How to Protect Your Business From Scams

How to Protect Your Business From Scams

Business scams do not always look suspicious at first. They often resemble ordinary workplace communication: an invoice from a vendor, a request from an executive, a notice about a business registration, a message from technical support, or an email asking an employee to update account information.

A scammer may impersonate a company leader, government agency, bank, utility provider, customer, supplier, or technology company. The message may use familiar names, company information, logos, email signatures, and details gathered from websites or social media to make the request appear legitimate.

The consequences can extend beyond a single fraudulent payment. A successful scam may expose passwords, financial accounts, employee information, customer data, tax records, or access to the company’s network. It may also interrupt operations and damage trust with customers and vendors.

Effective small business scam prevention depends on more than reminding employees to be careful. Businesses need clear payment procedures, reliable verification methods, secure accounts, employee training, and a plan for responding when something goes wrong.

Why Business Scams Can Be Difficult to Recognize

Many scams work because they fit into normal business activity.

A fake invoice may arrive at the same time as dozens of legitimate invoices. A fraudulent bank-account change may appear in an existing email conversation with a familiar vendor. A phishing message may look like an ordinary password-reset notice. A request for gift cards may appear to come directly from the company’s owner.

Scammers frequently create urgency because they want the recipient to act before checking the request. Common claims include:

  • A payment is past due
  • A business license is about to be suspended
  • A utility service will be disconnected
  • A vendor has changed banks
  • An executive needs an immediate purchase
  • A computer has been infected
  • A customer payment was too large
  • A tax issue requires immediate action
  • A domain name or trademark is about to expire

The Federal Trade Commission’s small business scam guidance identifies fake invoices, business impersonation, government impersonation, tech support schemes, phishing, fake checks, and online advertising scams among the common schemes targeting businesses. (Federal Trade Commission)

The goal is not to make employees suspicious of every customer, vendor, or message. It is to create procedures that allow legitimate business to move forward while giving employees a safe way to pause and verify unusual requests.

Common Scams That Target Small Businesses

Understanding how common scams work makes it easier to build safeguards around them.

Fake Invoices and Renewal Notices

A business may receive an invoice for a product or service it never ordered. The invoice could claim to cover:

  • Technical support
  • Domain registration
  • Search engine optimization
  • Office supplies
  • Business directory listings
  • Advertising
  • Workplace compliance materials
  • Software subscriptions
  • Equipment maintenance
  • License or registration renewals

The invoice may look professional and include an invoice number, payment instructions, a due date, and a “past due” warning. The sender is hoping that an employee will assume someone else authorized the purchase and pay it without checking.

The FTC recommends that businesses establish clear procedures for approving purchases and verify invoices against vendors and services the company actually uses. A May 2026 FTC warning specifically noted that fake invoices may claim to cover services such as technology support, domain registration, or SEO. (Consumer FTC)

Before paying an unfamiliar invoice, confirm:

  • The vendor is approved
  • The company actually ordered the product or service
  • The goods or services were received
  • The amount matches the agreement
  • The payment address or bank account is correct
  • The invoice has not already been paid
  • The employee who allegedly ordered it confirms the purchase

An invoice should not be approved solely because it looks official or includes accurate information about the business.

Business Email Compromise

Business email compromise, commonly called BEC, occurs when a criminal impersonates or gains access to the email account of a trusted person or organization.

The scammer might pose as:

  • A company owner or executive
  • A regular supplier
  • An employee
  • An attorney
  • A bank representative
  • A customer
  • A title company or real estate professional

The message may request a wire transfer, change to vendor banking details, gift card purchase, payroll update, or release of sensitive information.

The FBI describes business email compromise as one of the most financially damaging online crimes. Common examples include a vendor sending supposed new payment instructions or an executive asking an employee to purchase gift cards and send the card numbers. (FBI)

A BEC message can be convincing because the criminal may:

  • Use an email address that differs by only one letter
  • Copy a real employee’s name and signature
  • Refer to an actual project, customer, or invoice
  • Gain access to a legitimate email account
  • Wait for a real payment conversation before intervening
  • Ask that the request remain confidential
  • Contact the employee while the executive is traveling
  • Create an artificial deadline

Every request to change payment instructions should be verified through a separate channel. Call the vendor or employee using a phone number already stored in company records. Do not use the phone number included in the email requesting the change.

Phishing and Account-Theft Scams

Phishing messages attempt to trick recipients into clicking a link, opening an attachment, entering login credentials, sharing information, or sending money.

