The problem
An employee at a nonprofit received an email claiming to be from a well-known external vendor, purportedly from a contact the organization had worked with years prior. The email included attachments. Something felt off, so she forwarded it to us before opening anything.
“I have not opened these files yet, in case they contain a virus. Can you confirm, real or scam?”
What we did
We responded within minutes. The sender’s email address did not match the legitimate domain of the company it claimed to be from. The contact it referenced had not worked there in years. We confirmed it was a phishing attempt and instructed the client to mark it as phishing without opening any attachments.
The outcome
Nothing was clicked. Nothing was executed. No credentials were stolen, no malware was installed. The threat was stopped entirely because the client paused, and because we were there to respond immediately when she did.
Why it matters
Phishing works because it only takes one click. Having someone to call and getting a fast answer is one of the most effective security measures a business can have.
