A supplier payment change, a gift-card request, or a delivery text can sound routine during the holiday rush. Teach staff to pause and verify before money, accounts, or business information are at risk.
Why familiar-looking requests deserve a closer look
Tight deadlines, staff covering for one another, and extra purchasing make it easier to mistake an urgent message for routine business. Recent 2026 reporting documents invoice, Microsoft 365 sign-in, and remote-access tactics; the examples below are preparation scenarios, not a claim that every one is a newly reported holiday campaign.
- Microsoft: Executive impersonation and invoice fraud research (September 2026)
- Microsoft: EvilTokens and device-code phishing (September 2026)
- Microsoft: Phishing that abuses remote-management tools (September 2026)
- FBI holiday scam guidance
- FBI business email compromise guidance
- FBI cargo-theft advisory (April 2026)
Ten holiday requests worth pausing over
For any unexpected request involving money, access, or a change to business operations, verify it through a contact method already on file.
- Supplier bank details change — Call a known contact and require a second approval.
- An invoice includes an approval thread — Match it to a purchase order and confirm approval separately.
- The owner urgently requests gift cards or a transfer — Call the owner's known number; never send card codes from an unverified message.
- A delivery text demands a small fee — Check tracking in the carrier's app or website you open yourself.
- A deal offers unusually cheap equipment — Verify the seller and use your regular purchasing process.
- A Microsoft 365 file asks for a sign-in code — Stop and check with IT; don't approve a sign-in you didn't start.
- A bonus or payroll notice requests bank details — Open payroll from your usual bookmark and verify changes through your normal process.
- A technician asks you to install remote-access software — Confirm the request through your established IT support channel.
- A carrier changes a driver, route, or delivery location — Verify with a known broker, carrier, or customer before releasing goods.
- A charity asks for an immediate donation — Check the organization independently and use its established donation channel.
Prepare your team and know what to do next
Before the rush, make four things clear:
- Set a callback and second-approval rule for payment or bank-detail changes; name a backup approver.
- Practice realistic requests with the staff who handle money, payroll, email, and deliveries, including seasonal employees.
- Ask IT to review multifactor authentication, account recovery, mailbox changes, and approved remote-access tools.
- Choose one reporting channel. If someone acts on a suspicious request, contact the bank or IT provider promptly, preserve the message, and follow your incident and insurance procedures.
Choose the support your business needs
If staff need regular practice, Security Awareness Training uses short weekly scenarios and feedback to build safer habits. If you want to see how employees respond to suspicious email, Managed Phishing Testing & Staff Training provides authorized simulations, follow-up training, and campaign reporting.
If you need to check the safeguards behind those habits, the $1,995 Business Security Baseline reviews evidence for agreed internal controls, including Microsoft 365 access, email protection, devices, backups, and incident readiness. The free Zero-Access Business Exposure Review is a different first step: it checks public signals only, not internal safeguards.
Related resources
Start with practical staff training
Give employees short, regular practice recognizing and reporting suspicious requests, with feedback and manager visibility into participation.
