Search

From One Text Message to Financial Loss How These Cyber Attacks Work insights from ICTechnology

Most people picture a cyber attack as something dramatic. Code scrolling down a screen, firewalls falling over, an alarm somewhere. The reality is far more ordinary. A delivery notification arrives by text. A supplier emails an updated invoice. A login prompt appears at the exact moment someone expected one.

Nothing is broken into. Nobody writes malware. A person simply does what the message asked, because the message looked completely normal.

That is the uncomfortable truth behind a large share of cyber attacks on businesses today. The technical part often comes last, if it happens at all. The first move targets someone busy and trusting, and the financial damage follows.

Key takeaways

  • Many cyber attacks on businesses begin with a single message rather than a system breach, and the money usually moves before anyone notices.
  • Business email compromise is the costliest version of this tactic, with medium-sized organisations reporting an average of A$97,166 per incident.
  • SMS phishing (smishing) attacks work because a text feels personal, lands on a trusted device and is read within minutes.
  • Human error sat behind 37 per cent of reported data breaches in the first half of 2025, up from 29 per cent.
  • Security awareness training and simple verification habits stop more of these attacks than any single piece of software.

It starts with a message, not a breach

Email compromise is now the most reported cyber threat to organisations. In the Annual Cyber Threat Report 2024–25, business email compromise fraud accounted for 15 per cent of business cybercrime reports, with a further 19 per cent involving email compromise without a direct financial loss. Roughly one in three incidents began in an inbox.

That changes where your risk sits. You can buy an excellent firewall and still lose tens of thousands because someone updated a supplier’s bank details after reading a convincing email. The control that failed was not technical. It was a process that let a payment change happen without a second check.

How phishing scams work: urgency, authority and a single click

Phishing scams borrow something you already trust and add a reason to hurry. The trust comes from a familiar brand, a colleague’s name, or a genuine conversation the attacker has been quietly reading. The urgency comes from a consequence: an account about to close, a fine, a client waiting on payment.

Under pressure, people stop evaluating and start complying. That is not carelessness, it is how attention works when someone is juggling forty other things. Criminals design messages to trigger it, which is why showing staff what a phishing message actually looks like beats telling them to “be careful”.

Stage What happens What your team sees Where you break the chain
1. The hook A message arrives by text, email or chat “Your parcel is held”, “Please approve this” Treat unexpected requests as unverified
2. The pressure A deadline or consequence is attached A closing account, an unhappy client Urgency is the tactic, not the emergency
3. The capture Credentials or a code are entered on a fake page A login screen that looks right Phishing-resistant multi-factor authentication
4. The quiet period The attacker reads mail and learns your approval process Nothing unusual at all Alerts on new inbox rules and odd logins
5. The payout Bank details are changed on a real invoice A familiar supplier, a plausible thread Verify changes by phone on a known number

Stage four is the one most businesses miss. Attackers often sit in a mailbox for days, learning your language and your approval process, before asking for anything.

SMS phishing (smishing) attacks explained

Smishing is phishing delivered by text message. It works for the same reasons legitimate SMS marketing works: texts are short, they arrive on a personal device, and most are read within minutes. There is no email signature to inspect, no hover-over link preview, and the screen is small enough that a fake domain is easy to miss.

A typical smishing message impersonates a delivery service, a bank or a subscription provider, then asks the recipient to confirm a detail or unlock an account. The link opens a copy of a real login page, and whatever is typed there goes straight to the attacker, including the one-time code.

The volume is being pushed down. Reported text message scams fell from 77,365 in 2024 to 29,058 in 2025, according to the Targeting Scams report for 2025, helped by network-level blocking and measures such as the SMS Sender ID Register rules. That is real progress, but it has not retired the tactic: reports of online scams involving a loss rose 31.8 per cent over the same period. When one channel gets harder, criminals move to the next.

Business email compromise and what these attacks really cost

Business email compromise is the most financially damaging form of this attack. Instead of a mass message, the attacker gains access to a mailbox, waits for a genuine invoice discussion, then inserts new bank details at exactly the right moment. Nothing looks suspicious, because most of the conversation is real.

In the same scams report, payment redirection accounted for AUD$166.8 million in reported losses in 2025, second only to investment fraud, while phishing scams accounted for AUD$97.6 million. For organisations, the per-incident figures stand out.

Average cost of cybercrime per report by business size ICTechnology

 

Those costs rose across every category, by 14 per cent for small organisations and 55 per cent for medium ones, and the direct loss is only part of it. There is also the time spent reconstructing what happened, the supplier relationship to repair and possible notification obligations. For a smaller organisation, one redirected payment can absorb a month of profit.

