Skip to content
Keep credentials secure
phishing cybersecurity small business

How Credentials Get Stolen

TechKnowledge
TechKnowledge

 

How do Credentials Get Stolen? It’s easier than you may think.

Most small business owners don’t realize the level of sophistication, research, and social engineering that goes into a modern cyberattack, especially when it comes to stealing credentials (user ID and passwords).

Today’s phishing attacks look clean, make sense, feel normal, and many are successful. Criminals research our behaviors; they know who we are and how we’ll react. Their messaging is deliberately timed and designed to get us moving quickly, get us flustered, or even lull us into a false sense of security so that we stop thinking, react and execute.

Think your credentials are secure? Run a secure scan at www.HaveIBeenPwned.com and find out.

In the meantime, here are three sample attacks designed and socially engineered specifically to hit the small business. Would you have been compromised?

1. The Shared File That Needs Review

You get an email from an already compromised client. You believe the email address to be real, not realizing the client was breached on a prior attack a few weeks ago, and the hacker was able to create a fake email in their corporate domain.

The message explains that there's a shared document, and refers to an update in their payment processing. It doesn’t feel random. It feels like business, like something you need to look at. So you click through what appears to be a secure link and the document almost opens, but there’s an issue. You X out and try again. Same thing. You try once more, and this time you’re prompted for your Microsoft login.

“This is so aggravating,” you think. But you enter your credentials and approve the MFA prompt.

From your side, the document opens and nothing seems strange. It’s actually a pretty straight forward document on confirming payments by email.

But the attacker has what they need. The credentials you provided gives the attacker access to your email account, and all the conversations and information flowing through your business.

2. IT Is Here to Fix the Problem

You and a few employees have been getting blitzed with suspicious emails for weeks. It’s annoying. You’re tired of hearing about it. But everyone knows the routine: don’t click, delete, move on.

Then, one random Thursday evening, you’re enjoying a bit of down time and maybe a nice drink when your phone rings. It registers Microsoft.

You answer, and a kind support person explains they’re calling about the email attack your business has been experiencing. Good news — they can help end the madness!

They just need to send you a secure Microsoft link so you can verify your account and update your security settings.

The email arrives while they’re on the phone and they talk you through it – click, enter your credentials, approve the MFA, and you just handed over the keys to your business.

The fake emails were the setup. The phone call was the close and the timing of the close was no accident. It’s quiet time for you, and these criminals know businesses owners hate quiet time. This is your chance to knock something off your list, while enjoying a drink and be the hero…. careful!

Remember, just like your work, security should follow you everywhere!

3. The Vendor Password Reset That Wasn’t

Your employee gets an email from a vendor.

Maybe it’s your payroll company. Maybe it’s your accounting platform. Maybe it’s an industry-specific system your business uses every week, and again, the message looks real. The logo’s correct. Your company name is there. Their name is there. Maybe even an account number, invoice number, or real support case.

The problem is the vendor doesn’t yet know they’ve had a data issue and an account yielding customer information was exposed. Not a ton of data, enough pieces of the puzzel to make things feel normal. On email, criminals don’t need much. 

The message says that due to a recent security update, all users must reset their password by the end of the day to avoid losing access.

The employee’s busy. They need that system. Payroll may be coming up. Invoices may be going out. Whatever the case, the attackers have likely socially engineered the email to your employees weak spot. They know what’s in your staffer’s head and they’re gonna exploit it.

So they click. The page looks legit. They enter their current password and create a new one. Maybe they even get an MFA prompt.

Now the attacker has an old password, a new password, and possibly access to the real system. Also, if that's a reused password, there's no t

So, What Can Be Done?

Simple answer - stop. Take a beat. Don’t ever enter your credentials unless you’re the one who initiated the process. That is the most important thing you can do.

The next is of course letting your people know that it's ok to go slow, as we wrote about in our blog on cybersecurity training. Too many owners assume their people know what to do and will be cautious. We know you hire good people, but that doesn't mean they wont make a mistake. 

Know your risk. Protect what you’ve built. There are many security tools and software packages to help end-users in this very hand-to-hand combat style of attack. Some cost more than others and some require more setup and customizations. Do your research, find what works for you, or fill out the form below if we can be a resource.

How can we help?

Enjoyed our perspective? Share it with your network.