I have spent more than 25 years in technology and network security, the last 15 running a managed IT and security practice in Central Florida. In that time I have sat in a lot of conference rooms after the fact, going through logs with an owner repeating some version of the same sentence.
“But she is not stupid. She has been here eleven years.”
No, she is not stupid. That is the part the training videos get wrong. They teach people to watch for the misspelled domain, the impossible offer, the email that obviously screams fraud. Real social engineering inside a small business does not scream anything. It arrives politely, in the middle of a normal Tuesday, wearing the face of somebody you already do business with, and it asks you to do something you do dozens of times a month.
Below are three attacks walked line by line, in the three kinds of businesses I work with most: a general small business, a law firm, and a medical or dental practice. They are composites drawn from published federal alerts and from patterns I see repeatedly, and the scripts are representative rather than lifted from any single victim.
What social engineering is, and what the data actually says
Social engineering is manipulating a person into taking an action or giving up information instead of defeating a technical control. The attacker does not break the lock. He convinces somebody to open the door.
Verizon splits the category in a way worth borrowing. Phishing is asynchronous: send a message and hope for a click. Pretexting is building a trusted relationship through a concocted scenario, frequently by voice. The second kind is the one growing.
From the 2026 Verizon Data Breach Investigations Report, built on more than 31,000 incidents and 22,000 confirmed breaches across 145 countries:
- The human element was present in 62 percent of breaches, up from 60 percent.
- Social Engineering was the third most common breach pattern, showing up in 16 percent of all breaches.
- Pretexting was added this year as a tracked initial access vector and landed immediately at 6 percent. Phishing held at 16 percent.
- In simulations, the median successful click rate on mobile-centric vectors such as voice and text ran 40 percent higher than email.
From the FBI Internet Crime Complaint Center 2025 Annual Report: 1,008,597 complaints and $20.877 billion in losses, up 26 percent over 2024. Phishing and spoofing was the most reported crime type at 191,561 complaints. Business email compromise produced $3,046,598,558 in losses from just 24,768 complaints. Florida ranked third among states, with 71,843 complaints and roughly $1.6 billion lost.
The honest caveat on those numbers
Every figure above is all-industry, and whoever quotes them at you is usually selling something. In the DBIR small and medium business sample on its own, 7,256 incidents, the human element appears in 45 percent of breaches, not 62 percent, and phishing accounts for 9 percent of initial access rather than 16 percent.
Same with the BEC math. Divide $3.05 billion by 24,768 complaints and you get an average north of $120,000, but that average is pulled hard by very large wire fraud, including one municipal case in the FBI report involving a $6 million wire. Your realistic exposure is the size of your largest routine outgoing payment, multiplied by how many go out before somebody notices.
Anatomy one: the vendor invoice that was not from the vendor
A 40 person specialty contractor in Seminole County. Accounts payable runs on the 1st and the 15th. Microsoft 365, a decent firewall, MFA turned on.
Day one. Somebody phishes a project manager at the contractor’s masonry supplier. Not at the contractor. At the supplier. No malware, no alarm. Just a working login to one mailbox at another company.
Days one through fourteen. Nothing happens. This is the part nobody pictures. The attacker just reads mail, learning the PO format, who signs off, the billing calendar, the project manager’s tone, and the controller’s first name off a CC line.
Day fifteen. A reply lands inside an existing thread. Same signature block, same legal disclaimer, three real replies of history underneath.
Hi Teresa, quick heads up before this one goes out. We moved our banking over to a new institution as of this month. Updated remittance details are attached. Sorry for the hassle. Please use the new info for invoice 40982 and anything going forward. Let me know if you need a voided check for your records.
Read that again slowly, because every line is doing work.
- “quick heads up before this one goes out” puts the attacker ahead of the invoice. He is doing you a favor, not asking for one. And “as of this month” pre-answers the only question a careful person would ask: why have I never heard this before?
- “Sorry for the hassle” is the tell people read backwards. Real vendors apologize. Scam emails rarely do, so the apology reads as authenticity.
- “invoice 40982” is a real invoice number, pulled from the thread he has been reading for two weeks.
- “Let me know if you need a voided check” is the sharpest line here. Offering the verification document makes asking for it feel unnecessary, and if you do ask, you will get an excellent forgery within the hour.
