Could Someone Talk Your Bookkeeper Into Wiring $100,000 to a Criminal?

Most business owners answer that question with "probably not." Then they think about it for a second and change their answer to "I honestly don't know."

That's the right answer. And it's the reason this test exists.

Book My $100K Fraud Test Call Now: 760-992-5562

 

How It Actually Happens

A manager gets an email from a vendor the company deals with every month. Right name, right company, right logo, an invoice with a link to view it. He clicks. A Microsoft sign-in page loads — correct logo, correct layout, padlock in the address bar. He types his email and password, gets back to work, and never looks at the address bar closely enough to notice the domain is off by a single character.

He just handed his credentials to a stranger.

Nothing happens for eleven days.

During those eleven days the attacker is reading his mailbox. Not stealing anything — learning. Who approves payments. How invoices are worded. Which vendors are due. When the owner travels. He creates a rule that quietly moves certain replies into a folder nobody opens, so the real vendor's emails never show up.

On day twelve he sends one message from that mailbox to the company's largest customer, with a friendly note about updated banking details for the next payment. The customer pays. To the right company, apparently, from the right email address, on a normal Tuesday.

Nobody's computer was hacked. No virus was installed. The antivirus was running the entire time and had nothing to report, because nothing malicious ever ran. A person logged in with a valid password and then behaved patiently.

Three weeks later the real vendor calls about the invoice that never got paid, and the conversation everybody dreads begins.

What I've Watched Happen Here

I'm Noah Yaghoubian. I've been doing IT in this valley since 2010, and everything below is something I've either cleaned up after or watched happen to a business down the road. No names, for obvious reasons. But these are real companies, real amounts, and real people who run businesses like yours.

  • An HVAC company lost more than $50,000. Hacked email account, changed payment instructions.
  • A roofing company lost around $70,000. Same pattern.
  • An electrical contractor lost upwards of $70,000. Same pattern again.
  • A nonprofit lost $30,000. Money that was supposed to go to their mission.
  • A financial services company lost over $50,000 in a single transfer. They'd cut corners on computer security. A trojan sat on the CFO's machine watching him work, and when he logged into the company's bank account, the attacker was watching every keystroke. He got in and wired the money out in one move.
  • A distribution company lost $600,000. Their own systems were fine. It was their customer who got hacked. The attacker waited for exactly the right moment, sent an email changing the payment instructions, and the staff didn't follow the verification process — because nobody had ever trained them on one.

Every one of these came down to the same three things: an email account somebody got into through a phishing link, a wire or EFT that nobody verified, and staff who were never trained on a process to protect themselves.

How Far They'll Go

One case is worth telling in full, because it changed how I think about this.

An attacker got into a company's email. Sent the perfectly timed message changing EFT instructions — normal enough. But then he also mailed a physical letter. On what looked like company letterhead. With the real logo. The real street address. Confirming the new banking details in writing.

And a phone number to call and verify.

His phone number.

Think about what that means. Somebody at the receiving company did the responsible thing. They didn't just trust the email. They picked up the phone and called the number on the official-looking letter to confirm — and reached the criminal, who cheerfully confirmed everything.

That's the level of effort now. Not a typo-riddled email from a foreign prince. Printed mail, matched branding, and a verification line staffed by the person stealing from you.

And Here's Why They Keep Doing It

Because they know how it usually ends.

Some of these companies had cyber insurance. Some had wire fraud coverage specifically. Some had neither. Some called the police. Some called their bank the same day.

Most of them got nothing back.

Wire transfers move fast and are extremely difficult to reverse once the money lands. Local police generally aren't equipped to chase funds that left the country in minutes. Banks will try, but their obligation is limited when the transfer was authorized by your own employee using valid credentials.

That's the whole business model. Attackers target small and mid-sized companies precisely because they know the money will be gone, the recovery will fail, and most owners will absorb the loss quietly and never talk about it publicly.

Which is why nobody warns you before it happens. That's what this page is for.

This Is the Second Most Expensive Crime in America

Not ransomware. This.

