Phishing Is the #1 Threat to NJ Small Businesses. Train Your Team.
Three real emails that landed in North Jersey inboxes this year, and why the standard once-a-year training video would have stopped none of them.
Three Emails From the Front Lines
Forget the stock photo of a hacker in a hoodie. Here's what phishing actually looks like in the inboxes we protect across North Jersey, three real examples from this year, details changed, patterns intact.
Email #1: The invoice that almost paid for someone's vacation
A construction company's bookkeeper received an invoice from a supplier they'd used for years. Right vendor name, right logo, right project reference, because the attacker had compromised the supplier's email account weeks earlier and read the whole thread. The only change: "Please note our updated remittance details" and a new bank account. There was no malware, no suspicious link, nothing for a spam filter to catch. It was just a quiet lie inside a legitimate conversation. The amount: $38,400. It stopped because the bookkeeper happened to call the supplier about an unrelated delivery. That's not a control. That's luck.
Email #2: The payroll redirect
An office manager at a professional firm got an email "from" an employee: casual tone, no signature, sent at 8:52 on a Monday morning. "Hi, I switched banks over the weekend, can you update my direct deposit before this payroll runs? I'll send a voided check later." The display name matched the employee perfectly; the actual sending address was a Gmail account created the day before. These cost only a paycheck or two each, which is exactly why they work, the amount is small enough that nobody escalates, and the attacker runs the same play against fifty companies a week.
Email #3: The fake Microsoft login that defeats weak MFA
The most dangerous of the three. An employee received a document-share notification, "Contract_Revised.pdf has been shared with you", that led to a pixel-perfect Microsoft 365 login page. Not a sloppy copy: a reverse-proxy kit that relays the real Microsoft login, captures the password, and steals the session token, which means it can ride straight through basic app-prompt MFA. From there the attacker doesn't smash anything. They sit in the mailbox, set up forwarding rules, study the billing conversations, and become Email #1 for somebody else's vendor list. When we run incident response on business email compromise, this is almost always page one of the story.
Notice What All Three Have in Common
No attachments full of viruses. No princes, no lottery winnings, no broken English. Modern phishing is a social attack that happens to use email: it exploits trust in a known vendor, a colleague's name, a familiar login page. Filtering and email security remove the bulk of the garbage, and hardening your Microsoft 365 tenant with phishing-resistant MFA and alerting on new forwarding rules blunts Email #3 specifically, but some volume of well-crafted bait will always reach a human. Which means the human is part of your security stack whether you train them or not.
Why the Annual Training Video Fails
Most companies' phishing training is a 45-minute compliance video every October, followed by a ten-question quiz everyone passes. We'll say it plainly: this approach does not work, and the industry data has shown it for years. Memory of a single training session decays within weeks. Worse, the video teaches people to spot last decade's phishing (typos, weird URLs, Nigerian princes) and none of the three emails above contain any of those tells. An employee who aced the October quiz will still pay the November invoice, because the invoice doesn't look like anything the video warned about.
What actually changes behavior is the same thing that works for anything else: frequent, small, realistic practice.
What We Run Instead: Simulation Plus Micro-Training
For our clients across Essex County and the rest of North Jersey, phishing defense is a monthly rhythm, not an annual event:
- Monthly simulated phish, modeled on the real attacks above (fake vendor banking changes, payroll requests, document-share logins) at varying difficulty, sent at unpredictable times to small groups rather than the whole company at 9 a.m. (employees warn each other, which is cheating but also, frankly, the behavior we want).
- Sixty-second micro-training at the moment of failure. Click a simulation and you immediately see the exact tells you missed, not a calendar invite to a remedial course. That instant feedback while the email is still on screen is where the learning actually happens.
- Tracking that looks at trends, not trophies. A typical office starts at a 20-30% click rate on a well-crafted simulation. Within six months of monthly practice, we routinely see that under 5%, with reporting rates (people actively flagging suspicious mail) climbing past 50%. That second number is the one we care about.
The No-Blame Rule (This Is the Part Most Companies Get Wrong)
Here's our strongest opinion in this entire article: if you punish people for clicking, your security gets worse. An employee who fears being written up will not report the click, and an unreported click is the difference between us locking a session token within minutes and an attacker reading your email for three months. The goal of a phishing program is not zero clicks; humans will always occasionally click. The goal is fast reporting. So the rules we set with every client: a one-click report button in Outlook, a standing promise that reporting (even reporting your own mistake) is always praised and never punished, and a hard process backstop for the money paths: any banking or payroll change gets verified by phone at a known number, no matter how legitimate the email looks. Train the inbox, but armor the workflow.
Where This Fits in the Bigger Picture
Training is one layer. The clients who sleep well have the full set: filtering and hardened MFA in front of the inbox, monitored endpoints behind it through a managed IT plan, and tested backups underneath it all in case Email #3 ever becomes a ransomware story, our ransomware recovery guide covers that scenario. It's also no longer optional for many of you: as we detailed in our cyber insurance requirements guide, carriers increasingly ask point-blank whether you run phishing simulations, and "no" shows up in your premium.
Want to know your team's actual click rate instead of guessing? Book a free IT assessment and we'll set up a baseline simulation, the results are usually humbling, occasionally terrifying, and always useful. More guides for NJ business owners on our blog.
Find out who on your team would click, before an attacker does.
Book a free IT assessment and we'll baseline your team with a realistic phishing simulation, then show you the monthly program that drives click rates toward zero.
- (646) 719-0490
- info@setnomconsulting.com
- Response within one business day