No link, no attachment, no lookalike domain. The mail comes from the supplier’s real account and passes every authentication check you have, so email filtering has nothing to flag. The FBI data shows how ordinary this is: 86 percent of BEC losses in 2025 moved by wire or ACH. Not crypto. Your regular bank, your regular payment run.
What stops it: one phone call to the number on a prior invoice or the signed contract, never a number in the message. Any banking change triggers a voice callback and a second approver, with no exceptions for people you like.
Anatomy two: the IT support call that is not your IT company
This is the one I would bet on hitting a Central Florida law firm next, because the federal government has warned about it two years running.
On May 26, 2026, the FBI issued FLASH alert FLASH-20260526-01 on the Silent Ransom Group, also tracked as Luna Moth, Chatty Spider, and UNC3753. The group has targeted United States law firms consistently since spring of 2023 and has also hit insurance, finance, and healthcare. They do not encrypt anything. They talk their way in, take the files, and extort.
Tuesday, 3:40 in the afternoon. A paralegal’s desk phone rings.
Hi, this is Mark over at the help desk. We are seeing some phishing come through your mailbox this afternoon. Did you get anything odd today? … Yeah, that is the one. OK, we want to get ahead of this before it spreads. I just need to run a quick scan on your machine, takes about four minutes. Are you at your desk right now?
- “over at the help desk” is deliberately vague. He does not name your IT provider because he does not know it, and most staff cannot name theirs under pressure anyway.
- “Did you get anything odd today?” is the whole trick in one question. Everybody gets something odd. The moment she says yes she has confirmed his story for him, and from there she is not evaluating a stranger, she is helping a colleague who was right.
- “get ahead of this” and “takes about four minutes” supply urgency that feels protective and an ask small enough to absorb. Threatening urgency gets reported. Helpful urgency gets obeyed, and nobody escalates a four minute favor to the managing partner.
What comes next is an install: Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, or Atera. Every one is a legitimate commercial tool, so your antivirus will not stop it, and should not, because your own IT company probably uses one. The FBI says so directly: these intrusions leave few artifacts because nothing malicious is deployed.
Then the variant that surprises people. If the remote session fails, the FBI reports the group sends a human being to the office. That person says they need to image the device or create a backup to deal with the phishing email, and inserts a storage device. The data leaves on a USB drive, physically, out the front door.
Either way the data goes out quietly, through WinSCP, a renamed copy of Rclone, or straight into OneDrive. The extortion email arrives afterward, and then they call your clients directly to apply pressure. For a law firm, that second call is the real weapon.
Legal is not an accident. In the FBI’s 2025 ransomware complaints from businesses outside the 16 critical infrastructure sectors, legal services was the most reported industry at 18 percent.
What stops it: a written rule about how IT identifies itself, communicated to every employee, plus a callback number on a sticker on the monitor rather than inside an email. That tracks the FBI’s own recommendations: define how IT support authenticates to employees, verify the credentials of everyone entering company spaces, and disable remote access and external drive permissions on machines holding sensitive data.
Anatomy three: the front desk email that becomes a HIPAA problem
In a medical or dental practice, owners picture the practice management system as the crown jewels. That is usually not the thing that gets them. A mailbox is.
Monday morning, front desk, the inbox that handles referrals and records requests.
Good morning, attached is the records request for patient Whitaker. Please confirm receipt today if possible. Secure link expires in 24 hours.
- A records request is the most routine thing that desk handles. There is nothing unusual to notice, which is the point.
- The name is real. Attackers pull surnames from obituaries, public reviews, and the practice’s own social media. A plausible name turns a generic lure into a specific one.
- “Secure link” inverts the training. Staff are taught to expect secure links around patient information, so its presence reads as compliance rather than a red flag.
The link leads to a credential page that looks like Microsoft 365. If the practice uses simple push-based MFA, the attacker relays the prompt in real time and the staffer approves it, because as far as she knows she just logged in. That is the same failure I walked through in MFA Approved the Login. Someone Else Got In. Now somebody else is reading that mailbox, and their first move is usually an inbox rule that hides their own replies.
What got breached is not one email. It is everything in that mailbox: years of referrals, imaging, insurance correspondence, attachments carrying dates of birth, policy numbers, and diagnoses.
