Skip to main content

When Cyber Criminals Target the Most Vulnerable

Media When Cyber Criminals Target the Most Vulnerable

 

Cyber criminals do not always attack the biggest company or the organisation with the most valuable technology.

Often, they target whoever appears easiest to manipulate at that particular moment.

That could be:

  • a new employee who doesn't yet know company procedures
  • a finance worker rushing to complete payroll
  • a director travelling between meetings
  • somebody working late from home
  • an employee dealing with an unfamiliar IT problem
  • a customer receiving a convincing fake invoice
  • a business going through an acquisition or office move

This is an important distinction.

Cyber vulnerability isn't necessarily about who somebody is. It can be about the situation they're in.

Attackers look for uncertainty, urgency, distraction and weak processes. They exploit the moments when otherwise careful people are more likely to make the wrong decision.

Understanding those moments—and building safeguards around them—is an important part of protecting your employees, customers and business.

Cyber Criminals Look for Opportunity

Many cyber attacks aren't highly targeted initially.

Criminals can send huge numbers of phishing messages, test previously stolen passwords or scan internet-facing systems looking for weaknesses.

When something works, they concentrate their efforts.

They may be particularly interested in:

  • employees who can authorise payments
  • people with access to confidential information
  • new starters
  • privileged administrators
  • businesses using unsupported technology
  • organisations without strong authentication
  • employees working remotely
  • companies experiencing significant change
  • people who reveal useful information publicly

You don't need to be a multinational company to become a target.

Sometimes being easier to attack is enough.

Vulnerability Can Be Temporary

This is one of the most important things businesses should understand.

The employee most susceptible to an attack today may normally be one of your most security-conscious people.

Imagine somebody who is:

Working late.

Covering for an absent colleague.

Trying to complete payroll before a deadline.

Travelling.

Managing an office move.

Dealing with an important customer complaint.

Working through an acquisition.

Their attention is divided.

Then an email arrives:

“This payment needs to be made before 5pm. I'm in a meeting, so don't call me.”

The timing is perfect for the attacker.

Good cybersecurity therefore cannot depend entirely on employees recognising every scam.

Your processes and technical controls need to protect people when their judgement temporarily fails.

Why Small Businesses Are Attractive Targets

Small and medium-sized businesses sometimes assume cyber criminals are interested primarily in large corporations.

That is dangerous.

SMEs still possess valuable assets:

  • money
  • customer information
  • employee information
  • Microsoft 365 accounts
  • supplier relationships
  • intellectual property
  • business data

But smaller organisations may have fewer people dedicated to protecting them.

They can also have:

  • informal payment procedures
  • ageing systems
  • limited security monitoring
  • shared accounts
  • inconsistent backups
  • excessive user permissions
  • limited security training
  • heavy dependence on individual employees

Attackers do not need your business to be worth billions.

They need an opportunity they can exploit.

New Employees Are Particularly Exposed

A new employee may not yet know how the business normally operates.

They might not know:

  • who can request payments
  • how the Managing Director normally communicates
  • which suppliers are genuine
  • how IT support contacts employees
  • how suspicious messages should be reported
  • what information can be disclosed
  • whether an unusual request is actually unusual

Attackers can exploit the employee's natural desire to be helpful.

Imagine somebody has been at the company for three days and receives:

“Hi Sarah, I'm the MD. I'm tied up in meetings but urgently need you to purchase £500 of gift cards for a customer event.”

Would the employee know that the MD would never make such a request?

This is why cybersecurity should form part of employee onboarding, not something delivered six months later.

Finance Teams Are High-Value Targets

Finance employees are particularly attractive because they can potentially move money.

Attackers may impersonate:

  • directors
  • suppliers
  • customers
  • banks
  • accountants
  • payroll providers
  • colleagues

A particularly dangerous attack involves changing supplier payment details.

An email arrives saying:

“We've changed banks. Please update our account details before paying the attached invoice.”

The email may look completely genuine.

It could even originate from a compromised supplier mailbox.

The solution is not simply:

“Look carefully at the email.”

The solution is a business process.

Any unusual payment or change of bank details should be independently verified using contact information you already trust.

Do not telephone the number supplied in the email requesting the change.

For significant transactions, consider requiring a second authorised person to approve them.

Senior Leaders Can Be Vulnerable Too

Seniority doesn't make somebody immune to cybercrime.

In fact, directors can be particularly attractive targets because they often have:

  • broad access
  • financial authority
  • confidential information
  • extensive contacts
  • privileged accounts

They are also frequently highly visible.

Company websites, LinkedIn profiles, press releases, conferences and social media can reveal useful information about:

  • responsibilities
  • colleagues
  • travel
  • projects
  • customers
  • suppliers

Attackers can use those details to make impersonation much more convincing.

Senior employees should therefore receive at least the same cybersecurity training and protection as everybody else.

Employees Under Pressure

Attackers deliberately manufacture urgency.

Watch for messages such as:

“This must be paid immediately.”

