
What follows is a composite scenario, assembled from patterns we see repeatedly rather than any single client. The details are typical. The sequence is accurate. The outcome is more common than most business owners realise.
Week one, Thursday, 4:52 PM
Dana handles accounts payable at a twenty-two person firm in Folsom. She’s been there six years, she’s careful, and she has never once fallen for anything.
At 4:52 on a Thursday she receives an email that appears to come from the company’s Microsoft 365 administrator. Her password expires today, it says, and she needs to update it before the weekend or she’ll be locked out Monday morning.
The link goes to a page that looks exactly like the login screen she uses every day. Same layout, same logo, same colours. She enters her current password, then a new one. The page accepts it and redirects her to the real Microsoft 365 site, which is already logged in from her browser session.
She assumes it worked. She closes the tab and goes home.
Nothing appears to have happened. That is the entire design.
There’s no error, no alert, no warning. Dana has no reason to mention it to anyone, because in her experience she completed a routine task. The one detail she’d have needed to notice — that the URL was subtly wrong — is exactly what nobody checks at ten to five on a Thursday.
Weeks two and three: silence
For the next seventeen days, nothing observable occurs.
Inside Dana’s mailbox, someone is reading. Not downloading, not disrupting, not doing anything that would show up as unusual activity to a system nobody is watching. Just reading.
They learn who the firm’s suppliers are. They learn that Dana processes payments on Thursdays. They learn the name of the operations manager who approves anything over $10,000, and roughly how he writes — short sentences, no greeting, signs off with just his initial.
They find a thread about an ongoing project with a supplier the firm has used for four years. Payment terms, invoice schedule, contact names, the lot.
Then they set up a mail rule. Any incoming message containing that supplier’s domain gets automatically moved to a rarely-used folder and marked as read. Dana will never see those emails again, and she has no reason to look for something she doesn’t know is missing.
This period is called dwell time, and it’s where the outcome is decided. In a monitored environment, a login from an unfamiliar location, or the creation of an unusual mail rule, produces an alert. In an unmonitored one, seventeen days pass exactly like any other seventeen days.
Week four, Tuesday, 9:14 AM
The invoice arrives.
It comes from the supplier’s genuine email address — because the attacker has, by now, also compromised an account at the supplier’s end, or has spoofed it convincingly enough that it passes every check. It references the correct project. The amount, $84,000, matches what the firm was expecting for this stage of the work.
One thing has changed. A short line near the bottom notes that the supplier has recently changed banks, and provides updated account details.
Dana has processed nine invoices from this supplier. Nothing about the message strikes her as unusual, because nothing about it is unusual except the account number.
Week four, Tuesday, 10:31 AM
She forwards it for approval.
The operations manager sees an invoice from a known supplier, for an expected amount, on a project he’s familiar with. He replies with a single word: approved.
He does not notice the bank details, because bank details are not what anyone reads on an invoice they were expecting. He’s approved this supplier’s invoices before. He’s looking at the amount and the project code.
Week four, Tuesday, 2:47 PM
The payment goes out.
By Wednesday morning the funds have moved through two intermediary accounts. By Thursday they’re gone in any practical sense — recovery at that point depends on speed, and nobody yet knows anything is wrong.
Week six, Monday, 11:20 AM
The supplier calls to ask about the outstanding invoice.
That call is the first anyone at the firm learns that anything happened. Not a security alert. Not a system warning. A confused phone call from someone wondering why they haven’t been paid, thirteen days after the money left.
The next three weeks involve the bank, the insurer, a forensic investigation to establish what the attacker accessed beyond the payment thread, and a difficult conversation with the supplier about a relationship that has become awkward.
The insurer’s first question is whether Multi-Factor Authentication was enforced on all accounts.
It was enforced on most.
Four moments where this stopped being inevitable
Reading it back, the striking thing is how ordinary every step was. Nobody was careless. Nobody ignored a warning. The attack worked precisely because it never asked anyone to do something they wouldn’t normally do.
But there were four points where it could have ended differently.
Moment one: Thursday, 4:52 PM
If Multi-Factor Authentication had been enforced on Dana’s account, the stolen password would have been worth nothing. The attacker would have had valid credentials and no way to use them.
This is the single highest-value control available to any business, and it directly prevents the attack described here. The failure in this scenario wasn’t absence — it was partial coverage. MFA had been rolled out to most staff, with a handful of exemptions granted to people who found it disruptive during a busy period.
