Your sales team is trained to chase every lead — which is exactly why attackers now pose as customers. A fake enquiry is a friendly-looking door straight past your defences.
Why sales is the target
Salespeople open attachments, click links and reply quickly — that's their job. A malicious "quote request" or "purchase order" exploits that helpfulness.
Spotting a fake lead
- Generic company details that don't check out
- Attachments named like "RFQ" or "PO" you didn't expect
- Pressure to click a link to "view the requirements"
Training without slowing sales down
You don't need to make your team paranoid — just give them one habit: verify unusual requests before opening anything. A quick check of the sender's domain and a pause before clicking stops most attacks cold.
If you'd like a plain-English session tailored to your team, let's talk.