A phishing message may claim to come from:

  • Microsoft or Google
  • A payroll provider
  • A bank
  • A file-sharing service
  • A shipping company
  • A customer
  • A coworker
  • A government agency
  • A social media platform
  • The company’s IT provider

The link may lead to a fake login page designed to steal the employee’s username, password, and verification code. An attachment may install malicious software or give a criminal access to company files and systems.

The FBI recommends examining email addresses and web addresses carefully, avoiding unsolicited links and attachments, and contacting the supposed sender through independently located contact information. (FBI)

Employees should be especially cautious when a message:

  • Arrives unexpectedly
  • Requests a password or verification code
  • Says an account will be closed immediately
  • Contains an unfamiliar attachment
  • Leads to a login page through an email link
  • Uses an unusual sender address
  • Requests sensitive information by email
  • Creates fear, urgency, or secrecy

A message is not necessarily safe because it includes the correct logo, company name, or employee information.

Government and Utility Impersonation

Scammers may pretend to represent a government agency, tax authority, utility company, licensing office, or regulatory organization.

They may claim that:

  • The company owes a fine or tax payment
  • A license or registration must be renewed
  • A required workplace poster must be purchased
  • A utility bill is overdue
  • The company’s electricity or water will be disconnected
  • A trademark or business name is at risk
  • Legal action will begin unless payment is made
  • The company qualifies for a government grant after paying a fee

The FTC warns that government and business impersonators often use threats and urgency to pressure businesses into sending money or revealing information. (Federal Trade Commission)

Tax-related messages require particular care. The IRS identifies unexpected contact, threats, demands for immediate payment, and pressure to provide personal or financial information as common scam warning signs. The IRS also states that it does not initiate contact through email, text message, or social media to request personal or financial information, and it does not demand gift cards as tax payment. (IRS)

When a business receives an unexpected notice:

  1. Do not use the phone number or link in the message.
  2. Locate the agency’s official website independently.
  3. Sign in through a bookmarked portal or call a verified number.
  4. Ask the company’s accountant, attorney, or responsible manager to review the notice.
  5. Do not make immediate payment because of a threat.

Tech Support and Remote-Access Scams

A tech support scam may begin with an unexpected call, email, text message, invoice, or computer pop-up. The sender claims that a computer has a virus, an account has been compromised, or a subscription needs to be renewed.

The scammer may ask the employee to:

  • Install remote-access software
  • Share the computer screen
  • Provide a password or security code
  • Download a program
  • Pay for unnecessary services
  • Move money to a supposedly protected account
  • Call a phone number shown in a pop-up

The FTC advises that legitimate technology companies do not unexpectedly contact users to announce a computer problem. Businesses should contact their established IT provider through a known phone number instead of calling a number displayed in an unsolicited pop-up or message. (Consumer FTC)

Employees should never give an unknown caller remote access to a company computer. Remote access may expose financial records, customer information, saved passwords, email accounts, and other systems.

Online Directory and Advertising Scams

A caller may offer to create or confirm a free business listing. Later, the company receives an invoice for advertising or a directory placement it did not knowingly purchase.

Some scammers record part of the original call and use the recording to claim that an employee authorized the service. Others send invoices that resemble legitimate advertising renewals.

The FTC also warns about companies that promise to remove negative reviews, post positive reviews, or improve ratings through deceptive practices. Reviews and endorsements must reflect genuine experiences and opinions. (Federal Trade Commission)

Employees who answer company phones should not be authorized to approve marketing purchases merely by confirming basic business information. All advertising agreements should follow the company’s normal purchasing and contract-review process.

Fake Check and Overpayment Scams

In an overpayment scam, a customer sends a check for more than the amount owed. The customer then asks the business to refund the difference or forward part of the payment to another person.

The check may initially appear in the business’s account, but that does not mean it is valid. When the bank later determines that the check is fraudulent, the business may be responsible for the money it sent to the scammer.

The FTC warns that a fake check may appear to have cleared before the bank discovers the fraud. (Federal Trade Commission)

Businesses should not:

  • Refund an overpayment before the original payment is fully verified
  • Send part of a customer’s payment to a third party
  • Accept unusual payment arrangements without review
  • Assume a check is valid because funds temporarily appear in the account
  • Allow a customer to control how the business forwards money

An unexpected overpayment should be referred to the company’s bank and financial manager before any refund is issued.