On September 17, 2026, the HHS Office for Civil Rights announced a settlement with Ambry Genetics over a January 2020 phishing compromise of one employee email account. Protected health information for 225,370 individuals was potentially exfiltrated. Ambry paid $700,000 and accepted a corrective action plan under OCR monitoring for two years.
Be careful with that number. Ambry is not a small practice, so do not read the dollar figure as yours. Read the finding instead. OCR’s named failure was not that somebody clicked. It was that the organization had not conducted an accurate and thorough risk analysis of where its electronic protected health information lived and what could happen to it. That same finding appears in settlement after settlement, including the four ransomware resolutions OCR announced in April 2026, and it applies identically to a six operatory dental office in Longwood. The click starts the incident. The missing risk analysis is what turns it into an enforcement action. I covered what that analysis actually involves in HIPAA Compliance Is Not a Binder.
Why competent people fall for all three
Strip the three down and the same four mechanics sit underneath all of them.
- The attacker already had context. Nobody starts cold. Two weeks in a vendor’s mailbox, a scraped surname, a guess about your help desk. Context makes an approach feel like continuation rather than initiation.
- The request was routine. Update remittance. Run a scan. Open a records request. Nothing asks anyone to do something they have not done a hundred times.
- Verification was engineered to feel redundant. Offering the voided check. Confirming what the victim already half suspected. Wrapping the lure in the language of security.
- The channel was chosen on purpose. We spent twenty years training people to be suspicious of email and nobody to be suspicious of a phone call. The DBIR measures the result: median successful click rates on mobile-centric vectors run 40 percent higher than email.
Artificial intelligence sits on top of all four and makes each one cheaper. The FBI logged 22,364 AI-related complaints in 2025 with $893,346,472 in losses, including more than $30 million tied to business email compromise with an AI component. Voice cloning is real and the grammar tell is gone. Note the DBIR’s restraint, though: threat actors used AI across a median of 15 documented techniques, and most of that tooling mapped to attacks that already existed. AI made the same attacks smoother, not new.
The names worth knowing
| Term | What it means in practice |
|---|---|
| Phishing | A message sent out and left to work on its own. Still the most reported crime type to the FBI. |
| Spear phishing | The same thing aimed at one named person, using details about their job or vendors. |
| Pretexting | A fabricated scenario used to build trust before the ask, often by phone. |
| Vishing | Voice phishing. The fake help desk call is the version small businesses actually meet. |
| Smishing | The text version. Usually a spoofed shipping notice, or the owner asking a favor. |
| Business email compromise | Fraud run from inside a real mailbox, usually to redirect a payment. No malware required. |
| Tailgating | Walking in behind an employee who holds the door. The in-person theft above is its modern cousin. |
What actually stops social engineering in a small business
Process, ranked above awareness. Awareness asks a human under time pressure to make a correct judgment call. Process removes the judgment call.
- Out-of-band callback plus a second approver on anything involving money. Any change to bank details, any payment over a threshold you set, any urgent request appearing to come from an owner. Verified by voice on a number already on file, never one contained in the request, and released by a second person.
- A written rule for how IT identifies itself. Our clients’ staff are told they may hang up on anyone claiming to be us and call our main number back. Nobody here will ever be annoyed by that call. Put the number somewhere physical.
- Phishing-resistant MFA where you can get it. Number matching beats plain approve or deny push. Hardware keys or passkeys for administrators and anyone who touches money.
- Restrict who can install remote access tools. Most staff have no legitimate reason to install AnyDesk or run Quick Assist. This one control breaks the second scenario outright.
- Verify visitors, including the ones claiming to be IT. Paranoid, right up until you read the FBI alert about people arriving with a USB drive.
- Monitor the mailbox, not just the endpoint. Alert on new inbox rules, new forwarding addresses, and impossible-travel logins. The hiding rule usually appears within minutes of a compromise. This is the work I described in Identity Is the New Perimeter.
- Rehearse the first hour. If a wire goes out wrong, speed beats accuracy. In 2025 the FBI’s Recovery Asset Team ran 3,900 Financial Fraud Kill Chain actions on $1,163,919,846 in attempted theft and froze $679,013,183, a 58 percent success rate. That depends on your bank being called and a report filed at ic3.gov immediately, not Monday morning.
What this does not fix
- None of it stops the compromise of your vendor’s mailbox. Third-party involvement appeared in 48 percent of breaches in the 2026 DBIR, up 60 percent year over year. Your controls end at your edge. Your exposure does not.
