Don’t Get Hooked: Spotting Phishing and Invoice Scams at The Daily Grind
Topic: Phishing and business email compromise (BEC) | The Daily Grind Café & Catering
Don’t Get Hooked: Spotting Phishing and Invoice Scams at The Daily Grind
Topic: Phishing and business email compromise (BEC) | The Daily Grind Café & Catering

Every day, our small back office at The Daily Grind coordinates supplier orders, staffing schedules and catering invoices, in the midst of serving customers behind the counter. As such, our email inbox represents one of the most easily compromised assets in our business, as a frazzled or inattentive employee would be just the sort of person a scammer hopes to catch.
These sorts of attacks are called business email compromise (or BEC) scams. In this case, rather than launching any kind of direct assault on our infrastructure, cybercriminals seek to impersonate or hijack an email account in order to redirect funds, gather customer data, or spy on internal communications. According to the Australian Cyber Security Centre, some of the more common BEC scams have been broken down into different types, including invoice fraud and employee impersonation.
In regards to our team, an example of invoice fraud may be a letter seemingly coming from one of our fruit or coffee bean suppliers that would instruct our company to change the bank account of the correspondent before payment on the following invoice is done. An employee impersonation could take the form of a letter seemingly coming from our cafe manager urging the recipient to make some sort of transaction immediately because there is not enough time for a face-to-face talk.
There are several key factors worth pointing out for everyone in our team who is going to use any e-mail correspondence or deal with invoices. Firstly, the sending domain may have some spelling mistakes, making it somewhat different from the legitimate one of the supplier. Secondly, the letter is likely to create some kind of urgency in the recipient forcing him to act without taking any extra precautions. Moreover, the letter may include some uncommon requests from this particular contact, as well as be written in poor quality.
The fix doesn’t necessarily have to be very costly or very complex. If an employee gets an odd request from a customer, colleague, or a vendor that could be related to money transactions or requires changing bank account details or gift cards, they should check with another source that such a message is legitimate instead of responding to the message itself or clicking links provided therein. In our case, at The Daily Grind, it would be one more rule to be followed by everyone: we will check any requests to change our bank account details and perform payments by phone with a known phone number first, before making any changes in accounts.
Multi-factor authentication on our email and ordering platform accounts would also be enabled — it significantly reduces the chances for criminals to get into the inbox, even if a password got stolen, and it is considered the best possible single defense mechanism to prevent such scams.
If you see something suspicious in your inbox, stop, don’t click and ask a manager. Better safe than sorry.
메타데이터
- post_id
- 6af7e9bbf1b8
- slug
- dont-get-hooked-spotting-phishing-and-invoice-scams-at-the-daily-grind-6af7e9bbf1b8
- url
- https://medium.com/@ajinkyakamble648/dont-get-hooked-spotting-phishing-and-invoice-scams-at-the-daily-grind-6af7e9bbf1b8
- canonical_url
- https://medium.com/@ajinkyakamble648/dont-get-hooked-spotting-phishing-and-invoice-scams-at-the-daily-grind-6af7e9bbf1b8
- author_url
- https://medium.com/@ajinkyakamble648
- status
- ok
- fetched_at
- 2026-08-09 19:35:47