Abstract phishing advice — “watch out for suspicious emails” — doesn’t change behavior. Real examples do. Below are seven phishing attacks we’ve seen land in real Nashville small business inboxes in the last 12 months. Details have been anonymized, but the techniques are exactly what attackers are using today. Share this with your team at the next staff meeting; it’ll do more for your security posture than any annual training module.
1. The “DocuSign you didn’t expect” invoice trap
What the email looked like: Subject “Completed: Q4 Agreement – signature confirmation.” Branding that perfectly matched DocuSign. The body said an agreement had been signed and provided a “View Completed Document” button. The sender was notify@docuspign-mail.com — note the spelling.
Why it worked: The employee had genuinely used DocuSign for a real transaction the day before. The timing felt plausible. The button led to a Microsoft 365 credential-harvesting page that also captured the MFA token via a real-time proxy.
Red flags missed: Misspelled sender domain, urgency framing, unexpected login prompt after clicking “View.”
The fix: Phishing-resistant MFA (FIDO2 keys) would have stopped the token-capture attack cold. DNS filtering on newly registered domains would have blocked the phishing page.
2. The fake CFO gift card request
What the message looked like: SMS to a junior accounting staffer: “Hi, this is [CFO First Name]. I’m in a meeting and need you to buy $2,400 in Apple gift cards for a client thank-you. I’ll reimburse. Can you handle it now?” The SMS came from an unknown number.
Why it worked: The CFO’s name was on the company website. The staffer didn’t want to look uncooperative. SMS felt personal. The attacker had researched the org chart on LinkedIn.
Red flags missed: Unknown phone number, unusual request type, urgency, refusal to handle through normal channels.
The fix: A bright-line policy: no executive ever asks for gift cards, and any financial request over SMS is automatically escalated to a voice call on a known number.
3. The vendor email compromise ACH change
What the email looked like: A real invoice from a real vendor the business had paid for years. Sent from the vendor’s real email address. Said “Please note our updated banking information effective immediately” and included new ACH details at a bank in a different state.
Why it worked: Everything technical checked out. DKIM passed. SPF passed. The vendor’s account had been compromised two weeks earlier and the attacker had been sitting quietly, reading the invoice threads, waiting for the right moment.
Red flags missed: Sudden change in banking details, different-state bank without explanation, no phone call or prior warning from the vendor.
The fix: Written vendor verification policy — any change to banking details is verified by phone to a number already on file, never the number in the email.
4. The Microsoft Teams “voicemail” hoax
What the email looked like: “You have 1 new voicemail from +1 615-…” with a play button leading to a fake Teams login page.
Why it worked: Many Teams users do get voicemail notifications. The 615 area code was Nashville, matching the recipient’s location. The play button was a plausible UI element.
Red flags missed: Microsoft does not send unauthenticated voicemail emails like this, and the destination domain wasn’t microsoft.com.
The fix: Security awareness training that covers the Teams/voicemail phishing variant specifically, combined with URL rewriting that catches the fake login page.
5. The Google Drive OAuth consent attack
What the email looked like: “Your colleague [Real Name] shared ‘Q4 Budget’ with you” — a legitimate-looking Google Drive share notification. Clicking it led to a real Google consent screen for an app called “Google Docs” (a name the attacker registered on their own domain) requesting full mailbox access.
Why it worked: The consent screen was real Google UI. MFA didn’t stop it because the user was legitimately authenticating to Google. Once consent was granted, the attacker had persistent access that survived password resets.
Red flags missed: Unfamiliar app name, unusually broad permissions, no prior conversation about the document.
The fix: Admin-level OAuth app consent policy that requires approval for any app requesting more than basic profile scopes. Quarterly audit of granted permissions.
6. The “invoice overdue” callback phishing
What the email looked like: A plain text email — no links, no attachments — saying “Your GeekSquad subscription of $489.99 has renewed. To cancel, call 1-888-…” The From address was a throwaway Gmail account.
Why it worked: Email filters had nothing to block — no URL, no attachment. The panicked user called the number. The “support agent” walked them through installing AnyDesk for “a refund,” then used it to deploy ransomware over the weekend.
Red flags missed: Unexpected invoice from a service the company didn’t use, refund process that required installing remote access software.
The fix: Training that specifically covers callback phishing (“TOAD” attacks), and endpoint policy requiring admin approval for remote-access tool installation.
7. The QR code on the “parking ticket”
What it looked like: A physical flyer left on employees’ windshields in the company parking lot — a fake parking violation with a QR code “to pay the fine.” Scanning the QR led to a credential harvesting page that mimicked the company’s login portal.
Why it worked: Physical delivery bypassed every email control. Parking lot flyers felt authoritative. Most phones scanned QR codes without any security filtering.
Red flags missed: The flyer wasn’t from the actual parking vendor, and the URL preview on most phones would have shown a non-company domain.
The fix: MDM-pushed DNS filtering on mobile devices, and awareness training that extends to physical-world social engineering.
Pattern recognition: what every example has in common
| Attack | Trust hijack | Urgency | Bypasses one control |
|---|---|---|---|
| DocuSign | Brand familiarity | Expired agreement | Standard MFA |
| Fake CFO SMS | Authority | “I’m in a meeting” | Email filters |
| Vendor ACH change | Known relationship | “Effective immediately” | DMARC/SPF |
| Teams voicemail | Platform familiarity | Missed message | URL scanners |
| Google OAuth | Google UI trust | Shared document | MFA |
| Callback invoice | Financial anxiety | Auto-renew charge | Email filters (no links) |
| Parking QR | Physical authority | “Fine” framing | All digital controls |
Every one of these attacks succeeds by combining three elements: a trusted context, an urgent trigger, and a control gap. Address any one of the three and the attack usually fails.
Related services
- Phishing attack prevention
- Phishing attack methods
- Phishing protection software
- Cybersecurity services
- Managed IT services
Want to test your team with realistic examples like these? ClearMax runs targeted phishing simulations tuned to the attacks your industry actually sees. Book a free phishing posture review and we’ll send you your baseline phish-prone rate and a prioritized improvement plan.
Related ClearMax Services
Ready to Protect Your Business?
Get a free consultation with our team. We’ll assess your needs and build a custom IT solution — no obligation, no pressure.