According to the FBI's Internet Crime Complaint Center, business email compromise accounted for $3.05 billion in reported losses in 2025 across 24,768 complaints — the second-costliest category of cybercrime in the country, behind only investment fraud. Reported losses are only the ones somebody filed a complaint about, so the real number is higher.

And it's getting easier for them. The FBI's 2025 report documented AI-driven fraud for the first time: more than 22,000 complaints referencing artificial intelligence, with roughly $893 million in losses. The badly written scam email with the odd grammar is gone. Now the email is well written, in your vendor's voice, and sometimes the follow-up phone call is a cloned voice too.

The national numbers just confirm what we already see locally: this attack doesn't care how big you are. There's no server to break into and no software to defeat. There's a person, an inbox, and a payment process. A twelve-person company is as easy as a twelve-hundred-person company, and often easier.

Why the Things You Already Have Don't Stop It

1 YOUR ANTIVIRUS The login page is a spoofed website on an attacker-owned domain — the FBI describes these as legitimate domains altered slightly, like a zero instead of the letter O or .co instead of .com. Correct logo, and a padlock that only proves encryption, not ownership. Nothing installs, so antivirus has nothing to scan. Then the attacker signs into the real Microsoft 365 with those credentials, and that login looks like an employee arriving at work.
2 YOUR SPAM FILTER Most filters catch bulk junk. A targeted email written specifically for your company, referencing a real vendor and a real invoice, with no attachment and no obvious bad link, sails straight through. Some of these arrive from a genuine vendor mailbox that was compromised first.
3 YOUR CURRENT IT COMPANY Possibly they've got this covered. But most IT providers secure devices and networks, and this attack happens in an inbox and in your accounting procedures. Ask yours when they last checked your mailboxes for hidden forwarding rules. The answer will tell you a lot.
4 YOUR CYBER INSURANCE Fraudulent transfer coverage is frequently a separate add-on rather than part of a base cyber policy. And carriers investigate claims against the answers you gave on your application. If multi-factor authentication was missing on one account, that becomes their argument.

What the FBI and Microsoft Say to Do About It

The stories above are mine. This part isn't — and it shouldn't be. When it comes to what actually protects you, you shouldn't take an IT company's word for it. You should take the FBI's and Microsoft's, and then find an IT company that does all of it.

The FBI publishes a specific list for this exact attack. Their advisory on business email compromise through cloud email services tells businesses to:

  • Enable multi-factor authentication on all email accounts
  • Disable basic and legacy authentication that doesn't support MFA
  • Prohibit legacy protocols like POP, IMAP, and SMTP that can be used to get around MFA
  • Verify all payment changes and transactions in person or via a known telephone number
  • Prohibit automatic forwarding of business email to external addresses
  • Add a banner to messages arriving from outside your organization
  • Configure SPF, DKIM, and DMARC to prevent spoofing of your domain
  • Educate employees on how to identify phishing and what to do if they suspect a compromise
  • Be careful what you publish on your website and social media — job duties, org structure, and out-of-office details are research material

Microsoft is blunter about the first one. Their own research puts multi-factor authentication as blocking more than 99% of account-compromise attacks, and the overwhelming majority of compromised accounts didn't have it turned on. Microsoft has since made MFA mandatory for Azure sign-ins on the strength of that data. They also specifically call out blocking legacy authentication, because older protocols let a stolen password work even when MFA is switched on — the attacker signs in and MFA never fires.

Turn MFA on. It's the highest-value thing you can do this week.

But anybody telling you MFA alone solves this is either behind or selling you something.

The Part Most IT Companies Haven't Caught Up To

MFA used to end the story. Not anymore — and Microsoft has published exactly how.

It's called adversary-in-the-middle. The fake page sits between you and the real Microsoft, passing everything through live. You type your password, you approve the MFA prompt on your phone, you get logged in. Everything works. What the attacker captures isn't your password — it's your session token, the thing that proves you already passed MFA. Microsoft's own description: they intercept the authentication, capture the session cookie, then replay it to impersonate the user with no further MFA prompt.

Your MFA worked perfectly. You approved it yourself. It didn't matter.

