A client emailed me asking whether a conversation was legitimate. It was not. Someone was emailing our clients using our company name and, of course, a generic Gmail address.
Everything else in the email looked convincing: a friendly request to run an audit, genuinely technical language, and screenshots from Google PageSpeed Insights. It read exactly like something we would send.
Why it worked
Two details made it dangerous. First, they were offering what looked like a legitimate service, then asking the client to pay into their own bank account. Second, and this is the part more people should know: the client never noticed the email address was different, because the Gmail app shows only the sender icon and display name, not the actual address.
That is the whole attack. Not clever code, just a display name and a plausible story. It is the mirror image of the fake RFQ emails aimed at agencies, where the same social engineering runs in the other direction.
What to tell your team and your clients
Expand the sender address before acting on anything, especially on mobile. Treat any change of bank details as untrusted until confirmed on a channel you already had. And if an audit or invoice arrives unprompted from a supplier you know, ring the person you actually deal with.
If you are hit by something like this, you can report it to Google. Worth doing, because the same template gets reused across hundreds of businesses.
Security is a relationship problem too
The reason my client caught it is that they felt able to ring and ask a slightly awkward question. That is worth more than any filter, and it is the practical value of being reachable quickly and of the care that makes clients comfortable asking.
The technical side still matters, of course, which is why I keep pushing owners not to become one of the hacked stores nobody wants to hear about and not to end up like the client who ignored a security audit.
If you want a security review that covers your process and not just your server, book a call.