We Travel PC ← Security at We Travel PC
CASE NOTE 002 / SOCIAL ENGINEERING, CAUGHT BY STAFF / 5 MINUTE READ

The email arrived right after payroll was submitted. So did the doubt.

Identifying details, timing, dollar amounts, and technical specifics may be changed or withheld to protect the people involved.

What happened

The person who runs payroll at a small organization we protect finished submitting the pay run, the way she does every period. Minutes later an email arrived: an urgent meeting invitation about a payroll issue, asking her to join and resolve it.

The timing was the weapon. Right after payroll, a message about payroll feels like a consequence, not a coincidence.

What gave it away

Her own instinct. The message had slipped past the surface filters, but it broke routine: no one schedules a surprise meeting about a pay run that just went in cleanly. Instead of clicking to join, she forwarded it to us and asked one question: what do you think of this email?

That pause, forward, ask sequence is trained behavior, and it is the entire story.

What we checked

What we found

A credential-harvesting lure dressed as a meeting invitation, sent from infrastructure with no connection to the organization or its payroll provider. Nothing in her account suggested the sender had inside knowledge; payroll timing is guessable rhythm for any small business, and attackers play the calendar. No one clicked, nothing was entered, nothing was accessed.

What we did

What changed afterward

Nothing needed to be contained, which is the point. The change had already happened months earlier, when short trainings and realistic phishing simulations made pause, forward, ask the reflex. The filters catch most things. The trained person caught this one.

What another business can learn

Real incidents. Identifying details removed. How this protection is layered is documented at wetravelpc.io. If something feels wrong at your business right now, start with what to do first, and call or text 701-306-0188.