
The Holiday Scam That Cost One Company $60 Million (And How To Protect Yours)
Last December, an accounts payable clerk at a midsize company got an urgent text from her “CEO”: Buy $3,000 worth of Apple gift cards for
It’s called an identity-based attack, and it’s becoming the top way hackers get into systems. They steal passwords, trick employees with fake e-mails or overload people with login requests until someone slips. And, unfortunately, it’s working.
In fact, one cybersecurity company reported that 67% of serious security issues in 2024 came from stolen logins. Big companies like MGM and Caesars were hit by this kind of attack just last year – and if it can happen to them, it can definitely happen to smaller businesses too.
Most of these attacks start with something simple, like a stolen password. But the techniques are getting smarter:
They’re even targeting things like employee personal devices or outside vendors (like your help desk or call center) to find a way in.
Here’s the good news: You don’t need to be a tech wizard to protect your company. Just a few smart steps can go a long way:
If your employees don’t know how to spot a scam, your security is only as strong as their inbox. Teach them how to recognize fake e-mails and suspicious requests and where to report issues.
Only give employees access to what they need, not to everything. If a hacker gets in, they won’t get far if the account they’re using has limited permissions.
Hackers are after your login credentials, and they’re getting more creative every day. Staying ahead of them doesn’t mean doing it all alone.
That’s where we come in. We can help you put the right protections in place to keep your business safe – without making things harder for your team.
Make sure your business isn’t an easy target. Book a free discovery call and let’s talk about how to secure your logins before hackers get in.
Want to know if your business is vulnerable? Let’s talk. Book a discovery call here.

Last December, an accounts payable clerk at a midsize company got an urgent text from her “CEO”: Buy $3,000 worth of Apple gift cards for

You wouldn’t drive without a seat belt. You wouldn’t leave your office unlocked overnight. So why go online without multifactor authentication (MFA)? MFA is like

Last updated: October 21, 2025 Request Your Free IT Compliance Assessment Introduction IT compliance for Nova Scotia businesses requires navigating federal PIPEDA regulations, provincial PHIA