol. Never act on an urgent financial or security request received by phone. Hang up and call the person back on a number from your internal directory, not the number they gave you, and not the one on your caller ID.
- Ask for real verification. Request a code sent to your device, or ask something only the real person could answer. Scammers hesitate or try to rush past it.
- Listen for scripted urgency. The details may check out, but the pressure feels artificial. Legitimate colleagues allow a pause to verify.
- Notice the background. A caller claiming to be at busy HQ in dead silence, or with noise that doesn't match, is a red flag.
3. Smishing (text messages)
Text-message phishing is often used to bypass email filters, and with insider knowledge it can mimic your company's own notifications.
What it looks like with insider knowledge
- Fake internal alerts: "IT Alert: Your password expires in 1 hour. Reset here: [link]" where the link looks like an internal subdomain.
- Personal details: "Hi, about the travel reimbursement for your trip last week, please approve the attached document."
- Shortened links that hide the real destination.
How to protect yourself
- Ignore unsolicited links. IT departments almost never text password-reset links you didn't request. If you didn't ask for it, don't tap it.
- Check the sender. Real internal systems send from a consistent short code or verified business number. A random mobile number is a major red flag.
- Cross-reference. If the text mentions a trip, meeting, or expense, check your calendar or project tool, then verify by email or chat if anything feels off.
- Don't reply "YES." Even replying can confirm your number is live or trigger a subscription scam.
4. Invoice scams (business email compromise)
The most financially damaging attack of all. Attackers use stolen invoice data and real vendor relationships to redirect payments.
What it looks like with insider knowledge
- Accurate history: the email includes a copy of a genuine past invoice, with the bank account number quietly changed, or a new "processing fee" added.
- A perfect vendor persona: real PO numbers, delivery dates, and contact names that match your records exactly.
- An "update" story: "Our banking details changed due to a merger, so please send the next payment to this new account."
How to protect yourself
- Verify out-of-band. Never change payment details based on an email alone. Call the vendor on the phone number you already have on file, not the one in the email.
- Compare bank details character by character. Check new account numbers against your last successful payment. A single changed digit is all it takes.
- Treat urgent payment requests as suspect. "The client is angry, payment is late" is manufactured pressure designed to skip your verification steps.
- Inspect the thread. A suspiciously short email history, or a "Reply-To" address that differs from the "From" address, warrants immediate investigation.
Quick-reference defense matrix
When an attack includes accurate internal details, the usual "does this look suspicious?" test fails. Use verification of intent instead:
Key takeaway: attackers who have breached an account or database hold the "keys to the castle" when it comes to context. So the presence of accurate internal information proves nothing. When money, credentials, or sensitive data are on the line, always verify through a separate channel you established beforehand.