← Back to Blog

5 Phishing Emails That Fooled Small Business Owners This Month

Modern phishing doesn't look like the scams you remember. Here are five real attacks that fooled small business owners this month. A construction firm, a solo accountant, a real estate agent, a marketing agency, and a dental practice and the red flags that would have stopped them.

Phishing in 2026 is sharper than it used to be. Today's attacks are crafted by AI, sent from legitimate infrastructure, and hit finance inboxes on Friday afternoons when everyone's rushing to clear their desk before the weekend.

The FBI reported $2.7 billion in business email compromise (BEC) losses in 2024 alone. Behind every number is a real small business; a dental practice, a real estate agency, a solo law firm that clicked the wrong link or wired money to the wrong account.

Here are five real scams that got through in the past month, with the details changed to protect the victims. If you run a small business, you've probably seen something similar sitting in your inbox this week.


1. The "Updated Bank Details" Email From a Trusted Vendor

Who got hit: A 12-person construction firm in Texas.

What they saw: An email from their long-standing concrete supplier, with the usual signature, logo, and friendly tone. The message said the supplier had changed banks and included new wire transfer details for the next invoice.

What actually happened: Attackers had compromised the supplier's email account two weeks earlier and were quietly reading the message history. When the next invoice was due, they sent the "update" from a look-alike domain — concretesupply-co.com instead of the real concretesupplyco.com. The finance manager didn't notice the extra dash.

The loss: $47,000 wired straight to the attacker. By the time anyone called to confirm, the funds were already routed through three countries.

The red flag: The sending domain. A single character difference in a domain name is the most common BEC trick there is. If a vendor changes payment details, always verify by calling a number you already have on file and never the number in the email.


2. The Microsoft 365 "Password Expiring" Warning

Who got hit: A solo practising accountant in Manchester.

What they saw: A clean-looking email from "Microsoft Account Team" saying her password was about to expire and she needed to click through to keep her account active. The landing page looked identical to the real Microsoft login.

What actually happened: She entered her credentials. The attacker immediately logged into her Microsoft 365 account, set up an auto-forwarding rule to a Gmail address, and started watching every email coming in. Two weeks later, when a client asked about a tax refund payment, the attacker intercepted the thread and redirected the refund to their own account.

The loss: £8,400 intercepted. Worse, her client relationships took months to rebuild.

The red flag: Microsoft doesn't ask you to "verify your account" via email links. Password expiry notifications come from inside Microsoft 365 itself, not as an external email. And the sending address, if you'd looked, ended in .onmicrosoft-security.com — not a real Microsoft domain.


3. The Fake DocuSign "Agreement Ready for Signature"

Who got hit: A 4-person real estate agency in Florida.

What they saw: A DocuSign email saying a purchase agreement was ready for the agent's signature. The branding was perfect. The sender was "DocuSign via dse.docusignmail.com".

What actually happened: The agent clicked through and was taken to a convincing Microsoft 365 login page (not DocuSign, that was the tell). She entered her work email password. The attacker immediately pulled her contact list, found a pending property sale worth $340,000, and sent the buyer "updated wire instructions" for the closing deposit.

The loss: The buyer's $34,000 earnest money deposit went to the attacker. The sale still closed, but the buyer had to come up with the deposit twice. The agency lost the client.

The red flag: DocuSign never asks you to sign into Microsoft or Google to access a document. If clicking a link takes you to a login page for a different service than the one that sent the email, close the tab immediately.


4. The "CEO Urgent Favour" Text-Style Email

Who got hit: A 20-person marketing agency in London.

What they saw: A short email from the founder's name to the office manager:

"Are you at your desk? Need a quick favour, in a meeting can't talk. Let me know when you're free."

No signature, no logo, just a casual ask. When the office manager replied "sure, what do you need?", the follow-up was:

"Need you to grab £400 in Apple gift cards for a client thank-you gift. I'll reimburse you today. Send the codes over once you have them, I'll explain later."

What actually happened: The attacker had scraped the founder's name from the company's About page on LinkedIn. The sending address was a free Gmail account using the founder's full name as the display name, so the office manager only saw "Sarah Mitchell" in her inbox — not the actual Gmail address behind it.

The loss: £400 in gift card codes, gone. Small compared to the others on this list, but the office manager was mortified and the company had to rebuild internal verification processes from scratch.

The red flag: Any request involving gift cards is almost always a scam. Legitimate businesses don't buy gift cards for client gifts via their office manager's personal card, and any executive asking you to do something "urgent and quiet" is either a scammer or a bad boss. Verify with a quick phone call or a Slack message on a different channel.


5. The QR Code "Voicemail From HR" Email

Who got hit: A mid-sized dental practice in Chicago.

What they saw: An email supposedly from their HR system saying a voicemail had been left for the office manager. Instead of a link, the email contained a QR code with the instruction to "scan to listen on your phone".

What actually happened: The QR code took her phone browser to a fake Microsoft login page. Because the attack moved from her work computer (which had endpoint protection) to her personal phone (which didn't), none of the practice's security tools saw it happening. She entered her credentials. The attacker used her M365 access to send phishing emails to every patient in the contact list, pretending to offer refunds for overpaid dental bills.

The loss: No direct financial loss for the practice, but dozens of patients got phished through them. Reputational damage took months to recover from.

The red flag: QR codes in emails are almost always suspicious. Real companies link directly. The reason attackers use QR codes is specifically to move you off your monitored work device and onto your unprotected phone. If you have to scan a QR code to read an email, don't.


The Common Thread

Every one of these scams relied on the same thing: a moment of inattention at a busy time. None of them required the victim to be careless or untrained. They required them to be human — glancing at an email between meetings, trusting a familiar name, wanting to be helpful to a boss.

Modern phishing isn't caught by reading emails more carefully. The signals have moved into places the human eye can't easily see: sender IPs, authentication results, domain age, reply-to mismatches, hidden link destinations.

That's exactly why we built InboxXray. Paste any suspicious email's headers into the tool (or upload an .eml file) and you get a plain-English security report in seconds. SPF, DKIM, DMARC, URL reputation, brand impersonation checks, the whole lot.

For Gmail, Outlook and Yahoo Mail users, the InboxXray browser extension brings the same checks straight into your inbox. One click on any suspicious email and you get an instant safety verdict without leaving your mail client. Available free for Chrome, Firefox, and Edge.

If one of the five scams above had landed in your inbox this month, would you have caught it in time?

Check a suspicious email now →