Photo: free stock photography (Unsplash licence) — see imprint
The attack has changed
Nobody is sending you a badly spelled prince letter any more. They are replying inside a real email thread, with your supplier's real signature, asking you to update the bank details on an invoice you were actually expecting.
Technology first, because it never gets tired
SPF, DKIM and DMARC on your own domain. 2FA everywhere, especially on email and the shop admin. External-sender banners. These do not depend on anyone staying alert at 4:45 p.m. on a Friday.
Then one process rule that actually works
Bank details are never changed on the basis of an email. Ever. They are changed after a phone call to a number you already had. This single rule blocks the most expensive attack in German SMEs.
Plan for the click
Someone will click. Have the answer ready: who is called, what gets disconnected, which passwords are rotated, who talks to the bank. A rehearsed plan turns a catastrophe into a bad afternoon.
- Modern phishing arrives inside a real thread.
- Never change bank details based on an email.
- Rehearse the incident plan before you need it.
Frequently asked questions
Often you cannot, and any training that promises otherwise is selling comfort. The current attack replies inside a real thread, carries your supplier's real signature, and concerns an invoice you were genuinely expecting. There is no spelling mistake to catch. That is why the defence has to be technical and procedural rather than a moment of vigilance at 4:45 on a Friday.
Assume it worked and act on that. Rotate the credentials involved, disconnect what needs disconnecting, and call the bank first if payment details were in play. Speed beats certainty here. Decide who does each of those things now, on a quiet day — a rehearsed plan turns a catastrophe into a bad afternoon.
Not on its own. People get tired at the end of a long week; SPF, DKIM and DMARC on your domain do not. Neither does 2FA on email and the shop admin, nor a banner marking external senders. Do the technical work first, because it keeps working when nobody is paying attention. Train afterwards — training is the last layer, not the first.
Bank details are never changed on the basis of an email. Ever. They change after a phone call to a number you already had — not the number in the message. It is unglamorous, it mildly annoys your suppliers, and it blocks the most expensive attack aimed at German SMEs. One sentence in a process document, and it earns its keep.
We do this for a living — Shopware, Node.js, React, ERP integration and automation for B2B.
Talk to an engineer