Microsoft reported a 146% rise in these attacks in a single year and names business email compromise as the follow-on. The kits sell by subscription, so the attacker needs a credit card, not skill. And once inside, they often register their own MFA method — so changing the password later doesn't lock them out.

It all starts with a domain off by one character. A zero instead of an O. .co instead of .com. Nobody catches it at 4:45 on a Friday.

So What Actually Works

Not one product. Three layers — and the last one holds even when the first two fail.

1 BLOCK THE BAD WEBSITES If the fake page never opens, there's nothing to steal. Browser and DNS filtering stops the lookalike domain before anybody types into it. Most small businesses don't have this layer at all.
2 KEEP HACKERS OUT OF THE EMAIL If they do get a session, they still have to use it — and that shows up as a new device, an impossible location, or a mail rule created minutes after sign-in. Microsoft's detection guidance points at exactly those signals. Our SOC catches it in minutes. Nobody catches it on Monday.
3 MONEY CAN'T MOVE IF NOBODY SENDS IT Assume the worst — they're in the mailbox reading everything. If no banking change happens without a callback to a number already on file, they still don't get paid. That's the FBI's own recommendation, it costs nothing, and it's the only control here that works after the attacker has won every technical round.

Here's the uncomfortable part. The FBI's list is public and has been for years. When we run the Fraud Test, most businesses are missing four or more items on it — usually MFA gaps on a few accounts, legacy authentication still on, no external email banner, and DMARC misconfigured or absent.

Not because anybody was careless. Because nobody was assigned to check.

What the $100K Fraud Test Actually Checks

Most "free cybersecurity assessments" run a scan and hand you a report full of red bars. This isn't that. We walk the FBI's list above against your actual environment, then look at the half nobody else looks at: your payment procedures.

The technology side

  • Multi-factor authentication coverage — Every user, every admin, no exceptions. We find out who's missing it, because it's almost never everybody.
  • Hidden mail rules and forwarding — We look for the rules attackers create to hide their tracks. Finding one means you have an active problem right now.
  • Sign-in history review — Logins from places and devices that don't make sense.
  • Legacy authentication and conditional access — The old protocols that let somebody bypass MFA entirely, and whether they're still turned on.
  • Email authentication records — SPF, DKIM, and DMARC. These determine whether a criminal can send email that appears to come from your domain. Most small businesses have them configured incompletely or not at all.
  • Impersonation and spoofing protection — Whether your system flags an email that claims to be from your owner but isn't.
  • Dark web exposure check — Whether your company's credentials are already for sale from somebody else's breach.

The procedure side — and this is the part nobody else does

  • Who can move money — Who is actually authorized, and who could do it in practice if they were convinced it was urgent.
  • Your vendor banking change process — What happens today when an email arrives saying a vendor's account number changed. Walk us through it honestly.
  • Verification requirements — Whether anybody is required to call a known number before payment details change, and whether that requirement is written down or just understood.
  • Approval thresholds — Whether a second person has to sign off, and at what dollar amount.
  • What your staff would do — If the owner emailed at 4:45 on a Friday asking for an urgent wire, would anybody push back? Would they feel allowed to?

"We test whether a criminal could steal money from your business — not whether you have antivirus."

What You Get

1 A WRITTEN FINDINGS REPORT What we found, in plain English, ranked by what would actually let money leave. Not a scan output with 400 items. The things that matter, and what to do about each one.
2 THE EFT VERIFICATION POLICY Our Electronic Funds Transfer Policy, ready to put your company name on and hand to your finance staff. It's the single control that stops this attack even when the email gets through. You get it whether or not you ever hire us.
3 A CONVERSATION, NOT A PITCH We'll tell you what's solid, what's exposed, and what we'd fix first. If your setup is already in good shape, we'll say so and you'll have spent forty minutes finding that out for certain instead of assuming.
4 NO COST AND NO CONTRACT Free, and there's nothing to sign to get it. We'll be straight with you though: we will follow up afterward, because we'd like to earn your business. If the answer is no, tell us and we'll stop. And if you'd rather take our report to your current IT provider so they can fix what they missed — go ahead. You'll be paying them to get better at the job you already hired them for, but that's your call and we'd still rather you were protected.

