The email arrived right after payroll was submitted. So did the doubt.
What happened
The person who runs payroll at a small organization we protect finished submitting the pay run, the way she does every period. Minutes later an email arrived: an urgent meeting invitation about a payroll issue, asking her to join and resolve it.
The timing was the weapon. Right after payroll, a message about payroll feels like a consequence, not a coincidence.
What gave it away
Her own instinct. The message had slipped past the surface filters, but it broke routine: no one schedules a surprise meeting about a pay run that just went in cleanly. Instead of clicking to join, she forwarded it to us and asked one question: what do you think of this email?
That pause, forward, ask sequence is trained behavior, and it is the entire story.
What we checked
- The message's routing headers, to establish where it actually came from
- The meeting link's destination, detonated safely away from her machine
- Whether the same message had reached anyone else in the organization
- Her account's sign-in history, to confirm the timing was observation or coincidence, not access
- Mailbox rules and recent account activity, to rule out a quieter foothold
What we found
A credential-harvesting lure dressed as a meeting invitation, sent from infrastructure with no connection to the organization or its payroll provider. Nothing in her account suggested the sender had inside knowledge; payroll timing is guessable rhythm for any small business, and attackers play the calendar. No one clicked, nothing was entered, nothing was accessed.
What we did
- Confirmed to her, quickly, that her instinct was right, because fast feedback is what keeps people forwarding
- Blocked the sender and its infrastructure across the organization
- Checked every other mailbox for siblings of the same lure
- Added the pattern to what the screening layer watches for
- Retold the story, anonymized, in the organization's security training
What changed afterward
Nothing needed to be contained, which is the point. The change had already happened months earlier, when short trainings and realistic phishing simulations made pause, forward, ask the reflex. The filters catch most things. The trained person caught this one.
What another business can learn
- Attackers read calendars, not minds. Payroll runs, invoice cycles, tax deadlines: the rhythms of a small business are guessable, and a message timed to them borrows credibility it did not earn.
- The pause is the protection. Nothing about stopping to ask cost this organization anything. Clicking would have. Slow is safe when a message wants you to hurry.
- Forward, do not investigate. She did not click the link to see where it went. She handed it to people with a safe place to look. That division of labor is exactly right.
- Praise the report, every time. People stop forwarding the moment reporting feels like bothering someone. Fast, warm confirmation is a security control.