Skip to main content
Phishing Scams

One Phishing Email, One Click: How a Small Business Loses $50,000

Phishing is the most-reported crime, with 193,407 complaints in 2024. Here's how a single click can cost a small business $50,000—and how to stop it.

193,407. That's the number of phishing and spoofing complaints the FBI's IC3 received in 2024. It was the most-reported crime category of the year. One hundred ninety-three thousand people—and that's just the ones who bothered to report. The real number is higher.

I'm going to walk you through how one of those complaints happens. Not a hypothetical from a textbook. A realistic scenario you can map onto almost any small business. Then I'll show you the exact defenses that work, and which ones are theater.

Meet the target: a 12-person accounting firm

Imagine you run a small accounting firm. Twelve employees. You handle payroll, tax prep, and bookkeeping for about 80 clients. You have a business bank account, a cloud email system, and a shared drive full of W-2s and Social Security numbers.

On a Tuesday morning, your office manager gets an email. It looks like it's from you. The display name says your name. The subject line: "Urgent wire needed for new software." The email says you're in a meeting, can't talk, and need a $50,000 wire sent to a vendor by noon. The account number is included.

She's busy. She's loyal. She wants to help. She sends the wire.

That's business email compromise. The FBI's IC3 reported about $2.77 billion in BEC losses in 2024 from 21,442 complaints—the second-costliest crime type of the year. Your $50,000 is a rounding error in that total. It's also your entire cash reserve.

The two defenses that actually stop this

Here's my position: if you do only two things, make them phishing-resistant MFA and a callback verification rule. Everything else is secondary.

First, MFA. Microsoft says enabling MFA can block over 99.9 percent of account compromise attacks. But not all MFA is equal. CISA ranks phishing-resistant MFA—FIDO/WebAuthn and PKI-based—as the gold standard. That means hardware security keys or passkeys. SMS codes are a last resort because they're vulnerable to SIM swapping, where an attacker convinces your carrier to move your number to their SIM. CISA calls FIDO/WebAuthn 'the only widely available phishing-resistant authentication.'

Second, the callback rule. No wire transfer, no payment change, no sensitive data release based on email alone. Call the person at a number you already have. Not the number in the email. CISA says if a suspicious message might be real, don't click any link or call any number in the message—look up another way to contact the company or person directly.

That one rule would have stopped the $50,000 wire. The office manager would have called you. You would have said you didn't send it.

Why 'just train your employees' fails

Training matters. CISA's small-business guidance says to teach employees to avoid phishing. But Verizon's 2024 Data Breach Investigations Report found that 68 percent of data breaches involve a non-malicious human element—people falling for phishing, making mistakes, getting tricked. You cannot train that to zero.

And the attacks are getting better. CISA warns that in the era of AI, some phishing emails now have perfect grammar and spelling. The old advice—look for typos—is dead. You have to watch for urgent language and requests for personal information instead.

The variants are multiplying too. Smishing (SMS), vishing (voice), and quishing (malicious QR codes) are all active. Verizon's 2026 DBIR reports that mobile devices have become a new favorite attack target, noting people are often more likely to fall for a fake text or scam call than a traditional phishing email.

So train, yes. But don't rely on training as your control. Rely on technical controls that don't depend on someone noticing a red flag at 11:58 a.m. on a Tuesday.

Comparing your options: what stops what

Control Stops credential phishing? Stops BEC wire fraud? Effort to implement
Phishing-resistant MFA (FIDO2/passkeys) Yes Partially Medium
SMS or voice MFA No (SIM swap, SS7) No Low
Callback verification rule No Yes Low
Annual phishing training Partially Partially Low
Password manager + unique passwords Partially No Low

Notice that no single row is all yes. That's the point. You layer them. But if you're choosing where to start, start with the two that close the biggest holes: phishing-resistant MFA and the callback rule.

The cleanup: what happens after the click

Say the wire goes out anyway. What now?

Speed matters. Report it to the FBI's IC3 at www.ic3.gov and contact your bank immediately. CISA advises ransomware victims—and BEC is often a precursor to worse—to report to federal law enforcement via IC3 or a Secret Service Field Office and to contact CISA for technical assistance.

Then fix the root cause. If credentials were stolen, rotate every password. Check for breached credentials using a service like Have I Been Pwned, which has tracked breaches since 2013. Turn on MFA everywhere it's supported, starting with email, banking, and cloud accounts.

And patch. Verizon's 2026 DBIR found that breaches starting with exploitation of software vulnerabilities have overtaken stolen passwords as the top way attackers get in. So update everything. CISA recommends turning on automatic updates so devices and applications patch themselves as soon as updates are available.

The average reported loss per IC3 complaint in 2024 was $19,372. Your $50,000 wire is nearly three times that. And 256,256 of the 859,532 complaints that year reported an actual loss. Most people who report don't lose money. The ones who do lose a lot.

One more number: victims aged 60 and older submitted 147,127 complaints in 2024 and lost about $4.8 billion. If you have older clients or family members, that's who the attackers are hunting. Set up their MFA. Have the callback conversation with them too.

The takeaway: phishing works because it targets people, not systems. You cannot patch a human. But you can make the human's mistake survivable. Phishing-resistant MFA means a stolen password is useless. A callback rule means a fake email is useless. Together, they turn a $50,000 disaster into a five-minute phone call. Do those two things this week. Not next quarter.

Sources

  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • Verizon (2026 Data Breach Investigations Report) - https://www.verizon.com/business/resources/reports/dbir/
  • CISA (Recognize and Report Phishing) - https://www.cisa.gov/secure-our-world/recognize-and-report-phishing

Share this article:

Comments (0)

No comments yet. Be the first to comment!