Please ensure Javascript is enabled for purposes of website accessibility

A First Look at Fresno State’s Quarterback Battle

2 days ago

Israeli Columnist Alleges Ethnic Cleansing Plan in Gaza

2 days ago

Tesla to Roll out Bay Area Robotaxis With Safety Drivers, Report Says

2 days ago

Thailand and Cambodia Exchange Heavy Artillery Fire as Border Battle Expands

2 days ago

California Cannot Require Background Checks to Buy Ammunition, US Appeals Court Rules

3 days ago

TikTok Will Go Dark in US Without Chinese Approval of Sale Deal, Lutnick Says

3 days ago

Fresno County Authorities Still Searching for Missing Mother and Infant

3 days ago
Holidays Bring Phishing Scam Surge Aimed at Small Business
gvw_ap_news
By Associated Press
Published 6 years ago on
December 4, 2019

Share

NEW YORK — The email looked legitimate, so Danielle Radin clicked on the link it contained, expecting to have her products included in a holiday gift guide.
“I instantly regretted it,” says Radin, owner of Mantra Magnets, a website that sells wellness products. “It took me to some random website that looked like those pop-ups telling you that you’ve won the lottery.”

“In the last year or two they’ve been running more professional campaigns. It can take a couple of minutes for me to determine that they’re phishing scams. That tells me they’re doing a very good job.” — Perry Toone, owner of Thexyz, an email service provider based in Toronto
Within days of that click three weeks ago, Radin began getting notifications that people in Ecuador, China and elsewhere were trying to access her email account. She wasn’t surprised; she knew her San Diego-based small business had been the target of a phishing scam.
While cybercriminals strike at any time of the year, they’re particularly active during the holiday and income tax filing seasons when computer users expect to see more emails — and scammers are increasingly targeting individual small businesses with phishing scams, sending messages that look legitimate but do harm instead. An unsuspecting owner or employee clicks on a link or attachment and like Radin finds that malicious software has invaded their PCs.
Cybersecurity experts find that criminals who used to blanket thousands of computer users in hopes of fooling a handful have refined their methods. Scammers find small businesses through websites, social media sites and by combing email address books. They also mine personal data from breaches at retailers and other large companies. Then, using a process called social engineering, they construct emails that increasingly look realistic, as if they truly come from a boss, colleague, friend, potential client or vendor, a bank and even the IRS.
“In the last year or two they’ve been running more professional campaigns,” says Perry Toone, owner of Thexyz, an email service provider based in Toronto. “It can take a couple of minutes for me to determine that they’re phishing scams. That tells me they’re doing a very good job.”

Computer Users May Not Be Looking as Closely as They Should at an Email

Radin believes the scammers found her through her website or a blog. Like many small businesses, she has an email address on her site, and the scammers figured out that she might be interested in selling via a holiday gift guide. But finding a target is one thing; the scam won’t work unless it tricks an email recipient into clicking. Even those who are tech savvy can sometimes let their guard down. Radin was duped even though she’s the author of “Everyone’s Been Hacked,” a book sold online.
Often a scam succeeds because there’s just a shred of doubt in a computer user — the email is realistic enough that an owner or employee feels they need to read it. Sometimes a staffer clicks out of fear or a sense of responsibility, says Rahul Telang, a professor of information systems at Carnegie Mellon University’s Heinz College.
“It might not sound very personal, but you have an idea that you should go ahead — you feel like the email is coming from the boss,” he says.
Computer users may not be looking as closely as they should at an email — there can be subtle signs that a message is trouble. Terry Cole, owner of Cole Informatics, a company whose work includes cybersecurity, recalls getting an email that truly seemed to be from a colleague. He was one of several people in the industry to receive it.
“It said that this colleague had sent me a secure private message that was ready for me to read and included a link to click. This was absolutely consistent with my normal experiences communicating with him,” says Cole, whose company is located in Parsons, Tennessee.
Cole didn’t do in that instance what he usually does and advises everyone to do: check the email address to be sure it’s completely correct. When he clicked on the link, it took him to a bogus website claiming to be connected with Microsoft and asking him for his ID and password. He went no further and suffered no damage to his PC.

A Scam Succeeds in Getting an Employee to Click on a Personal Email While on a Company PC

The holidays provide scammers with extra opportunities: emailed greeting cards, package shipment notices, offers of discounts — all of them false. Cybercriminals also seek personal information from owners and employees under the guise of needing them to create a W-2 or 1099 tax form; at this time of year, business owners’ thoughts are turning to taxes.

“Something that claims to know you, your name, where you work and wants you to take some action is harder to spot.” Sherrod DeGrippo, senior director of threat research and detection at Proofpoint, a cybersecurity company based in Sunnyvale
“Something that claims to know you, your name, where you work and wants you to take some action is harder to spot,” says Sherrod DeGrippo, senior director of threat research and detection at Proofpoint, a cybersecurity company based in Sunnyvale, California.
A common scam at holiday time is an email purportedly from the boss telling a staffer to go buy gift cards and email the numbers back, DeGrippo says.
“When it appears to come from a boss or CEO, I think there is that tendency among employees to follow those directions. They’re playing on their emotions,” she says.
Often, a scam succeeds in getting an employee to click on a personal email while on a company PC — many workers check their personal email while at work. Even though the email came through on a personal message, it’s the company’s machine that can be infected.
Companies can protect themselves in part by restricting employees’ access to personal email sites, Telang says. He also suggests seminars to help staffers understand the risks that even legitimate-looking emails can present.
Some of the scams aim at monitoring a user’s keystrokes. So anyone accessing a company or personal account of any sort can be giving a criminal access to their money or sensitive personal data. One tool to prevent a bank account from being emptied or a credit card maxed out is to have accounts with multifactor authentication; that requires a password and a separate code sent to a different device and that is different for each login.

