Technology Advisor Blog



Business Email Compromise: A Tale of Three Businesses

Posted by Ann Westerheim on 8/20/26, 3:55 PM

Imagine three small businesses facing the exact same cyber threat.

An attacker gets access to an employee’s email account. Maybe a password was stolen through phishing. Maybe the attacker found credentials from an earlier breach. However they got in, they now have something incredibly valuable: access to a real business email account.

From there, they can quietly watch.

They can learn who handles invoices. Who approves payments. Which vendors the company works with. How the owner communicates. They may even watch an existing email conversation and wait for exactly the right moment to step in.

This is Business Email Compromise, or BEC. And it’s one of the most financially damaging forms of cybercrime facing businesses today.

According to the FBI’s 2025 Internet Crime Complaint Center (IC3) Annual Report, Business Email Compromise was the second-highest crime type by reported financial losses, behind investment fraud. Businesses and individuals reported approximately $3.05 billion in BEC losses in 2025 from 24,768 complaints.  Read the full FBI report here.

That’s billion with a “B.”

But statistics don’t always make cyber risk feel real.

So let’s look at what happens when the same kind of threat hits three different businesses.

Read More

Tags: eMail, cybersecurity, business email compromise





What If the Cyberattack Starts With a Conversation?

Posted by Ann Westerheim on 6/24/26, 4:54 PM

 Modern cybersecurity threats don't always begin with malware or a suspicious link. Sometimes they start with a conversation that seems completely legitimate. Here's what one recent social engineering assessment can teach small businesses about protecting themselves. 

When most people think about phishing attacks, they picture an email filled with spelling mistakes, suspicious links, and obvious red flags. 

Unfortunately, that's not how many modern attacks work.  "Don't click on a suspicious link" doesn't cut it anymore for security awareness training.

A recent social engineering assessment conducted by security researchers at NetSPI demonstrated just how sophisticated today's attackers have become. Instead of sending a traditional phishing email, the researchers spent time building trust before ever introducing a malicious link.

The scenario they created was simple - and highly believable. Too many people think they'll never fall for a

Read More

Tags: eMail, cybersecurity, Cybersecurity Awareness Training





What If They’re Already In? The Blind Spot in Email Security Most Businesses Miss

Posted by Ann Westerheim on 5/6/26, 10:20 AM

 We hear this all the time: 

“We already have email security in place - we’re good.”
“We’re on Microsoft 365 (or Google Workspace) - they take care of that.”

And it’s easy to see why at first that feels like enough. 

 Platforms like Microsoft and Google provide a powerful foundation - offering the infrastructure, built-in protections, and security features that businesses rely on every day. 

But here’s the part that often gets misunderstood:

They provide powerful tools - but they don’t replace a complete security strategy.

And even with strong protections in place…

No system catches everything.

What happens if something does get through?

Read More

Tags: eMail, cybersecurity, Microsoft 365





What Really Happens When Your Email Gets Hacked (And How to Stop It)

Posted by Ann Westerheim on 10/17/25, 4:08 PM

This week, we received what looked like an official Request for Proposal (RFP) email from a local business we know. It was well-written, professional, and completely believable.

Read More

Tags: eMail, cybersecurity, hack





Why DMARC Matters: A Real-Life Voicemail Scam Example Every Business Should See

Posted by Ann Westerheim on 9/22/25, 12:44 PM

Last week, I didn’t even see a suspicious voicemail notification in my inbox - and that’s the point! Our email security blocked it before it ever got to me. At first glance, the message looked pretty legitimate.  It  was well-formatted, had a sense of urgency - “Your voicemail system has received a new message.  Review it promptly to stay updated”, and looked like something that could easily trick someone into clicking.

Read More

Tags: eMail, cybersecurity, DMARC, Cybersecurity Awareness Training





DMARC Gets Serious: Microsoft Enforces Stricter Email Rules

Posted by Ann Westerheim on 4/30/25, 4:47 PM

Starting May 5, 2025, all businesses - regardless of size - must meet Microsoft’s stricter email authentication requirements when sending to Outlook, Hotmail, and Live addresses. These changes are designed to reduce spoofing and impersonation, aligning with similar updates from Google and Yahoo to improve overall email security.

Read More

Tags: eMail, SPF record, Cybersecurity, email scams, cybersecurity, DMARC





Important Notice Regarding Your Domain Name(s)

Posted by Ann Westerheim on 6/4/18, 2:15 PM

A few clients have asked us about recent notifications received from Network Solutions (and others):    "Action Required: Notice Regarding Your Domain Name(s)".  In this day and age, we recommend that all users stay alert when opening email, and we welcome questions about the legitimacy of received mail - better safe than sorry!

This notification states as follows:

"This notification is being sent to you as a contractual requirement of the Internet Corporation for Assigned Names and Numbers (ICANN) WHOIS policy. When you registered your domain with us, you agreed to keep your contact information in Account Manager current, and the WHOIS policy mandates that we ask you to verify and/or update this information periodically. Further, ICANN requires us to remind you that providing inaccurate or dated contact information may be grounds for domain name cancellation."

In this case the message IS legitimate, and we always recommend as an extra precaution that you go straight to the website in question (in this case, the company you registered your domain name with, typically Network Solutions), rather than clicking through the link in the website.  Yes, we just said the email was "real", but as a "best practice", don't follow links in emails when you don't have to. 

You don't have to reply to the email, it's just a reminder to check that the current information is still valid, and t

Read More

Tags: eMail, Internet, web site





Sending an email to more than just a few recipients? DON'T hit the send key before reading this....

Posted by Ann Westerheim on 4/16/18, 3:54 PM

You need to send an important update or invitation to all your clients and you're ready to hit the "send" key.  Don't!  

Read More

Tags: eMail, email security





eMail Delays in the "Always On" World

Posted by Ann Westerheim on 7/17/17, 2:02 PM

Modern technology enables us to accomplish so much, but when there's a disruption, we're reminded of our dependence, and it's painful!  Last Thursday and Friday, many users were affected by delays in sending and receiving emails.   The systems at Rackspace, one of the leading cloud providers in the world, became overloaded and disrupted services for many users, including a number of Ekaru clients.

Read More

Tags: eMail





What's my email password?

Posted by Ann Westerheim on 12/13/16, 2:57 PM

Cybersecurity is a hot topic these days.  We need "strong" passwords, we're not supposed to use the same pasword for multiple applications, and we need to change passwords on a regular basis.  It's hard to remember all the passwords, and especially hard when you don't even know a password exists!   Your email has a password, but its likely you don't remember it because you don't usually need it on a regular basis.

Read More

Tags: eMail, password





Subscribe by Email





    Browse by Tag

    See all tags...


    Posts by Month

    See all months...


    Connect With Us



    Older Blog Posts

    For older Ekaru blog posts, go to ekaru.blogspot.com.