Payroll, W-2 and Direct-Deposit Scams

A scammer may impersonate an employee and ask payroll to update direct-deposit information. Another version involves someone posing as an executive and requesting copies of employee W-2 forms or payroll records.

The IRS warns that criminals send emails to businesses and payroll providers to steal W-2 information. Names and Social Security numbers can then be used for fraudulent tax filings or other forms of identity theft. (IRS)

Businesses should require independent verification for:

  • Direct-deposit changes
  • Requests for W-2 forms
  • Payroll account changes
  • Changes to an employee’s mailing address
  • Requests for employee tax information
  • Requests to add a new payroll administrator

A direct-deposit request should not be completed based only on an email, even when the sender’s name appears correct.

Business Identity Theft

A criminal may use a business’s name, Employer Identification Number, financial information, or account credentials to open accounts, submit fraudulent filings, impersonate the company, or file a false tax return.

Possible signs of business identity theft include:

  • A tax return is rejected because one was already filed
  • The business receives an unexpected tax transcript or notice
  • The company’s address is changed without authorization
  • Unfamiliar accounts appear on financial records
  • Customers receive fraudulent messages using the company’s name
  • Vendors report unusual payment requests
  • Unauthorized changes appear in online accounts

The IRS provides business identity-theft guidance, including warning signs and reporting options for suspected business identity theft or employee-data loss. (IRS)

Warning Signs of a Business Scam

Scams take different forms, but many share recognizable patterns.

Warning sign

Appropriate response

An unexpected demand for immediate payment

Pause and verify the request independently

A vendor suddenly changes bank accounts

Call a known contact using a previously verified number

An executive requests gift cards by email or text

Contact the executive through another channel

A message asks for a password or MFA code

Do not provide it and notify IT

An unfamiliar invoice is marked past due

Match it to an approved purchase and vendor

A caller threatens to suspend a license or utility

Contact the agency or utility directly

A customer sends too much money

Do not refund or forward funds until the payment is verified

A pop-up tells an employee to call tech support

Close the window and contact the company’s IT provider

An email address is slightly misspelled

Treat it as suspicious and verify the sender

A request must remain secret

Require normal approval procedures anyway

Payment is requested through gift cards or cryptocurrency

Do not pay

A message asks an employee to bypass policy

Stop and refer it to a manager

The FTC recommends paying attention to both the request and the proposed payment method. Demands for gift cards, cryptocurrency, or unusual wire transfers are strong warning signs. (Federal Trade Commission)

Build a Small Business Scam Prevention System

The most reliable protection is a system that does not depend on one employee noticing one misspelled word.

1. Create Clear Purchase and Payment Rules

Document how purchases, invoices, refunds, and payment changes must be approved.

The policy should explain:

  • Who can authorize a purchase
  • Who can add a vendor
  • What documentation is required
  • Who can approve invoices
  • When a second approval is required
  • How banking changes are verified
  • How refunds are processed
  • Which payment methods are prohibited
  • What employees should do with a suspicious request

Consider requiring two approvals for payments above a set amount. A business may also separate responsibilities so that one employee cannot create a vendor, change the vendor’s bank information, and release the payment without review.

Smaller companies may not have enough staff to fully separate every duty. They can still require the owner, accountant, or outside bookkeeper to verify high-risk transactions.

2. Verify Requests Outside the Original Message

Do not verify a suspicious request by replying to the same email. If the account has been compromised, the scammer may be the person responding.

Use a separate method:

  • Call a known phone number
  • Speak to the person directly
  • Use an established customer or vendor portal
  • Contact the employee through the company directory
  • Ask a second manager to confirm the request
  • Review a prior invoice or contract for verified contact information

The FBI specifically recommends independently verifying payment requests and any change to account numbers or payment procedures. (FBI)

3. Require Multifactor Authentication

Multifactor authentication, or MFA, requires an additional form of verification beyond a password.

Enable MFA on:

  • Business email
  • Banking and payment platforms
  • Payroll systems
  • Accounting software
  • Cloud storage
  • Customer relationship management systems
  • Website administration
  • Social media accounts
  • Domain and hosting accounts
  • Remote-access tools

CISA recommends using phishing-resistant MFA where it is available. Even when that option is not available, another form of MFA provides more protection than relying on a password alone. (CISA)

Employees should never approve an MFA prompt they did not initiate or share a verification code with someone who contacts them.

4. Use Unique Passwords and a Password Manager

Reusing one password across several accounts allows a stolen password to create multiple points of access.