Practical steps for protecting staff from cyber attacks

These attacks rely on predictable human moments, so predictable habits defend against them.

  1. Verify every bank detail change by voice. Call a number you already hold, never one supplied in the message. Make it a rule, not a judgement call.
  2. Require a second approver above a set value, so no single person can move money alone.
  3. Use phishing-resistant multi-factor authentication such as passkeys for email, finance and remote access. Codes sent by SMS can be captured on a fake page; passkeys cannot.
  4. Filter aggressively at the gateway. Well-configured email and network security removes many of these messages before anyone has to judge them.
  5. Review access regularly. Dormant accounts and unnecessary administrator rights turn a small compromise into a large one, which is where disciplined access control earns its keep.
  6. Run security awareness training on real examples, including simulated smishing, and track whether reporting rates improve.
  7. Make reporting easy and blameless. If staff fear being blamed, they stay quiet, and quiet is what the attacker needs.

The Essential Eight mitigation strategies and practical guidance on staying secure online both map closely to this list.

Why a proactive approach matters

Human error sat behind 37 per cent of reported data breaches in the first half of 2025, up from 29 per cent, based on published notifiable data breach statistics. Treating people as a weak point to be scolded does not move that number. Treating them as a control that needs support does.

Proactive work is cheap by comparison: a verification rule agreed in advance, monitoring that flags a suspicious inbox rule, an annual review of how sensitive data is protected from cyber attacks. Reactive work is expensive because every cost arrives at once. As organisations grow, so does the number of people authorised to move money, which is why growing businesses face more advanced cyber threats.

How ICTechnology supports your people and your systems

ICTechnology works with small and medium organisations to reduce the risk of exactly these attacks, on both sides of the problem: the systems, and the people using them.

Through managed cyber security services, that typically covers end-user security awareness training on social engineering and phishing, email and gateway filtering, multi-factor authentication rollout, access and privilege management, monitoring for unusual account behaviour, security auditing, and incident response when something does get through. Where broader cover is needed, this sits alongside managed IT services and tested data backup arrangements, so recovery is predictable rather than improvised.

The difference usually comes down to attention. The engineers and consultants looking after your environment are the ones who notice a mail-forwarding rule nobody created, and that daily vigilance is a large part of why organisations stay with ICTechnology.

Frequently asked questions

What is smishing?

Smishing is phishing carried out by SMS. An attacker sends a text impersonating a trusted organisation, such as a delivery company or bank, asking the recipient to click a link or confirm details. The link leads to a fake login page that captures credentials and one-time codes.

Why is business email compromise so damaging for businesses?

Because the request looks legitimate. The attacker sits inside a real email thread, using real context, and simply changes the bank details. Medium-sized organisations reported an average of A$97,166 per cybercrime report, and payment redirection caused A$166.8 million in reported losses in 2025.

How can businesses protect themselves from phishing scams?

Verify bank detail changes by phone on a known number, require a second approver for significant payments, use phishing-resistant multi-factor authentication, filter email at the gateway, limit administrator access, and run security awareness training on realistic examples.

What are the risks of ignoring these cyber attacks on businesses?

Direct financial loss, funds that cannot be recovered once transferred, exposure of customer or supplier data, notification obligations, damaged supplier relationships, higher insurance premiums, and days of lost productivity during the investigation.

What should small businesses do first?

Start with the two cheapest controls: a written rule that no bank detail change is actioned without a voice call to a known number, and multi-factor authentication on email and remote access. Then add security awareness training and a blameless way to report suspicious messages.

When should a business seek professional IT support?

Seek support if you handle customer or payment data, process supplier invoices regularly, have staff working remotely, or lack the in-house expertise to configure these controls consistently. Ongoing IT support also means someone is watching when your team is busy.

Staying one message ahead

These attacks succeed because they arrive dressed as ordinary work. There is no obvious moment where someone is asked to make a security decision, which is precisely the point. The defence is not suspicion of everything. It is a few habits applied consistently: verify money movements by voice, use authentication that cannot be phished, filter what you can, and make it easy to raise a hand when something feels off.

None of that needs an enterprise budget. It needs a decision to put the habits in place before they are needed. If you are not sure where your process would break, a short conversation with ICTechnology will show you quickly.

Interested in a quote and consultation? Reach out to: [email protected]

Need managed cyber security support? Please reach out! [email protected]

Any other enquiries? Fill out our contact form here.

Leave a Comment