Attackers specifically look for the accounts that were left out. Finding them is rarely difficult.
Moment two: the seventeen days of silence
A login from an unfamiliar location. The creation of an unusual mail forwarding rule. Access at hours the account holder doesn’t normally work.
Each of these produces an alert in a monitored environment. Each passed unnoticed here, because there was nobody watching — not through negligence, but because reactive support has no mechanism for noticing things that aren’t causing visible problems.
Seventeen days is a long time to catch something. That window existed and nobody was looking through it.
Moment three: Tuesday, 9:14 AM
The invoice contained new bank details.
A written procedure requiring any change to payment or banking information to be verified by telephone — using a number already on file, never one supplied in the email requesting the change — would have ended this in about ninety seconds. Dana calls the supplier’s known number. The supplier says they haven’t changed banks. The invoice goes in the bin.
This control costs nothing. No software, no licence, no installation. It requires one written rule and a team that knows it applies without exception, including when the request appears urgent and especially when it comes from someone senior.
It is, by a considerable margin, the cheapest thing on this page and the most frequently absent.
Moment four: Tuesday, 10:31 AM
The approval step was a real safeguard that didn’t function as intended.
Approval was checking the amount and the project, which is what approval usually checks. Nobody had told the operations manager that his job included verifying bank details, because nobody had thought about it in those terms.
A safeguard only works if the person operating it knows what they’re actually looking for.

What training would have changed
It’s worth being precise here, because “we should do security training” is easy to say and easy to do badly.
A generic annual session covering phishing awareness would probably not have saved this firm. Dana knew about phishing. She’d have told you confidently that she’d never click a suspicious link — and she was right, because the link she clicked wasn’t suspicious.
What changes outcomes is narrower and more practical:
Recognising the specific pattern. Not “be careful of phishing” but “any message asking you to log in from a link deserves a pause, and the correct response is to open the application directly instead.”
Knowing the payment rule exists and applies always. Written down, understood by everyone who touches payments, and explicitly immune to urgency and seniority.
Understanding that nothing visible happens. This is the piece almost nobody knows. Most people assume they’d realise if they’d been caught. Knowing that a successful credential theft produces no symptom at all changes how seriously someone treats a moment of doubt.
Reporting without fear. If Dana had thought, even briefly, that was slightly odd — and had a blame-free way to mention it — the entire chain ends on Thursday evening. Teams that report give you warning. Teams that stay quiet leave you blind.
Short sessions, repeated a few times a year, built around examples that look like your actual suppliers and your actual software. That’s what shifts behaviour. Two hours in January does not.
The uncomfortable arithmetic
The firm in this scenario lost $84,000 directly. Add the forensic investigation, the legal advice, the staff time consumed over six weeks, and the insurance excess, and the real figure sits meaningfully higher.
Against that, the four controls that would have prevented it:
Enforcing MFA on the remaining accounts — an afternoon’s work, no ongoing cost beyond what was already being paid.
Continuous monitoring — a fixed monthly cost, and the thing that would have caught the mail rule.
A written payment verification procedure — free.
Quarterly staff training — modest, and the same investment that reduces every other category of risk simultaneously.
That comparison is the whole argument, and it’s the reason this conversation belongs on an ordinary Tuesday rather than after a phone call from a confused supplier.
What Folsom businesses should take from this
Business email compromise takes more money from firms of this size than ransomware does. It attracts less attention because there’s no dramatic screen, no ransom note, nothing that photographs well for a news story. Just a payment that went to the wrong account and a relationship that got harder.
The defence isn’t complicated. It’s Multi-Factor Authentication with no exemptions, somebody watching for unusual account behaviour, a payment verification rule that everyone follows, and a team that knows what the attack actually looks like.
Our cybersecurity services cover the technical layers, and our managed IT services provide the monitoring that would have made those seventeen quiet days visible. But the single most valuable item on the list still costs nothing at all, and you could implement it before lunch.
Start with the free one
Whatever else you do after reading this, write down the payment verification rule and tell everyone who handles money that it applies without exception.
Then find out, this week, whether Multi-Factor Authentication is genuinely enforced on every account in your business — or enforced on most, with a few exceptions granted during a busy period that nobody has revisited since.
That second question is where most firms find their version of Dana’s account.
Book an appointment and we’ll go through your accounts properly, identify the exemptions nobody remembers granting, and set up the monitoring that turns seventeen silent days into a same-day alert. Call 209-920-4077 or choose a time here — it’s a conversation, not a sales pitch.