Our client was almost phished and almost lost money and her entire web domain

Our client was almost phished and almost lost money and her entire web domain

Last week, one of our clients had a closed call. She was almost the victim of a phishing scam. It was an incident that all business owners must pay attention to because this scammer did more due diligence than the others. If not for us, she would have lost money. Worse still, she could have lost her entire website and domain!

Frantic email

Last week, we received a frantic email from her:

I just saw this email about my domain lapsing. We paid for this back in April. Could you let us know what’s happening with it please?

In her email, she sent a screenshot of that phishing email:

Phishing email sent to client

That email looked very realistic. It even had the design colour scheme and logo of the domain registrar. In other words, the scammer had made the extra effort to find out the domain registrar of her business’s web domain and created a phishing email that looked exactly as if it was from that domain registrar.

Alternative nightmare scenario…

Let’s imagine a business owner signing up to one of those cheap web hosting providers where it is pretty much reliant on self-service efforts from their clients.

Such a business owner could have clicked on that button in that phishing email, thought that he had visited his web-hosting provider’s website (which doubled up as his domain registrar) and attempted to log in. He would have given away his password and multi factor authentication codes. As I wrote 4 years ago in Multi-Factor Authentication will soon be useless,

Multi-Factor Authentication (MFA) is a security measure that requires two or more proofs of identity to grant you access. For example, in addition to providing your password, you need a one-time password (OTP) sent as an email, text message or an authenticator app. On some websites, it can be an approval prompt sent to a smartphone app after you enter your password.

The conventional wisdom is that MFA will increase your security. But unfortunately, this conventional wisdom will soon be inadequate.

Make no mistake, MFA will soon no longer protect you from phishing attacks. A new class of phishing technology will be able to bypass MFA.

Not only that, he might have given away his credit card numbers to ‘reactivate’ his ‘expiring’ web domain.

These things could have happened in this alternative scenario (that thankfully did not happen to our client):

  • He would be a victim of credit card fraud.
  • The scammer would have gained control of his cheap web hosting account, transferred his web domain to another overseas domain registrar, and taken control of his website. In this case, it is not clear what legal recourse he would have, if any, to regain his web domain..
  • If he re-used his passwords (or re-used with slight variations), his other online accounts might be compromised as well. He would be the victim of a credential stuffing attack, where multiple accounts get compromised over time.

What happened instead?

Fortunately for our client, this nightmare scenario did not happen. We were able to advise her that she could ignore that phishing email.

Unlike those cheap web hosting providers that are reliant on self-service efforts from their clients, we provide complete personal service to our clients. Our client was able to contact us and talk to us. In this case, the phishing scam could never have worked on our clients. Why?

We ensure our clients are reminded

Our client, upon learning from us that it was a phishing scam, said:

Oh thank goodness. At first I was thinking did I miss paying for it but surely you would have texted and reminded me.

We make sure our clients are reminded of important events related to their online business. We text, email, and even call them if necessary. They simply cannot miss important events like the expiry of their web domains because we make sure our clients do not miss them.

We check the expiry of their web domains

That phishing email claimed that her web domain would expire in two days. We knew straight away that it was a lie because we knew her domain would expire next year. We check these details and conduct due diligence for our clients to ensure their cybersecurity.

No log-ins to phish

As we explained here,

No log-ins and online accounts are required to work with us. We provide the human touch.

In other words, our clients cannot be tricked into logging into a phishing website because none exist. This eliminates an attack surface for our clients.

Happy ending

Make no mistake, scammers are now on the prowl to target small business owners. They not only want to steal your money, they are also looking to steal your entire website!

The emails they send are becoming increasingly difficult to identify. For our clients, if an email or text message appears suspicious, whether it is a domain renewal notice, an invoice or a login request, please forward it to us before clicking on it. We will review it and inform you promptly whether it is safe or a scam. We provide a straightforward response so you can return to your business operations.

That is the peace of mind that you will get as our client.

Gain your UNFAIR ADVANTAGE!
Do you want razor-sharp, human-written insights from a straight shooter who cannot stand nonsensical, hogwash propaganda from the industry?

Then sign up to our Business Tech & Strategy Insights!
About the Author
Terence Kam Terence Kam
Terence is the founder of Stratigus. See his profile here.

Leave a Reply