A client calls and says they received a strange email from you yesterday.
It had your name, your email address, and perhaps even your usual signature. Everything looked normal until they noticed that the link pointed somewhere suspicious. Thankfully, they did not click it.
They want to know whether you sent it.
You did not.
For many small business owners, this is the first warning that something may be wrong. No files were encrypted. No ransom message appeared. Nobody was locked out of the system. Instead, a trusted client noticed something suspicious before the business owner did.
That phone call may have prevented a much larger problem.
Did Someone Actually Access Your Email?
An email that appears to come from your address does not automatically mean your mailbox was hacked.
Criminals can use email spoofing to forge the sender information shown in the From field. The message may display your name and address even though it never passed through your email account. Microsoft describes spoofing as the forgery of sender information to make a message appear as though it originated somewhere else.
Several possibilities need to be investigated:
The attacker may have spoofed your email address.
They may have gained access to your actual mailbox.
They may have compromised a computer, mobile device, or connected application that has permission to send email.
They may also have collected your signature, writing style, client names, or previous messages from an earlier data leak.
The difference matters. Changing your password will not stop someone who is simply spoofing your domain. Configuring email authentication will not remove an attacker who is already signed into your mailbox.
A proper investigation should review the original message headers, recent account sign-ins, sent messages, deleted messages, forwarding settings, connected applications, and mailbox rules.
The Attacker May Not Want You to Notice
Not every attacker wants to lock you out.
Quiet access can be far more valuable. Someone inside your mailbox may be able to read conversations, learn how you communicate, identify important clients, and wait for the right opportunity.
They may create hidden or unfamiliar mailbox rules that automatically forward certain messages, move warnings into obscure folders, or delete replies from suspicious recipients. Microsoft lists unexpected forwarding, unusual inbox rules, missing messages, suspicious sent items, and unexplained account activity among the warning signs of a compromised Microsoft 365 account.
This allows the criminal to remain in the background while you continue using the account normally.
The Federal Bureau of Investigation received 24,768 business email compromise complaints during 2025, with reported losses exceeding $3 billion. Those figures only represent incidents reported to the Internet Crime Complaint Center, so they do not capture every affected business.
Three Ways Your Business Can Be Used Against Others
Your identity can be forged.
A criminal can send phishing emails that appear to come from your domain without accessing your mailbox.
This is where SPF, DKIM, and DMARC become important. These email authentication records allow receiving mail systems to evaluate whether a message claiming to come from your domain was sent through an authorized source. Proper configuration can make it harder for criminals to impersonate your domain successfully.
These protections are especially important for accountants, attorneys, medical offices, consultants, contractors, and other businesses whose clients regularly receive documents, invoices, and links through email.
Your real mailbox can be taken over.
When an attacker controls the actual account, the message is no longer merely an imitation. It is being sent through a legitimate mailbox.
Your name, signature, contact history, and previous conversations may all be available. The attacker can create a message that fits naturally into an existing relationship.
A client is much more likely to open a document, follow payment instructions, or sign into a fake portal when the request appears in a genuine email conversation.
This is why business email compromise is about more than spam. It turns the trust your company has earned into part of the attack.
Your equipment can become part of a botnet.
Computers, routers, cameras, and other internet-connected devices can be infected or exploited and then added to a botnet.
A botnet is a collection of compromised devices controlled remotely. Those devices may be used to send malicious traffic, distribute malware, host fraudulent content, or participate in distributed denial of service attacks.
The device may slow down, behave unpredictably, or show other warning signs. In some cases, however, the activity produces little that an ordinary user would immediately notice. CISA has documented botnets built from vulnerable internet-connected devices and widespread campaigns targeting home and office routers.
Your employees could be working normally while equipment inside your business is communicating with criminal infrastructure.
Your Reputation May Be Damaged Before Your Computer Is
The immediate concern is whether somebody clicked the link or lost money.
The longer-term concern is trust.
A client who receives a convincing phishing message from your address may begin questioning how securely their information is being handled. That doubt can be especially damaging for professional service businesses where clients regularly share tax records, financial information, medical details, legal documents, or login credentials.
Telling the client that you did not know about the activity may be honest, but it does not erase the experience.
Massachusetts also has data breach notification requirements for businesses that own or license certain personal information belonging to Massachusetts residents. In addition, 201 CMR 17.00 establishes minimum safeguards for protecting that information. Whether a specific email incident triggers reporting requirements depends on what happened, what information was involved, and whether it was acquired or used without authorization.
This is one reason suspected compromises should be documented and investigated rather than handled with a quick password change and forgotten.
Multi-Factor Authentication Is Essential, but It Is Not the Entire Solution
Multi-factor authentication is one of the strongest practical protections available for business email accounts.
Microsoft research found that MFA reduced the risk of account compromise by more than 99 percent in the population studied.
However, not every MFA method provides the same protection.
Text message codes are better than relying on a password alone, but they can still be stolen through phishing, phone number transfers, and attacks against mobile networks. CISA recommends phishing-resistant options, such as security keys and passkeys, wherever available.
Businesses also need to review:
- Mailbox forwarding and inbox rules
- Account sign-in logs
- Authorized applications and connected services
- SPF, DKIM, and DMARC records
- Administrator accounts and permissions
- Router and device firmware
- Endpoint security and monitoring
- Network separation for sensitive or untrusted devices
CISA recommends endpoint detection, network logging, updated software and firmware, and network segmentation as important ways to detect malicious activity and limit how far an intrusion can spread.
Monitoring Is What Turns a Hidden Problem Into a Visible One
Security software is important, but installing it once is not the same as actively monitoring a business.
Someone needs to review alerts, investigate unusual sign-ins, confirm that updates are being installed, watch for suspicious communication, and respond when something changes.
That visibility is often what small businesses are missing.
It is not necessarily because the owner has been careless. Most owners are focused on serving clients, managing employees, and keeping the business running. They are not spending each morning reviewing authentication reports and firewall logs.
Unfortunately, criminals understand that.
Make Sure Your Business Is Not Being Used Against Your Clients
Bob’s Computer Service helps small businesses in Springfield, MA, and Chicopee review their email security, computers, networks, and connected equipment.
I can help verify multi-factor authentication, inspect suspicious mailbox activity, review Microsoft 365 or Google Workspace security, check email authentication records, and implement ongoing computer and network monitoring.
You should not have to learn that your business has a security problem from one of your clients.