Book My $100K Fraud Test Call Now: 760-992-5562

The One Rule That Stops This — Straight From the FBI

This isn't our opinion. It's what the FBI tells businesses to do, and it's the single most effective control against this attack. Give it to your finance staff today:

No employee changes payment instructions based on an email, text, fax, or letter alone. Any banking change requires calling the vendor back on a phone number you already had on file — never a number from the request itself.

The FBI's guidance on business email compromise says to verify payment and purchase requests in person or by calling the person directly, and to verify any change in account number or payment procedures with the person making the request. Their advisories are specific about the phone number: call a known number or the business's main line, not a number provided in the email. One FBI agent put it plainly — don't rely on email alone.

They also flag urgency as a warning sign. Be especially suspicious when somebody is pressing you to move fast. That pressure is the tactic.

That single rule defeats nearly every version of this attack, because the criminal controls the email but not your existing vendor file. It costs nothing. It requires no software. And most businesses in this valley don't have it written down anywhere.

Our Electronic Funds Transfer Policy turns that rule into a real procedure — who verifies, who approves, what gets documented, and how the record is kept. Download it and use it, whether we ever speak or not.

Download the Free EFT Policy Template

How We Actually Stop This

1 SECURITY IS THE FOUNDATION, NOT AN UPSELL All of this is in every managed plan we offer. There's no "security tier" and nothing here is an add-on you can accidentally decline. If you're our client, you have it.
2 WE KILLED A LIVE COMPROMISE IN 2.5 MINUTES An attacker signed into a client's Microsoft 365 with stolen credentials. Session killed, account locked, password reset, hidden mail rules checked — before he read a single email. The question isn't whether somebody gets a password. It's how long they get to sit in the mailbox once they do.
3 THE FAKE SITE NEVER LOADS Browser and DNS filtering blocks spoofed domains before anyone can type into them. And your team gets a visible signal when they're on a legitimate site, so nobody has to inspect a URL character by character on a Friday afternoon.
4 WE FIX THE PROCESS, NOT JUST THE TECH Money leaves through a procedure, not a firewall. Tools, a written verification policy, and trained staff. Any two out of three still loses the money — which is why we look at all three.

Fifteen Minutes Now, or $100,000 Later

That's the actual trade. Every business in the stories above had the same fifteen minutes available before it happened to them.

Here's exactly how it works, so there are no surprises:

Step one — a 15-minute call. We ask a handful of questions about how your company handles email and payments. That's it. At the end of it we'll tell you honestly whether a full assessment is worth your time. Sometimes it isn't, and we'll say so.

Step two — the assessment itself. One to two hours, scheduled when it suits you. We walk the FBI's list against your actual environment, review how money moves through your company, and hand you written findings plus the Electronic Funds Transfer Policy ready to use.

What it costs you: Nothing. No contract, no commitment, no obligation to buy anything afterward. You keep the findings and the policy either way.

What it costs to skip it: Ask the roofing company. Ask the nonprofit. Ask the distributor who lost $600,000 because their customer got hacked and nobody made a phone call.

The businesses that lost the money weren't careless. They just never got around to checking. Fifteen minutes is all it takes to stop being one of them.

Book My $100K Fraud Test Or Call Now: 760-992-5562

Fifteen-minute qualifying call first. Full assessment runs one to two hours. No cost either way.

Frequently Asked Questions

What does the $100K Fraud Test cost?

Nothing. No cost, no obligation, and no contract to sign to get it. You keep the written findings and the EFT policy template either way. We do it because most businesses that go through it discover something worth fixing, and some of them ask us to fix it.

How long does it take and how much of my time?

Two steps. First a 15-minute call so we can ask a few questions and tell you honestly whether a full assessment is worth doing. If it is, the assessment itself runs one to two hours with you or whoever handles your finances, scheduled when it suits you, plus some review work on our end afterward.

Is this just a sales presentation with a different name?

No. You'll get findings specific to your company, not slides about the industry. If we don't find anything meaningful, we'll tell you that and the meeting will be short. We'd rather be the company that told you the truth than the one that manufactured a problem.

Do you need access to our systems?