- These controls add friction. A payment will get delayed at an inconvenient moment and somebody will be irritated. Decide you are willing to pay that cost before the day you need it, not after.
- Social engineering is not even the leading way attackers get in anymore. The 2026 DBIR puts exploitation of known vulnerabilities at 31 percent of breaches, ahead of credential abuse at 13 percent. Patching and knowing what you own matter more than another phishing simulation.
- Awareness training has a real but limited ceiling. It moves click rates. It does not turn a front desk coordinator into a fraud analyst, and it does little against a well-run pretexting call. I went through the actual evidence in Does Employee Cybersecurity Training Actually Work? If your whole program is an annual video, you have a compliance artifact rather than a control.
Where I have a stake in this
Harmony MSP sells managed IT and security services, and most of the controls above are things we implement and bill for, so weigh the advice accordingly. The first one, the callback and second approver, costs nothing, requires no vendor, and does not involve us at all. I put it first on purpose: a client who loses $180,000 to a redirected wire is a client who ends up blaming their IT company, and I would rather not have that conversation. That is self-interest, and I would rather say it out loud than pretend otherwise.
The short version
Social engineering inside a small business does not look like a scam. It looks like a vendor being helpful, a help desk being proactive, a records request arriving on time. It does not target your weakest employee. It targets your most cooperative one, mid-task, through whichever channel you have trained them least to question.
You cannot train your way out of this completely. You can build two or three rules that force the attacker to fake what he cannot: a live voice on a number he does not control, and a second person who was never part of the conversation.
If you want a second set of eyes on where your firm or practice would actually break in one of these three scenarios, that is a conversation worth having, and it does not have to turn into a proposal. We are in Lake Mary and we work with small businesses, law firms, and medical and dental practices across Central Florida. Call Harmony MSP at (407) 720-6540 and ask.
Frequently asked questions
What is social engineering in cyber security?
Social engineering is manipulating a person into taking an action or revealing information, rather than defeating a technical control. Instead of breaking encryption or exploiting a software flaw, the attacker builds a believable story and persuades an employee to approve a payment, grant remote access, or enter credentials. Verizon’s 2026 report found social engineering in 16 percent of all confirmed breaches, and the human element in 62 percent.
What is pretexting, and how is it different from phishing?
Phishing is asynchronous: a message goes out and the attacker waits for a click. Pretexting is interactive. The attacker invents a scenario, often a fake IT support issue or a data migration, and builds trust through live conversation before making the ask. Verizon began tracking pretexting as its own initial access vector in 2026, where it accounted for 6 percent of breaches. It is harder to filter because there is frequently no message to scan.
What is vishing and why is it harder to spot than email phishing?
Vishing is voice phishing, a phone call rather than a message. It is harder to catch because a live caller adapts in real time, and because most security awareness training is built around email. The 2026 DBIR found that in simulations, the median successful click rate on mobile-centric vectors such as voice and text messaging ran about 40 percent higher than on email.
How do you prevent social engineering attacks in a small business?
Put process above awareness. Require an out-of-band voice callback on a number already on file, plus a second approver, for any banking change or unusual payment. Publish a written rule for how your IT provider identifies itself. Use phishing-resistant MFA. Restrict who can install remote access software. Monitor mailboxes for new inbox rules and forwarding addresses. Training helps at the margins, but it will not stop a well-run pretexting call on its own.
Sources
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- Verizon, 2026 Data Breach Investigations Report Executive Summary
- Verizon, 2026 Data Breach Investigations Report
- FBI FLASH FLASH-20260526-01, Silent Ransom Group Impersonating IT Personnel through Social Engineering (May 26, 2026)
- HHS Office for Civil Rights, settlement with Ambry Genetics (September 17, 2026)
- HHS Office for Civil Rights, four HIPAA Security Rule ransomware settlements (April 23, 2026)
- Google Threat Intelligence Group and Mandiant, Ongoing Targeted Campaign Against US Law Firms
A note on statistics: the attack scenarios above are composites drawn from published federal alerts and from patterns seen in practice, not accounts of any single named victim. Where a figure is an average it is labeled as such, and the all-industry breach percentages are separated from the small and medium business figures on purpose, because they are not the same number.