Require employees to:

  • Use a unique password for every business account
  • Store credentials in an approved password manager
  • Avoid passwords based on public personal information
  • Change credentials promptly after suspected exposure
  • Never share passwords through email or text
  • Avoid shared accounts when individual accounts are available

CISA recommends strong passwords and password managers for business accounts. A password manager can generate and store unique credentials without requiring employees to memorize every password. (CISA)

5. Limit Access to Sensitive Information

Employees should have access only to the systems and information required for their work.

Pay particular attention to:

  • Banking credentials
  • Payroll records
  • W-2 forms
  • Customer payment information
  • Employee Social Security numbers
  • Tax records
  • Administrator accounts
  • Vendor banking information
  • Domain and website access
  • Backup systems

Remove access promptly when an employee changes roles or leaves the company. Avoid using one shared administrator login for several employees.

The IRS recommends limiting access to personal information, using unique passwords, choosing MFA, encrypting sensitive files, and backing up business data to a secure external source. (IRS)

6. Keep Software and Devices Updated

Outdated software may contain known vulnerabilities that criminals can use to gain access to business systems.

Businesses should:

  • Enable automatic security updates where appropriate
  • Update computers, phones, routers, and servers
  • Replace unsupported software and operating systems
  • Keep browsers and extensions current
  • Update website software and plugins
  • Use reputable security software
  • Review remote-access tools
  • Remove applications the business no longer uses

CISA identifies prompt software updates as a core step for protecting small and medium-sized businesses. (CISA)

7. Maintain Separate, Tested Backups

Backups can help a business recover from ransomware, accidental deletion, equipment failure, and some forms of account compromise.

Back up important information such as:

  • Accounting records
  • Customer and vendor records
  • Employee files
  • Contracts
  • Operational documents
  • Website files
  • Databases
  • System configurations

At least one backup should be stored separately from the primary systems so that the same incident cannot easily destroy both copies. The business should also test whether files can actually be restored.

CISA recommends maintaining secure copies of critical business data separately from primary systems. (CISA)

8. Protect the Company’s Email Domain

Criminals may send messages that appear to come from the company even if they never gained access to its actual email accounts.

Businesses using a company domain should ask their email or IT provider about:

  • Sender Policy Framework, or SPF
  • DomainKeys Identified Mail, or DKIM
  • Domain-based Message Authentication, Reporting and Conformance, or DMARC

These email-authentication tools help receiving servers determine whether a message that claims to come from the company’s domain is authorized.

The FTC recommends that businesses use SPF, DKIM, and DMARC to help prevent criminals from impersonating their email domains. (Federal Trade Commission)

Email authentication does not prevent every lookalike-domain or account-compromise scam, but it can make direct domain spoofing more difficult.

9. Train Employees With Realistic Examples

Scam prevention should be part of onboarding and regular employee training.

Training should cover:

  • Fake invoices
  • Phishing messages
  • Vendor banking changes
  • Gift card requests
  • Government impersonation
  • Tech support calls
  • Payroll changes
  • Overpayments
  • Password and MFA security
  • Reporting suspicious activity

Employees should know that stopping to verify a request is responsible behavior, even when the message appears to come from a senior leader.

Training is more effective when employees practice what to do. Show examples and ask:

  • What looks unusual?
  • Who should verify the request?
  • Which phone number should be used?
  • What information should not be shared?
  • How should the message be reported?

The FTC and CISA both emphasize employee education as an important part of protecting businesses from phishing and other scams. (Federal Trade Commission)

10. Vet New Vendors and Service Providers

Before signing a contract or sending payment to a new company:

  • Confirm the company’s legal name and contact information
  • Review the website and business address
  • Search the company name with words such as “scam” or “complaint”
  • Ask trusted business owners for recommendations
  • Review the entire contract
  • Confirm cancellation and renewal terms
  • Keep copies of all signed documents
  • Never sign blank forms
  • Verify licensing or professional credentials when relevant
  • Confirm how customer data will be protected

The FTC recommends researching unfamiliar companies and obtaining recommendations from trusted sources before doing business with them. (Federal Trade Commission)

A polished website, professional salesperson, or local phone number is not enough to establish that a company is legitimate.

11. Establish an Incident-Response Plan

Employees should know what to do when they click a suspicious link, release information, approve a fraudulent payment, or notice unusual account activity.