“Your Microsoft account will be disabled today.”

“Do not discuss this with anybody else.”

“The Managing Director is waiting for confirmation.”

“Approve the login notification so we can complete the update.”

Urgency reduces the time available for rational thought.

Businesses should therefore give employees explicit permission to stop and verify unusual requests.

A genuine director, supplier or IT technician should not object to somebody following the company's security procedures.

Remote and Hybrid Workers

Remote workers can face additional challenges because verifying something face-to-face is harder.

They rely heavily on:

  • email
  • Teams
  • telephone calls
  • cloud applications
  • mobile devices

An attacker can therefore impersonate a colleague, manager or IT technician without ever needing to enter the building.

Remote workers should have:

  • managed business devices
  • strong authentication
  • secure remote access
  • endpoint protection
  • clear support procedures
  • an easy way to verify unusual requests

Most importantly, employees should know how genuine IT support normally contacts them.

People Who Need Additional Support

Not everyone has the same experience or level of digital confidence.

Someone might be unfamiliar with Microsoft 365, new to remote working or uncomfortable distinguishing legitimate security prompts from fraudulent ones.

Accessibility requirements, language, unfamiliar systems or simply lack of experience can also affect how somebody interacts with technology.

Training should therefore be:

  • accessible
  • practical
  • relevant
  • understandable
  • free from unnecessary technical jargon

Nobody should feel embarrassed about asking:

“Is this genuine?”

Creating an environment where employees feel comfortable asking that question is a security control in itself.

AI Is Making Impersonation More Convincing

Businesses should also prepare for a world where seeing—or even hearing—someone is no longer sufficient proof of identity.

Generative AI can help criminals produce:

  • convincing phishing emails
  • personalised messages
  • realistic images
  • synthetic voices
  • fake video
  • translated scams

An attacker impersonating a director no longer necessarily needs to rely on a badly written email.

This makes process more important than appearance.

A familiar voice does not override the company's payment procedure.

A convincing Teams message does not remove the need to verify a sensitive request.

A video call should not automatically bypass financial controls.

For high-risk transactions and account changes:

verify through a separately established, trusted channel.

Customers Can Be Vulnerable Too

Cyber criminals may impersonate your company rather than attacking it directly.

They could use:

  • lookalike domains
  • fake invoices
  • cloned websites
  • fraudulent bank details
  • fake social-media profiles
  • compromised employee mailboxes

Even if your systems weren't directly breached, customers who lose money to somebody impersonating your company may still associate the experience with your brand.

Businesses should therefore protect customers as well as employees.

Technical controls such as SPF, DKIM and DMARC can help protect email domains from some forms of impersonation.

But communication matters too.

Tell customers how your business operates.

For example:

“We will never notify you of changed bank details solely by email without additional verification.”

or:

“We will never unexpectedly ask you to install remote-access software without an existing support interaction.”

Clear expectations make suspicious behaviour easier to recognise.

People With Access to Sensitive Information

Cyber criminals aren't always after money immediately.

Information itself can be valuable.

Employees working in HR, finance, legal and administration may hold:

  • payroll records
  • contracts
  • identity documents
  • employee information
  • customer databases
  • financial information
  • credentials

An attacker might impersonate a senior employee and request a copy of confidential records.

Sensitive-data requests should therefore be verified just like financial transactions.

Access should also follow least privilege.

Employees should only have access to information necessary for their role.

If an account is compromised, limiting its permissions limits what the attacker can steal.

Businesses Using Older Technology

Sometimes the vulnerability isn't a person.

It's the technology.

A server or application can continue working perfectly while being dangerously out of date.

Risks can include:

  • unsupported operating systems
  • old firewalls
  • unpatched applications
  • legacy servers
  • obsolete remote-access tools
  • unsupported network equipment

Businesses should maintain an accurate technology inventory and know when important products reach end of support.

Waiting for equipment to fail is not a cybersecurity strategy.

Organisations Going Through Change

Periods of organisational change are particularly useful to attackers.

Consider:

  • acquisitions
  • mergers
  • office moves
  • leadership changes
  • rapid recruitment
  • redundancies
  • system migrations
  • new suppliers
  • major projects

During these periods, unusual requests are expected.

An employee receiving an email from an unfamiliar consultant during an acquisition may think:

“I suppose they're part of the project.”

That uncertainty creates opportunity.

Security responsibilities and verification procedures need to remain clear even when everything else is changing.

Charities and Community Organisations

Charities can also be attractive targets.

They may hold sensitive information about:

  • donors
  • beneficiaries
  • employees
  • volunteers

They may also operate with smaller budgets, volunteers and shared systems.

Fundamental protections remain important regardless of organisational size:

  • strong authentication
  • secure backups
  • supported software
  • endpoint protection
  • email security
  • appropriate permissions
  • security awareness
  • incident response

The value of the information matters more than the size of the organisation.

Use Stronger Authentication

Multi-factor authentication remains one of the most important protections against stolen passwords.