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

California School Board Resigns After Audit Reveals $180M in Improper Funding

DON'T MISS

NASA Says 20% of Workforce to Depart Space Agency

DON'T MISS

Frustration, Gaza Alarm Drove Macron to Go It Alone on Palestine Recognition

DON'T MISS

Trump Golfs in Scotland as Epstein Questions Persist

DON'T MISS

Visalia Police Arrest Armed Robbery Suspect at Long John Silver’s

DON'T MISS

Grand Rising Brings Sober Day Party Vibes to Fresno

DON'T MISS

Jack McAuliffe, Who Started a Craft Beer Revolution, Dies at 80

DON'T MISS

Fresno Crash Leaves One Dead After Car Submerges in Canal

DON'T MISS

Lemoore Farmers Fed Up With Lack of Representation on Groundwater Agency

DON'T MISS

‘Jenny from the Block’ Rescued After Camping Out by Calwa ATM

UP NEXT

Trump Golfs in Scotland as Epstein Questions Persist

UP NEXT

US Judge Reaffirms Nationwide Injunction Blocking Trump Executive Order on Birthright Citizenship

UP NEXT

White House Will Release $5.5 Billion for Schools, After Surprise Delay

UP NEXT

US States to Get $608 Million From FEMA to Build Migrant Detention Centers

UP NEXT

Trump: Strong Dollar Sounds Good but ‘You Make a Hell of a Lot More’ With a Weaker One

UP NEXT

Trump Says US May Not Have a Negotiated Trade Deal With Canada

UP NEXT

Trump Says There Is a 50-50 Chance of Trade Deal With EU

UP NEXT

Amid Epstein Furor, Ghislaine Maxwell Seeks Relief From US Supreme Court

UP NEXT

US Justice Department Official Meets Epstein Associate Maxwell

UP NEXT

Lara Trump Skips North Carolina US Senate Race, Clears Way for Cooper Versus Whatley

Trump Golfs in Scotland as Epstein Questions Persist

21 hours ago

Visalia Police Arrest Armed Robbery Suspect at Long John Silver’s

21 hours ago

Grand Rising Brings Sober Day Party Vibes to Fresno

21 hours ago

Jack McAuliffe, Who Started a Craft Beer Revolution, Dies at 80

21 hours ago

Fresno Crash Leaves One Dead After Car Submerges in Canal

21 hours ago

Lemoore Farmers Fed Up With Lack of Representation on Groundwater Agency

22 hours ago

‘Jenny from the Block’ Rescued After Camping Out by Calwa ATM

22 hours ago

Tulare Officer Injured in Crash While Trying to Save Unresponsive Infant. Child Dies at Hospital

2 days ago

PBS Has a Future by Leaving the Past Behind: Opinion

2 days ago

Fresno Council Candidate Rassamni Says City Is Investigating Him Amid Allegations by Arias

2 days ago

California School Board Resigns After Audit Reveals $180M in Improper Funding

The entire board of directors overseeing Highlands Community Charter and Technical Schools in Sacramento has either resigned or been removed...

18 hours ago

The entire board of Highlands Community Charter in Sacramento stepped down after a state audit found the school improperly received over $180 million and engaged in questionable spending. (Shutter
18 hours ago

California School Board Resigns After Audit Reveals $180M in Improper Funding

The NASA logo is seen at Kennedy Space Center in Cape Canaveral, Florida, U.S., April 16, 2021. (Reuters File)
21 hours ago

NASA Says 20% of Workforce to Depart Space Agency

Egypt's President Abdel Fattah al-Sisi and French President Emmanuel Macron visit a ward for Palestinian patients at El Arish Hospital, close to the border with the Gaza Strip, in Arish, Egypt April 8, 2025. Ludovic Marin/Pool via REUTERS
21 hours ago

Frustration, Gaza Alarm Drove Macron to Go It Alone on Palestine Recognition

U.S. President Donald Trump golfs at Trump Turnberry resort in Turnberry, Scotland, Britain, July 26, 2025. (Reuters/Phil Noble)
21 hours ago

Trump Golfs in Scotland as Epstein Questions Persist

Noah Robinson, 38, was arrested after allegedly robbing a Visalia Long John Silver’s at knifepoint and attempting to flee through nearby backyards with $110 in stolen cash on Friday, July 25, 2025. (Visalia PD)
21 hours ago

Visalia Police Arrest Armed Robbery Suspect at Long John Silver’s

21 hours ago

Grand Rising Brings Sober Day Party Vibes to Fresno

Craft Brewer Jack McAuliffe With Jim Koch of Samuel Adams
21 hours ago

Jack McAuliffe, Who Started a Craft Beer Revolution, Dies at 80

fresno
21 hours ago

Fresno Crash Leaves One Dead After Car Submerges in Canal

Help continue the work that gets you the news that matters most.

Search

Send this to a friend