On June 1, Microsoft tracked a single business email compromise campaign that reached more than 67,000 people across 42,000 organizations in about three hours.
Not a person picking targets. A script.
Here's the part worth your attention: most of those emails asked for nothing. Microsoft found that 87 to 92 percent of first-contact messages were something forgettable — "Are you at your desk?" No link, no attachment, no wire request. Nothing a filter would flag.
The ask comes later, once you've replied and the thread looks like a real conversation. And often the attacker is already sitting inside a mailbox — a vendor's or a client's, not yours — reading how your firm actually talks about money.
I've watched this land. The email arrives from a real address, references a real account, and shows up the week a client is expecting a transfer. Your operations person isn't being careless. They're being helpful, which is what you hired them for.
What stops it isn't a smarter filter. It's a rule nobody is allowed to skip: any change to wire or payment instructions gets confirmed by phone, on a number you already had on file. Pair that with sign-in protection that survives a stolen session, and an alert when someone quietly creates an inbox rule that deletes mail.
None of that is expensive. Worth reviewing before your next cyber renewal.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email