For the technology portion, read-only access to your Microsoft 365 or Google Workspace admin center gives us the clearest picture, and we'll walk you through granting it and removing it afterward. If you'd rather not, we can still do a meaningful review by walking through settings together on a screen share. Your call entirely.

We already have an IT company. Can we still do this?

Yes, and plenty of the businesses we test do. This is a second opinion on one specific risk. If your provider has it covered, you'll have confirmation instead of hope. If there are gaps, hand them the report — we're not asking you to switch anything.

What is business email compromise?

It's when a criminal gains access to a business email account, or convincingly impersonates one, and uses it to redirect money. Usually by changing banking details on an invoice or requesting an urgent transfer. It rarely involves malware, which is why traditional security tools miss it. The FBI's Internet Crime Complaint Center reported $3.05 billion in losses to it in 2025, making it the second-costliest cybercrime category in the United States.

We already have MFA. Aren't we covered?

MFA is the single highest-value thing you can turn on, and Microsoft's research puts it at blocking more than 99% of account-compromise attacks. But it's no longer sufficient on its own. Microsoft has published detail on adversary-in-the-middle attacks, where a fake login page relays your credentials and MFA to the real Microsoft in real time and steals the resulting session token. You approve the prompt yourself, everything appears to work, and the attacker replays your session without ever needing another MFA challenge. Microsoft reported a 146% rise in these attacks in a single year. So yes, keep MFA on — and add filtering that blocks the fake page, monitoring that spots the stolen session being used, and a payment verification policy that holds even if both fail.

How would my staff spot the fake login page?

It's harder than it sounds. The FBI describes these spoofed sites as legitimate domains altered slightly — an alternate spelling, an extra character, or a different ending like .co instead of .com. Zeros replacing the letter O is a common one. The logo, layout, and colors are copied exactly, and the site almost always has a valid HTTPS certificate, so the padlock appears. That padlock only means the connection is encrypted; it says nothing about who owns the domain. The practical defenses are checking the address bar character by character, multi-factor authentication so stolen credentials aren't enough on their own, and staff who feel free to forward anything questionable to us before they click.

We're a small business. Are we really a target?

Yes, and possibly more than a large one. This attack requires no technical exploit — just an inbox and a payment process. Attackers send thousands of these and work whoever responds. Smaller companies tend to have fewer approval steps and less email security, which makes them faster to convert.

Doesn't our insurance cover this?

Check carefully. Fraudulent transfer and social engineering coverage is often a separate endorsement rather than part of a standard cyber policy, and limits on it are frequently much lower than your overall coverage. Carriers also investigate claims against your application answers. We look at this during the test and tell you what questions to bring to your agent.

What if you find something serious?

We tell you immediately, before the formal report, and we tell you what to do in the next hour. If we find an active compromise — a hidden forwarding rule, a live unauthorized session — that becomes an urgent conversation rather than a scheduled one. This has happened.

What do I do if it already happened to us?

Move fast, because the window matters enormously. Call your bank immediately and ask them to initiate a wire recall. Then file a report with the FBI at ic3.gov — reporting within 24 hours meaningfully improves the odds of funds being frozen, and the FBI's Recovery Asset Team exists specifically for this. Do both at the same time rather than one after the other, and call us so we can find out how they got in and whether they're still there. Most of the businesses we described above waited, and most of them got nothing back.

Can I just have the EFT policy without the test?

Yes. Download it below, put your company name on it, and give it to your finance team. It's genuinely useful on its own and we're not holding it hostage. If it makes you want a closer look at the rest, you know where to find us.

What areas do you serve?

Palm Desert, Palm Springs, Cathedral City, Rancho Mirage, La Quinta, Indio, Coachella, Thousand Palms, Desert Hot Springs, Blythe, and the surrounding Coachella Valley. Our office is at 73280 Hwy 111 Ste 102, Palm Desert.

How do I book it?

Book at lazeritconsultants.com/discoverycall, or call 760-992-5562 and ask for Noah. Tell us you want the Fraud Test and we'll get it scheduled.

Complete This Form To Get Instant Access

  • This field is for validation purposes and should be left unchanged.

Contact Us Today To Schedule Your Discovery Call