The plan should identify:

  • Who receives the first report
  • Who contacts the bank
  • Who manages IT containment
  • Who contacts the insurer
  • Who preserves evidence
  • Who speaks with customers or vendors
  • Who determines whether legal notice is required
  • Which law-enforcement agencies should be contacted
  • How operations will continue

Store the contact information somewhere employees can access even if the company’s email or network is unavailable.

Sample Verification Procedures

A short verification matrix can help employees respond consistently.

Request

Required verification

New vendor setup

Confirm business identity, contract and tax information

Vendor bank-account change

Call a known contact and obtain a second approval

Employee direct-deposit change

Verify through an established payroll process

Executive gift card request

Speak directly with the executive before purchasing

Wire transfer

Require independent confirmation and approval

Password reset

Go directly to the official service instead of using an email link

Unfamiliar invoice

Match it to an approved purchase and proof of delivery

Customer overpayment

Contact the bank before issuing any refund

W-2 or payroll-data request

Confirm the requester and business purpose

Tech support contact

Contact the established IT provider using a known number

The policy should apply to owners and executives as well as employees. A scammer will often claim that the leader wants normal procedures bypassed, so the company’s leadership must consistently support the verification process.

What to Do If Your Business Is Scammed

Speed matters, especially when money or account access has been compromised.

Contact the Financial Institution Immediately

When a fraudulent wire, ACH transfer, check, or card payment has been made:

  1. Contact the bank or payment provider immediately.
  2. Ask whether the payment can be stopped, recalled, frozen, or disputed.
  3. Provide the recipient account details and transaction information.
  4. Follow the institution’s fraud-reporting instructions.
  5. Continue monitoring all related accounts.

For business email compromise, the FBI advises victims to contact their financial institution immediately and request that it contact the institution that received the transfer. (FBI)

Recovery is not guaranteed, but delays can reduce the available options.

Secure Affected Accounts and Systems

If passwords, email accounts, computers, or verification codes may have been exposed:

  • Contact the company’s IT provider
  • Change affected passwords from a trusted device
  • Sign out active sessions
  • Enable or reset MFA
  • Review email-forwarding rules
  • Check for unfamiliar users or administrator accounts
  • Review recent logins and account changes
  • Disconnect affected devices when advised by IT
  • Preserve evidence before wiping or replacing equipment

Do not assume that changing one password completely resolves the problem. A criminal may have created forwarding rules, added recovery methods, or accessed connected accounts.

Preserve Evidence

Keep copies of:

  • Emails and email headers
  • Text messages
  • Invoices
  • Phone numbers
  • Voicemails
  • Screenshots
  • Payment instructions
  • Bank transaction details
  • Website addresses
  • Usernames used by the scammer
  • Dates and times
  • Notes from conversations

Do not continue communicating with the scammer except under the direction of law enforcement, legal counsel, the bank, or the company’s cybersecurity team.

Determine What Information Was Exposed

Identify whether the incident involved:

  • Business banking information
  • Customer information
  • Employee information
  • W-2 forms
  • Social Security numbers
  • Passwords
  • Tax records
  • Health information
  • Payment-card data
  • Confidential contracts
  • Trade secrets
  • Email accounts

The appropriate response depends on the type of information involved. A business may need assistance from cybersecurity professionals, legal counsel, its insurance carrier, financial institutions, and affected service providers.

The FTC’s Data Breach Response guide recommends moving quickly to secure systems, mobilize the appropriate response team, investigate the scope of the incident, and consult legal counsel about applicable requirements. (Federal Trade Commission)

Notify Customers or Vendors When Necessary

When criminals are impersonating the business, customers and vendors may also be at risk.

The FTC advises businesses that discover impersonation to warn affected customers promptly. A warning should explain how the company normally communicates, what information it will never request, and how recipients can verify future messages. (Federal Trade Commission)

Do not make assumptions about legally required notifications. Data-breach and privacy requirements vary depending on the information involved and the people affected. Consult qualified legal counsel.

Report the Scam

Depending on the type of incident, reports may be submitted to:

The FTC encourages businesses to report attempted and completed scams. Reports can help authorities identify patterns and warn other potential targets. (Federal Trade Commission)

Small Business Scam Prevention Checklist

Use this checklist to evaluate your current procedures:

  • Establish written purchase and invoice-approval rules
  • Require independent verification for payment changes
  • Require a second approval for high-value transactions
  • Prohibit gift card purchases based solely on email or text
  • Require verification for payroll and direct-deposit changes
  • Enable MFA on email, banking, payroll and cloud systems
  • Use unique passwords and an approved password manager
  • Limit employee access to sensitive records
  • Remove access promptly when employees leave
  • Keep computers, phones, websites and software updated
  • Maintain secure backups separate from primary systems
  • Test the company’s ability to restore backups
  • Configure SPF, DKIM and DMARC for company email
  • Train employees to recognize common scams
  • Give employees a clear way to report suspicious activity
  • Verify unfamiliar vendors before signing or paying
  • Keep an incident-response contact list
  • Review bank and account activity regularly
  • Protect the company’s EIN and tax information
  • Review procedures after every attempted scam

The checklist should be reviewed regularly as the company adds employees, systems, payment methods, and vendors.

