It is 4:47 on a Friday afternoon at a business in Plymouth.
An employee is finishing up before the weekend, traffic noise along Court St as
people fight for a good parking spot already drifts in through the window, when
an email arrives from someone whose name they recognize.
I'm heading into a meeting. Can you send me your cell
number? I need a quick favor.
There is no suspicious attachment. No Nigerian prince. No
paragraph filled with obvious spelling mistakes. Maybe the sender even appears
to be the owner of the company.
And that is what makes the message dangerous.
Modern phishing attacks are increasingly designed to look
like ordinary
business communication. They succeed not because employees are careless or
uninformed, but because attackers understand how people work: we respond to our
bosses, handle requests quickly, open shared documents, pay invoices, and try
to be helpful.
For Plymouth businesses, teaching employees to recognize
when someone is manipulating those normal behaviors can turn the people
attackers are targeting into an important part of the company's cybersecurity
system.
Cybercriminals Don't Always Need to Hack the Technology
Hollywood has given us a particular image of a cyberattack:
someone in a dark room furiously typing until they break through a firewall.
Sometimes that happens.
But sometimes it is much easier to send an employee an
email.
Verizon's 2026 Data Breach Investigations Report found that
a human element was involved in 59% of breaches in North America. That category
includes situations such as people falling for social-engineering attacks,
making mistakes, or otherwise becoming part of the chain that leads to a
security incident.
That makes sense from an attacker's perspective.
Why spend hours trying to defeat a security system if you
can convince someone who already has access to open the door?
That is the basic idea behind social engineering.
Instead of attacking software, the criminal manipulates a person into doing
something useful to the attacker: clicking a link, opening a document, entering
a password, approving a login, sending information, changing payment
instructions, or simply continuing a conversation.
The technology matters. Email filters, endpoint protection,
MFA, firewalls, and other security controls can stop enormous numbers of
attacks before employees ever see them.
But some messages will get through.
Employees need to know what to do when one does.
The Phishing Email Isn't Always Going to Look Like a
Phishing Email
For years, one of the easiest ways to teach phishing
awareness was to show employees a badly written message and point out all the
warning signs.
Look at the strange grammar.
Look at the misspelled company name.
Look at that suspicious logo.
Those clues can still matter, but employees should not
depend on them.
NIST now specifically warns small businesses that artificial
intelligence can be used to create increasingly convincing phishing attacks. A
criminal doesn't need to write a perfect email anymore. AI can help produce
polished messages that sound professional, imitate ordinary business language,
and eliminate many of the obvious mistakes people have been trained to notice.
The better question is no longer:
Does this email look professional?
It is:
Does this request make sense?
An email can be beautifully written and still be fraudulent.
A familiar logo proves very little.
Even a message that seems to come from someone you know
deserves a second look when the request itself is unusual.
That is particularly important because attackers often use
information that is readily available online. Company websites, LinkedIn
profiles, social media, press releases, and other public information can reveal
who works for a business, who manages the company, what people do, and who
might plausibly communicate with whom.
The attacker doesn't have to perfectly imitate your boss.
They only have to sound plausible long enough to get you to
act.
Phishing Isn't Just an Email Problem Anymore
Suppose the message at our Plymouth business had arrived as
a text instead.
Or a Teams message.
Or a phone call.
Would the employee recognize it as the same kind of attack?
NIST advises businesses to teach employees that phishing can
arrive through email, text messages, phone calls, social media, and other
channels. Verizon's 2026 research also found that interactive mobile
social-engineering attacks involving techniques such as fraudulent text
messages and voice calls were succeeding at a higher rate than traditional
email phishing.
That means phishing is a technique, not an inbox problem.
A criminal might send a fake Microsoft 365 notification
asking an employee to log in.
Someone might text an employee while pretending to be the
company president.
A caller might claim to be from IT and ask for an
authentication code.
A QR code might take an employee to a fake login page.
A message might appear to be a file-sharing notification
from a customer, coworker, or vendor.
The delivery method changes.
The basic goal does not.
The attacker wants to create a situation where doing what
they ask feels easier than stopping to question it.
Urgency Is a Feature, Not an Accident
Think back to our Friday afternoon email.
Why does the supposed owner say they are heading into a
meeting?
Why is the favor quick?
Why does the request arrive just before people are ready to
leave?
Because time pressure changes behavior.
The FBI has repeatedly warned businesses about scams that
use urgency, secrecy, executive impersonation, and changes to familiar business
procedures. Business Email Compromise, for example, can involve criminals
impersonating executives or vendors to convince employees to send money or
change payment information. The FBI recommends independently verifying unusual
financial requests rather than relying on the email itself.
These aren't theoretical losses.
In 2024, 14,254 Massachusetts victims reported nearly $339
million in internet-crime losses to the FBI. Across the FBI Boston Division's
New England territory, phishing and spoofing were among the three most
frequently reported types of internet crime.
That doesn't mean every unexpected email deserves a full
forensic investigation.
It means employees should learn when to pause.
A useful rule is:
Unexpected + urgent + consequential = slow down.
