View 39Security training events
Practical cyber security training for business owners, directors and teams.
View 39Security training events →A contact form or online order creates trust signals, but attackers can submit them too. Look for combinations of warning signs and verify unusual requests through independent channels.
Watch for unusual urgency, vague requests that do not match your services, pressure to move to WhatsApp or another channel immediately, inconsistent names/domains, unexpected attachments, requests to click unfamiliar file-sharing links and payment proposals that make little commercial sense.
Do not use links or phone numbers supplied in the suspicious message as your only verification route. Search for the organisation independently, check the sender domain, call a known published number and ask a colleague to review the request when money or sensitive information is involved.
A fraudster may offer to pay more than required and ask you to forward part of the money to a third party, supplier or “designer”. Treat unusual payment-routing requests as high risk. Do not send money merely because a payment appears pending or a screenshot claims it has been made.
No single signal proves fraud. Review unusual order value, repeated payment attempts, mismatched customer information, high-risk delivery requests, expedited shipping pressure and warnings from the payment gateway. Use the gateway’s own fraud and authentication tools.
Potentially. Treat unsolicited documents, archives and links cautiously. A form submission does not make an attachment safe. Where possible, restrict upload types, scan files and train staff not to enable macros or bypass security warnings.
For high-value or unusual enquiries, a quick independent call can be an effective verification step. A dedicated business number or phone system also gives the sales team a consistent process for callbacks and logging. See our website phone-number guide.
Use layered controls such as server-side validation, rate limiting, honeypots, challenge systems where proportionate and a WAF/bot-management service for persistent abuse. Avoid relying only on a hidden field or client-side JavaScript.
Stop the transaction or conversation long enough to verify it. It is better to delay a questionable order than to disclose credentials, open malware or send a fraudulent refund. Create a clear internal escalation route.