Cyber Security Blog

How to Protect Yourself From Cyber Crime and Social Engineering

Written by Aditi Uberoi | 30 July 2026

A few weeks ago, a client sent me a message asking whether I could verify my banking details. Then he asked a second question, and it is the question that saved him: is it actually you I have been speaking to on email?

It was not.

What had happened

Some weeks earlier, my client had received an email from an address that looked like it belonged to my MageCloud agency. It was not our domain. It was a free Gmail account, created for the purpose, built out of our company name so that it read as ours at a glance. 

The signature block was where the real work had gone in. My name, Paul Ryazanov, spelled correctly. My photo, lifted from our site. My job title. A link to our genuine website. Everything a person would check if they were checking casually, and all of it correct, because all of it had been copied from us.

The content was the part that should worry people. Whoever wrote those emails knew our project manager by name. They knew our web developer by name. They knew the platform the client's store ran on and the work that had recently been done to it. They wrote about it fluently, at length, over several days. 

None of that came from a breach. There is nothing to hack in it. It came from a case study on our own website, including a video of this client speaking warmly about working with us, naming the people on his account.

We published that video because we are proud of the work. It is good marketing. It is also, read differently, a complete briefing document: here is a real customer, here is the relationship, here are the names they would recognise, here is the tone in which they talk about us.

My client was reading on his phone, where you see a display name and not an address. He had no reason to think anything was wrong, because nothing was wrong with what he could see. The attempt ran for days, through a genuine-sounding technical discussion, before it arrived where it had always been heading: a request to send payment to different bank details. My client had paid us the same way every month for years. Being asked to change it did not sit right, and he stopped and asked me directly.

That question is the only thing that ended it. Nobody detected a forgery. A habit held, and we were fortunate.

Why it worked, and it is not what most people assume

This was not a technical attack. Nothing was compromised. No system was breached. Every control we had was working perfectly, because none of them were being tested. It was social engineering, and it used several mechanisms worth naming, because you will see them again.

They borrowed trust rather than building it. The hard part of any fraud is being believed. They skipped it entirely by stepping into a relationship that already had years of credibility in it. My client was not evaluating a stranger. He thought he was continuing a conversation with someone he knew.

They did their reconnaissance in public. Case studies, testimonials, video interviews, logo walls, tagged social posts, team pages. Every one of those is published deliberately, by us, to be found. Collectively they tell an attacker who our customers are, who works on their accounts, and how we speak to each other.

They used authority correctly. Signing as the founder of the agency, not as an account handler. Requests from the top of an organisation get fewer questions, and everybody knows it.

They were patient, which inverts the classic warning sign. We teach people that fraud arrives with urgency and pressure. This did the opposite. It took days. It answered questions thoroughly. It never once pushed. Slowness reads as legitimacy, and it is cheap to fake.

They offered a concession. A discount, unprompted. Somebody giving you something creates an obligation to reciprocate, and it makes the relationship feel real.

They built agreement in small steps. Nothing large was asked early. Each message secured a small yes, and the request that mattered arrived only after a chain of them.

They relied on politeness. This is the one I keep coming back to. My client hesitated to challenge his own agency of several years. Nobody wants to be the person who implies a trusted supplier might be a criminal. That embarrassment is the real attack surface, and no software addresses it.

Notice that not one of those depends on the target being careless. My client is an experienced business owner running a successful ecommerce operation. Being careful would not have helped him. Everything he could see was true.

What to actually do about it

Here is what we changed, and what I would recommend to anyone who sends or receives invoices.

1. Verify payment changes out of band. Always, and specifically.

Any request to change banking details is verified by voice, using a number you already held before the request arrived.

The specifics matter, because every failure mode lives in them. Not a reply to the email, which goes back to whoever controls that account. Not a number printed in the email, the signature or an attached PDF, because if the message is forged so is the number. Not a confirming email from a second address, which takes a minute to arrange.

A phone call, to a number already on file. Thirty seconds. Every time, including when you spoke to the person yesterday, and especially when the request sits inside a conversation that has been running for weeks.

Put more simply: an emailed request to change bank details is the alert. It does not matter how credible everything around it looks. The credibility is the attack.

2. Remove the social cost of asking.

If you sell: tell every client, at kick-off and in writing, that your bank details will never change by email, and that if they appear to, it is fraud. Give them a direct number and explicitly invite them to use it. Say the words "you will never look foolish for checking". I now do this in every kick-off call. It takes a minute and it dismantles the politeness barrier before anyone needs it.

If you buy: give your finance people standing authority to pause any payment for verification, with no approval required and no consequence for being wrong. Somebody who has to justify a delay to a director will not delay.

3. Read your own marketing as an attacker would.

Open your case studies page and ask what it tells someone who wants to impersonate you. Which customers are named. Which staff are named. Which relationships are documented well enough to imitate.

I am not going to stop publishing client work, and neither should you. But it is worth knowing that your customer list is public, that the people on those accounts are named, and therefore that any impersonation attempt you discover should be assumed to have gone to everybody on that list, not just the one client who told you. Warn all of them, quickly.

4. Check the address, not the display name.

Mobile email shows the display name and hides the address, which is exactly why these attacks land on phones. Expanding the header would have exposed this one instantly. Almost nobody expands the header, which is precisely why rule one carries the weight.

5. Know the limits of your email authentication.

SPF, DKIM and DMARC at enforcement are worth having and will stop somebody sending mail that claims to come from your real domain. They do nothing against a free webmail account built out of your company name, or a domain one character different from yours, because those are not technically forgeries. They are real emails from a different sender. "We have DMARC" covers one attack and leaves the more common one wide open.

6. Rehearse it.

Nobody consults a policy document at 4:50pm on a Friday when a familiar supplier sends an updated invoice. They do what feels normal, and what feels normal is what they have practised.

So run the scenario. A known supplier's payment details appear to change. Who pauses the payment, who holds the verified number, how long does it take, what happens when that person is on leave, and at what point does somebody think to warn the supplier? Most organisations find the gap is not the policy. It is that nobody is certain whose job it is to stop.

The short version

Attackers can now convincingly imitate your suppliers, your colleagues and your own writing. What they cannot imitate is where your money already goes, because they need it to go somewhere else.

Put your control on that one thing. Make questioning socially free. Practise it until it is reflex. We did not have this written down when someone came after our client. We do now.