Find Business Technology Resources in Longview

Scam prevention involves finance, operations, employee training, and technology. Business owners do not need to manage every part alone.

The Longview Chamber’s TechTalk program brings East Texas business leaders and technology professionals together for practical discussions about cybersecurity, artificial intelligence, data, automation, cloud technology, and IT strategy. (Longview Chamber)

Businesses can also explore the Chamber’s video library for previous technology discussions or visit Business Solutions for additional programs and resources that support business growth. (Longview Chamber)

A small business scam prevention plan does not need to be complicated. Start with the transactions and information that would create the greatest damage if compromised. Put clear verification rules around those activities, secure the accounts employees use every day, and make it easy for people to stop and ask questions.

A five-minute verification call can prevent a fraudulent payment, compromised account, or much larger interruption to the business.

Frequently Asked Questions

What are the most common scams targeting small businesses?

Common schemes include fake invoices, phishing emails, business email compromise, government impersonation, tech support scams, fake checks, payroll changes, online directory scams, and fraudulent vendor-payment requests. The exact approach varies, but scammers frequently use urgency, authority, fear, and familiar business information to make requests appear legitimate.

How can a business tell whether an invoice is fake?

Compare the invoice with approved purchase records, contracts, prior invoices, and evidence that the product or service was delivered. Confirm that the vendor, amount, account number, and payment address are correct. Contact the vendor using information already stored in company records rather than relying on contact details printed on the unfamiliar invoice.

What should an employee do when a vendor changes banking information?

The employee should stop the payment process and call a known vendor contact using a previously verified phone number. The change should also receive a second internal approval. Do not verify new banking information by replying to the email that requested the change.

Can a fraudulent wire transfer be recovered?

Recovery may be possible, but it is not guaranteed. Contact the sending bank immediately and request that it contact the receiving institution. Report the incident promptly to the FBI’s Internet Crime Complaint Center. The faster the business responds, the more opportunity the bank and law enforcement may have to trace or freeze funds.

What should an employee do after clicking a phishing link?

The employee should immediately notify the company’s IT provider or designated security contact. The business may need to change passwords, terminate active sessions, review account activity, check for forwarding rules, scan the device, and determine whether sensitive information was entered or downloaded. The employee should not hide the mistake or attempt to investigate it alone.

Is multifactor authentication enough to stop business scams?

No. MFA provides important account protection, but it does not prevent every scam. An employee can still be tricked into approving an MFA prompt, sharing a verification code, sending money, or providing information. MFA should be combined with payment-verification rules, employee training, strong passwords, software updates, access controls, and backups.

How often should employees receive scam-awareness training?

Businesses should include scam awareness during onboarding and reinforce it regularly throughout the year. Additional reminders are appropriate when a new scam targets the company, industry, or community. Short, practical training based on realistic invoices, emails, phone calls, and payment requests is often more useful than a single annual presentation.

Should a business report a scam if no money was lost?

Yes. Attempted scams can still be reported to the FTC, IC3, the Texas Attorney General, the company’s email provider, and other appropriate organizations. Reporting may help authorities identify larger campaigns and warn other businesses. The attempted scam should also be used to identify gaps in the company’s internal procedures.

Can scammers impersonate a business without hacking it?

Yes. A criminal can create a similar domain, alter the displayed sender name, spoof an email address, copy company branding, or create a fake social media profile without accessing the company’s systems. Email authentication, domain monitoring, customer warnings, and clear communication practices can help reduce the risk.

Where should a Texas business report a scam?

Texas businesses can report fraud to the FTC at ReportFraud.ftc.gov and submit internet-enabled crime reports to the FBI at IC3.gov. Complaints may also be submitted through the Texas Attorney General Consumer Complaint Portal. Businesses should contact their bank immediately when money has been sent and contact the IRS when business tax information, W-2 data, or an EIN may have been compromised.