If someone unexpectedly asks you to transfer money, reveal
information, enter credentials, change a process, approve a login, or bypass
the normal way of doing things, a thirty-second verification is not wasted
time.
It is cybersecurity.
Employees Don't Have to Become Detectives
There is a danger in cybersecurity training becoming too
complicated.
Employees start thinking they need to examine email headers,
understand domain-registration records, identify malware, or somehow determine
with certainty whether a message is malicious.
They don't.
Their job is to recognize when something deserves a second
look.
A simple mental checklist works much better:
Was I expecting this?
An unexpected invoice, password reset, shared document,
authentication request, or conversation should earn more scrutiny than
something you already knew was coming.
Is this request normal?
Would the company president normally text you about
purchasing gift cards? Does this vendor normally change bank accounts through
email? Does IT usually call employees and ask for MFA codes?
Is someone trying to make me act quickly?
Urgency is one of the easiest ways to push people past
normal procedures.
Am I being asked for something valuable?
Money, passwords, authentication codes, confidential
information, customer data, or access to a system should raise the stakes.
Can I verify this another way?
This may be the most important question.
If a vendor emails new payment instructions, call a known
contact using the number you already have.
If an executive makes an unusual request, confirm it through
a separate communication channel.
If Microsoft supposedly needs you to log in, navigate to the
service normally rather than using the link in an unexpected message.
The key is independent verification.
Replying to a suspicious email and asking, "Is this
really you?" doesn't help very much if the criminal controls the mailbox.
Thirty Seconds Can Make a Plymouth Business Harder to
Fool
Now return to our employee at 4:47 on Friday afternoon.
The message still looks convincing.
The owner's name is correct.
The request sounds plausible.
But something about it is unusual.
So instead of immediately replying, the employee pauses.
Maybe they call the office next door. Maybe they send the owner a message
through a familiar channel. Maybe they ask their supervisor or report the
message to IT.
Thirty seconds later, they learn the owner never sent it.
Nothing dramatic happens.
No ransomware screen appears. No bank account gets emptied.
Nobody has to spend the weekend recovering from an incident.
And that's exactly the outcome we want.
Good cybersecurity often looks remarkably uneventful.
For businesses in Plymouth and neighboring South Shore
communities such as Kingston, Carver, and Duxbury, employee cybersecurity
awareness doesn't require turning every person on the payroll into a security
expert. It means giving people a few practical habits that help them recognize
when normal business communication isn't quite normal.
Your employees aren't simply potential targets.
Properly trained, they are part of your security system.
During Cyber Smart September, we'll be looking at the
everyday actions employees can take to make their businesses harder to fool—and
a lot less like sitting
ducks.
In Short
Plymouth businesses can reduce phishing and
social-engineering risk by teaching employees to recognize unexpected requests,
artificial urgency, unusual changes in procedure, and requests involving money,
credentials or sensitive information. Effective employee cybersecurity
awareness focuses less on spotting badly written emails and more on slowing
down, independently verifying unusual requests, and reporting suspicious
activity.
Businesses in Plymouth, Kingston, Carver, Duxbury, and
throughout the South Shore can strengthen cybersecurity by making these
behaviors part of everyday work rather than treating security awareness as a
once-a-year training exercise.
Frequently Asked Questions
What are the most common signs of a phishing attack?
Common warning signs include an unexpected request, unusual
urgency, pressure to bypass normal procedures, requests for credentials or
authentication codes, unexpected attachments or login links, changes to payment
instructions, and messages that seem out of character for the supposed sender.
Spelling mistakes can still be clues, but employees should
not depend on them. Modern phishing messages can be polished and convincing.
Can phishing happen through text messages or phone calls?
Yes. Phishing and social-engineering attacks can arrive
through email, text messages, phone calls, social media, collaboration
platforms, QR codes, and other communication channels. Employees should focus
on the nature of the request rather than assuming a particular communication
method is safe.
How should an employee verify a suspicious email?
Use a communication method independent of the suspicious
message. Call the person using a number you already know, start a new message
through a trusted channel, or contact a supervisor or IT.
If the email requests a payment change, password,
authentication code, or sensitive information, don't use the contact
information contained in the suspicious message itself to perform the
verification.
Why do cybercriminals target small businesses in
Plymouth?
Cybercriminals do not have to specifically choose a Plymouth
business in advance. Many phishing, credential, and social-engineering attacks
can be sent at scale, while more targeted attacks can use publicly available
information to identify employees, executives, vendors, and normal business
relationships.
Small and midsize businesses can therefore be attractive
targets when attackers believe normal business processes can be manipulated to
gain credentials, access, information, or money.
How often should employees receive cybersecurity
awareness training?
Cybersecurity awareness works best as an ongoing business
practice rather than a single annual presentation. Employees should receive
foundational training when they join the organization, periodic refreshers, and
timely education when new threats or business processes create new risks.
Short, practical reminders throughout the year can reinforce
the behaviors employees need most: recognize something unusual, slow down,
verify independently, and report concerns quickly.