But businesses should increasingly think beyond simply:

“Do we have MFA?”

The better question is:

“What type of authentication are we using?”

Microsoft warns that traditional MFA methods including SMS codes and conventional push notifications can still be targeted through phishing, interception and MFA fatigue. It recommends moving towards phishing-resistant authentication such as passkeys/FIDO2 and Windows Hello for Business.

That is especially relevant now. From 1 September 2026, Microsoft says Entra users enabled for SMS or voice authentication will begin being automatically enabled and nudged towards passkey registration. Microsoft-provided SMS and voice authentication is then scheduled for retirement on 1 February 2027.

For Microsoft 365 businesses, now is a sensible time to review authentication rather than waiting for the deadline.

Protect the Highest-Risk People More Strongly

Not every account carries the same risk.

Give particular attention to:

  • Global Administrators
  • finance employees
  • directors
  • HR
  • IT administrators
  • people with access to confidential information
  • employees able to authorise payments

These accounts may justify stronger authentication, additional Conditional Access policies and tighter monitoring.

The more damage an account could cause if compromised, the stronger its controls should be.

Make Reporting Easy

Eventually, somebody will click something.

Your response to that event matters enormously.

Employees should know exactly how to report:

  • suspicious emails
  • unexpected MFA prompts
  • suspicious telephone calls
  • accidental clicks
  • exposed passwords
  • remote-access incidents
  • fraudulent payments

Most importantly, people should feel able to report mistakes immediately.

If employees believe they will be humiliated or punished for clicking a convincing phishing email, they may hide what happened.

That gives the attacker more time.

You want the opposite:

“I think I've made a mistake. I need IT now.”

Someone Fell for It — What Now?

Suppose an employee tells you:

“I entered my Microsoft 365 password into that website.”

Don't spend the first ten minutes asking why they clicked it.

Start responding.

Depending on what happened, the immediate response may include:

  1. Resetting compromised credentials.
  2. Revoking active sessions.
  3. Reviewing MFA methods.
  4. Checking recent sign-ins.
  5. Inspecting mailbox forwarding and inbox rules.
  6. Checking for malicious application consent.
  7. Isolating an affected computer where appropriate.
  8. Investigating other users who received the same attack.
  9. Preserving evidence.
  10. Contacting the bank immediately if money has been transferred.

The exact response depends on the incident.

What matters is having a plan before you need it.

Don't Make People Your Only Security Control

Security-awareness training matters.

But training cannot guarantee that every employee will identify every attack.

Your business should assume that eventually:

  • somebody will click
  • somebody will believe a convincing phone call
  • somebody will approve something they shouldn't
  • somebody will be distracted at precisely the wrong moment

Then build controls around that reality.

A stolen password encounters phishing-resistant authentication.

A fraudulent bank-detail change requires independent verification.

A compromised ordinary account doesn't have administrator permissions.

A suspicious attachment encounters endpoint protection.

An accidental click is reported immediately.

A good security strategy turns one human mistake into a contained incident rather than a business-wide disaster.

A Practical Protection Checklist

For most businesses, priorities should include:

  1. Provide practical security-awareness training from the employee's first day.
  2. Require independent verification of payment and bank-detail changes.
  3. Deploy MFA and move towards phishing-resistant authentication.
  4. Protect privileged accounts more strongly.
  5. Apply least privilege.
  6. Secure email with appropriate filtering plus SPF, DKIM and DMARC.
  7. Keep operating systems and applications supported and patched.
  8. Provide managed devices for remote workers.
  9. Give customers clear information about how genuine communications and payment changes are handled.
  10. Make incident reporting quick and straightforward.
  11. Maintain tested backups.
  12. Have an incident-response plan.

Vulnerability Isn't Weakness

Describing somebody as vulnerable to a particular cyber attack should not mean labelling them as incapable or careless.

Vulnerability can come from:

Access.

A finance employee can move money.

Authority.

A director can approve important decisions.

Inexperience.

A new employee doesn't yet know the procedures.

Circumstances.

Somebody working late is distracted.

Technology.

An old system has weaknesses that cannot be patched.

Cybersecurity is about identifying those circumstances and putting appropriate protection around them.

How Hamilton Group Can Help

Hamilton Group helps businesses reduce cybersecurity risk by protecting people, processes and technology rather than expecting employees to recognise every attack.

We can help with:

  • Microsoft 365 security
  • Microsoft Entra ID
  • phishing-resistant MFA and passkeys
  • Conditional Access
  • endpoint protection
  • email security
  • SPF, DKIM and DMARC
  • cybersecurity awareness training
  • backup and disaster recovery
  • device management
  • security monitoring
  • incident response
  • technology lifecycle planning

The goal isn't to eliminate human beings from cybersecurity.

It's to build a business where one tired, distracted or inexperienced person making one understandable mistake doesn't give an attacker the keys to everything.

Visit or call 0330 043 0069 to discuss improving your organisation's cybersecurity.