A builder I look after opened an email one afternoon. A business he had dealt with for years had shared a folder with him. The name was right, the signature was right, the phone number in it was the one he'd rung before.
He clicked it. Twenty-three hours later, somebody on the other side of the world had full control of his computer, and kept it for eight days.
Nothing he did was careless. That's the part worth writing down, because almost every piece of advice small businesses are given about this would have failed him too.
This is what he saw. The sender's name, address and signature block are removed — the business whose account was stolen is a victim here too.
shared a folder with you
Property Management invited you
to view a folder
I’m trying to get more organized in making our data for different things more shared/visible.
For Security reasons, please view the file on your desktop or windows laptop.
🔒 This invite will only work for you and people with existing access.
What hovering over the button actually showed
Original URL: https://-my.sharepoint.com/:f:/r/personal/…/Documents/Operations/Lab%20Service%20Providers — Click or tap if you trust this link.
↓ the link underneath actually went to jorzetk[.]vu/access/
The email was real
This wasn't a forgery. It genuinely came from that business's mailbox, sent through their own mail provider, cryptographically signed by their own domain. Nobody had faked the sender's address, because nobody needed to.
Their email account had been taken over. Once that happens, the attacker isn't impersonating anyone — they're sitting inside a real person's mailbox, sending real mail to that person's real contact list. Everything is authentic except the intent.
That's why the usual advice fell over. "Check the sender's address" — it was correct. "Does it look like it's from someone you know?" — it was from someone he knew.
Every check a mail system can make, passed
There are three technical standards that email systems use to work out whether a message is really from where it claims. Here is what they said about this one:
All three are worth having. None of them can tell you whether the person at the keyboard is the person who owns the account.
Those standards exist to stop someone forging your address. They do that job well. What they cannot do — what nothing in that category can do — is notice that a legitimate account has fallen into the wrong hands.
Hovering over the link made it look safer
The standard advice is to hover over a link and read where it actually goes before clicking. He did have a look. What appeared was a long, plausible Microsoft file-sharing address, followed by the words "click or tap if you trust this link."
That phrase is lifted straight from a genuine Microsoft security product — the one that checks links inside company email. Seeing it suggests the link has already been inspected and cleared by security software.
It hadn't. The address on display was decoration. The link underneath went somewhere else entirely: a two-week-old domain registered on an obscure island extension, sitting behind a service that hid where it really was.
Read that again, because it's the bit that sticks with me: the reassurance was part of the trap.
There was one real tell
The line that gave it away
"For security reasons, please view the file on your desktop or Windows laptop."
There is no security reason to require a particular device to look at a shared folder. Genuine file sharing works perfectly well on a phone.
That sentence is there because the attack only works on a Windows computer. It is the trap steering you to the machine it needs. Any message that insists you switch devices before opening something deserves a phone call to the sender before you do anything else.
Why it keeps coming from people you know
Buried in the code of that email was a trail showing it had been forwarded through 83 separate mailboxes before it reached him.
That's the whole business model. One account gets taken over. It quietly emails everyone in that person's contacts. A few of them click and enter their password. Now those accounts are sending it to their contacts. On it goes.
Which is why these messages so rarely look like the clumsy scams people picture. By the time it reaches you it has been through dozens of real businesses, and it arrives from a real person you have genuinely worked with.
The antivirus was working perfectly. It had nothing to find.
What eventually got installed on his computer wasn't a virus. It was ordinary commercial remote-support software — the same category of program IT companies use every day to help customers, properly sold and digitally signed by the company that makes it.
When I examined the machine, its security software was in excellent order: protection switched on, tamper protection enabled, definitions updated the day before, no detections, and nothing excluded from scanning. It had done nothing wrong. There was simply nothing there for it to recognise as bad.
Antivirus asks one question: do I recognise this file as dangerous? When the answer is a legitimate, signed program that thousands of businesses use for good reasons, the answer is no — and the answer will always be no.
Eight days, and no alarm anywhere
The access sat there for eight days. Nobody noticed. It wasn't spotted by the computer, or by the antivirus, or by anyone using it. It surfaced only when a third party noticed the mailbox being misused and pulled the plug.
And when I went to reconstruct what had actually been done during those eight days, I couldn't. Windows keeps that particular record for roughly two days before writing over it. The evidence had already gone.
That's the part that should bother a business owner more than the break-in itself. Not that something got in — that will happen to somebody eventually — but that it could sit there for over a week with nothing, anywhere, raising a hand.
What would actually have caught it
Not a better antivirus. Something that watches behaviour rather than files, and asks a different question: is what just happened normal for this computer?
An installer downloaded into a temporary folder, run by hand, registering itself as a permanent service that immediately starts talking to an unfamiliar server on the other side of the world — that is a strange thing to happen on a builder's PC on a Tuesday lunchtime, whether or not the software involved is legitimate. That question gets asked in minutes, not eight days.
The other half is simpler and cheaper. The whole chain runs on stolen email passwords. Two-factor authentication — the code on your phone — breaks it, because a stolen password on its own stops being enough. Most small businesses already have it included in what they're paying for and have never switched it on.
What I'd do this week
Turn on two-factor authentication for your email. If you do one thing, do this. It's usually already paid for.
Treat "open this on your computer" as a red flag. Genuine shared files open anywhere.
Verify by phone before money moves. If an email asks you to pay somewhere new, or a supplier's bank details have changed, ring the number you already have — never one from the email. This is where these attacks actually make their money.
Assume a familiar name proves nothing. The most convincing message you'll ever get will come from someone you genuinely know, because their account was taken first.
He did nothing stupid. It was a real email, from a real person, at a business he trusted, and it passed every test he'd been told to apply. The uncomfortable answer is that the advice most small businesses have been given stopped being sufficient a while ago.
Not sure what's watching your systems? Let's have a look.
Get in touch