A quiet office desk with Christmas decorations beside a computer
← Blog

Cyber security

Christmas scams: how to protect your business while the office is quiet

· 5 min read · Bold ICT team

December and January are peak season for scammers. Here is what they try, and a short shutdown checklist to protect your business over the break.

December and January are the busiest months of the year for scammers targeting Australian businesses, and it is not a coincidence. The office is quiet, approvals get rushed, and half the team is answering email from the beach.

Why the break is such a good time to try it on

Every safeguard a business has depends on someone noticing. Over the break, fewer people are looking, and the ones who are tend to be covering three jobs at once.

  • Skeleton staff: the person who normally checks supplier details is away, and someone unfamiliar is approving payments.
  • Rushed approvals: everyone wants invoices cleared before the shutdown, so a payment request gets less scrutiny than it would in March.
  • New casuals: seasonal staff do not yet know what a normal request from the boss looks like.
  • Everyone is on their phone: dodgy links are much harder to spot on a small screen where the sender's real address is hidden.
  • Genuine parcel deliveries everywhere: a fake delivery text does not stand out when you are actually expecting six parcels.

The ones we see every year

Fake invoices and changed bank details are the most expensive by a long way. An attacker gets into an email account – often at a supplier rather than at your end – reads the conversation, and sends a real-looking invoice with new account numbers. Everything about it is legitimate except where the money goes.

Parcel delivery texts are the highest volume. A message says a delivery failed and asks you to pay a small fee or confirm details on a link. The page looks right, and it collects your card details or your login.

The gift card request is the one that catches good, helpful staff. A message that appears to come from the owner or manager, often from a slightly wrong address, says they are travelling, cannot talk, and need gift cards bought urgently for clients. It preys on wanting to help the boss.

Then there are the fake government messages: myGov, the ATO, toll notices, energy rebates. Scamwatch reports on these patterns all year, and the January versions usually lean on refunds and end-of-year statements.

Your two-minute shutdown checklist

Before you lock up: name one person who can approve payments over the break and one backup; agree that no bank detail change is actioned until someone rings the supplier on a known number; confirm multi-factor authentication is on for every email account; log out of shared devices at reception and in the workshop; and put the after-hours IT contact on the staff room wall so nobody has to guess who to ring.

Setting the rules before you close

The single most useful thing you can do is decide, in advance and in writing, who is allowed to approve a payment while you are away and what the limit is. Scams work by creating urgency, and a rule that was agreed a fortnight ago is much harder to talk someone out of.

Give staff one place to send anything that looks odd. It might be a shared mailbox or simply one manager's mobile. What matters is that reporting is easy and that nobody is ever made to feel silly for asking. The moment people worry about looking foolish, they stop reporting and start deleting.

Tell your seasonal staff plainly on day one: nobody from management will ever ask them to buy gift cards, change bank details, or read out a code from a text message. Make it a specific instruction rather than general advice about being careful.

The first hour after someone clicks

Somebody will click something eventually. What decides whether it becomes a bad week is what happens in the first hour, so it helps to know the order in advance.

  1. Say so straight away. Speed matters far more than working out how it happened.
  2. Change the password on the affected account, and on anywhere else that password was used.
  3. Check the account for mail rules that quietly forward or delete messages – attackers add these to stay hidden.
  4. If bank details were entered, ring the bank immediately and ask about recalling any payment.
  5. Disconnect the computer from the network if files are being encrypted or behaving strangely, but leave it switched on.
  6. Ring your IT provider. If you are with us, we would rather be called about ten false alarms than one real thing three days late.
  7. Report it to Scamwatch, and to police through ReportCyber if money was lost.

Write those steps on the same page as the after-hours contact number. In the moment, people do not read policies, they read whatever is stuck to the wall.

A few technical things worth doing before you go

Make sure updates have been applied rather than sitting in a queue waiting for someone to restart. A machine that has been left on for three weeks with pending updates is an easy target.

Confirm your backups have run recently and that at least one copy sits somewhere separate from the main system. If the worst happens while the office is closed, that separate copy is what gets you trading again in January.

And if you have staff using their own laptops or phones for work over the break, take two minutes to check those have a screen lock and are not the family computer the kids also use for games.

Have a quiet one

None of this needs to take long. An hour before you shut the doors covers most of it, and it is a much better use of that hour than the alternative in the second week of January.

It is also worth telling your customers and suppliers how you will and will not contact them over the shutdown. A short line in your out-of-office saying that your bank details have not changed, and that any message claiming otherwise should be checked by phone, protects them as well as you. Scams travel both ways along a supply chain, and a supplier who gets caught can cost you a payment even when your own systems are fine.

From all of us at Bold ICT, we hope you get a proper break, that the phone stays quiet, and that the only surprises are the good kind. We are around if you need us.

Would you like us to check your business is set up safely before the shutdown?

Book a free cyber security assessment
  • cyber security
  • scams
  • christmas
  • business email compromise

Book a free, no-obligation chat

No jargon, no pressure – just a friendly chat about your business.

Book a free chat