The Phishing Attacks Targeting Buffalo Businesses
Not all phishing looks the same. The mass-produced spam emails with obvious typos are easy to spot, but modern attacks are far more sophisticated. Here are the types we see most often in the Buffalo area:
Spear phishing targets a specific person. The attacker researches your company on LinkedIn or your website, then crafts an email that references real projects, real people, or real invoices. A bookkeeper at a Cheektowaga accounting firm might receive what appears to be a legitimate request from a client asking them to update banking details.
Business Email Compromise (BEC) is the most financially devastating form. The attacker either compromises or impersonates an executive's email account, then sends instructions to wire money, purchase gift cards, or share sensitive data. The FBI reported over $2.9 billion in BEC losses nationally in a single year, and small businesses are disproportionately targeted because they lack the verification procedures that larger companies have.
Credential harvesting sends you to a fake login page that looks identical to Microsoft 365, Google Workspace, or your bank. Once you enter your password, the attacker has full access to your account and everything connected to it.
How to Spot a Fake Email
Training your team to recognize phishing is the most cost-effective security measure you can implement. Here are the red flags that should trigger suspicion:
The most important habit to build is hovering over links before clicking them. On a computer, hold your mouse over any link and look at the actual URL in the bottom-left corner of your browser or email client. If the URL doesn't match what you expect, don't click it. On a phone, press and hold a link to preview the destination without opening it.
Email Filtering and Security Tools
Even the best-trained team will occasionally miss a cleverly designed phishing email. That's why technical controls are essential. Modern email security works in layers, each one catching threats that the others might miss.
Built-in filtering from Microsoft 365 or Google Workspace catches the majority of spam and known phishing campaigns. Microsoft Defender for Office 365 adds advanced threat protection including safe links (URLs are checked at click time) and safe attachments (files are opened in a sandbox before delivery).
Third-party email gateways like Barracuda, Proofpoint, or Mimecast add an additional layer of scanning before emails even reach your inbox. For businesses handling sensitive data or financial transactions, this extra layer is worth the investment.
Multi-factor authentication (MFA) is not technically email filtering, but it is your best defense if credentials do get stolen. Even if an attacker obtains a password through phishing, MFA prevents them from logging in without the second factor.
Quick win: If your business uses Microsoft 365, enable Security Defaults in Azure Active Directory. This turns on MFA for all users at no additional cost and blocks the majority of credential-based attacks.
SPF, DKIM, and DMARC: Protecting Your Domain
These three email authentication protocols work together to prevent attackers from sending emails that appear to come from your domain. If you have ever received a bounce notification for an email you didn't send, your domain is likely being spoofed, and these records are your fix.
SPF (Sender Policy Framework) is a DNS record that lists which mail servers are authorized to send email on behalf of your domain. When a receiving server gets an email claiming to be from yourdomain.com, it checks your SPF record to verify that the sending server is on the approved list.
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every outgoing email. The receiving server can verify that the email hasn't been altered in transit and that it genuinely came from your domain.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) ties SPF and DKIM together and tells receiving servers what to do when an email fails authentication: nothing, quarantine it, or reject it outright. DMARC also sends you reports showing who is trying to send email as your domain.
| Protocol | What It Does | Difficulty to Set Up |
|---|---|---|
| SPF | Lists authorized sending servers | Easy (single DNS TXT record) |
| DKIM | Cryptographically signs outgoing emails | Moderate (DNS record + provider config) |
| DMARC | Enforces SPF/DKIM and provides reports | Moderate (requires monitoring before enforcement) |
Setting these up correctly is critical. A misconfigured SPF record can cause your legitimate emails to land in spam, and jumping straight to a strict DMARC policy without testing can block real email. We recommend starting DMARC in "monitor only" mode (p=none) for at least two weeks, reviewing the reports, and then gradually moving to quarantine and reject.
What to Do If Someone Clicks a Bad Link
It happens. Despite training and filtering, someone on your team will eventually click a phishing link or open a malicious attachment. What matters most is how quickly you respond. Here is the step-by-step process we recommend:
Step 1: Disconnect from the network. If you suspect malware was downloaded, disconnect the computer from Wi-Fi or unplug the ethernet cable immediately. This limits the malware's ability to spread to other devices on your network.
Step 2: Change passwords immediately. If you entered credentials on a fake login page, change that password right away, along with any other accounts that use the same password. Do this from a different, known-safe device.
Step 3: Notify your IT team or provider. Time is critical. A fast response can mean the difference between a minor inconvenience and a full-scale data breach. Your IT provider can check for unauthorized access, revoke compromised sessions, and scan for malware.
Step 4: Report the email. In Outlook, use the "Report Phishing" button. In Gmail, click the three dots and select "Report phishing." This helps train the email provider's filters to catch similar emails for everyone.
Step 5: Monitor accounts. For the next 30 days, watch for unusual activity in the compromised account and any linked financial accounts. Enable login alerts if they aren't already on.
Training Your Team Against Phishing
Technology alone cannot stop phishing. Your employees are both the target and the best line of defense. Effective security awareness training doesn't have to be expensive or time-consuming, but it does need to be consistent.
Run simulated phishing tests at least quarterly. Services like KnowBe4, Proofpoint Security Awareness, and even Microsoft's built-in Attack Simulation Training let you send realistic fake phishing emails to your team and track who clicks. The goal isn't to punish anyone but to identify who needs extra training and to keep phishing awareness top of mind.
Keep training short and relevant. A 5-minute monthly refresher is more effective than a 2-hour annual seminar that everyone forgets by the following week. Focus on real examples, ideally ones that targeted your industry or region.
Create a no-blame reporting culture. If employees are afraid of getting in trouble for clicking a phishing link, they will hide the incident instead of reporting it. Make it clear that reporting a suspected phishing email, even if you already clicked it, is the right thing to do and will be treated as a positive action.
IT Service Areas — Erie County
Driram Group provides email security, phishing protection, and cybersecurity services to businesses throughout Erie County, New York. Whether you need help setting up SPF, DKIM, and DMARC records, configuring email filtering, or training your team to recognize phishing attempts, we are here to help.