Abstract phishing advice — “watch out for suspicious emails” — doesn’t change behavior. Real examples do. Below are seven phishing attacks we’ve seen land in real Nashville small business inboxes in the last 12 months. Details have been anonymized, but the techniques are exactly what attackers are using today. Share this with your team at the next staff meeting; it’ll do more for your security posture than any annual training module.

1. The “DocuSign you didn’t expect” invoice trap

What the email looked like: Subject “Completed: Q4 Agreement – signature confirmation.” Branding that perfectly matched DocuSign. The body said an agreement had been signed and provided a “View Completed Document” button. The sender was notify@docuspign-mail.com — note the spelling.

Why it worked: The employee had genuinely used DocuSign for a real transaction the day before. The timing felt plausible. The button led to a Microsoft 365 credential-harvesting page that also captured the MFA token via a real-time proxy.

Red flags missed: Misspelled sender domain, urgency framing, unexpected login prompt after clicking “View.”

The fix: Phishing-resistant MFA (FIDO2 keys) would have stopped the token-capture attack cold. DNS filtering on newly registered domains would have blocked the phishing page.

2. The fake CFO gift card request

What the message looked like: SMS to a junior accounting staffer: “Hi, this is [CFO First Name]. I’m in a meeting and need you to buy $2,400 in Apple gift cards for a client thank-you. I’ll reimburse. Can you handle it now?” The SMS came from an unknown number.

Why it worked: The CFO’s name was on the company website. The staffer didn’t want to look uncooperative. SMS felt personal. The attacker had researched the org chart on LinkedIn.

Red flags missed: Unknown phone number, unusual request type, urgency, refusal to handle through normal channels.

The fix: A bright-line policy: no executive ever asks for gift cards, and any financial request over SMS is automatically escalated to a voice call on a known number.

3. The vendor email compromise ACH change

What the email looked like: A real invoice from a real vendor the business had paid for years. Sent from the vendor’s real email address. Said “Please note our updated banking information effective immediately” and included new ACH details at a bank in a different state.

Why it worked: Everything technical checked out. DKIM passed. SPF passed. The vendor’s account had been compromised two weeks earlier and the attacker had been sitting quietly, reading the invoice threads, waiting for the right moment.

Red flags missed: Sudden change in banking details, different-state bank without explanation, no phone call or prior warning from the vendor.

The fix: Written vendor verification policy — any change to banking details is verified by phone to a number already on file, never the number in the email.

4. The Microsoft Teams “voicemail” hoax

What the email looked like: “You have 1 new voicemail from +1 615-…” with a play button leading to a fake Teams login page.

Why it worked: Many Teams users do get voicemail notifications. The 615 area code was Nashville, matching the recipient’s location. The play button was a plausible UI element.

Red flags missed: Microsoft does not send unauthenticated voicemail emails like this, and the destination domain wasn’t microsoft.com.

The fix: Security awareness training that covers the Teams/voicemail phishing variant specifically, combined with URL rewriting that catches the fake login page.

5. The Google Drive OAuth consent attack

What the email looked like: “Your colleague [Real Name] shared ‘Q4 Budget’ with you” — a legitimate-looking Google Drive share notification. Clicking it led to a real Google consent screen for an app called “Google Docs” (a name the attacker registered on their own domain) requesting full mailbox access.

Why it worked: The consent screen was real Google UI. MFA didn’t stop it because the user was legitimately authenticating to Google. Once consent was granted, the attacker had persistent access that survived password resets.

Red flags missed: Unfamiliar app name, unusually broad permissions, no prior conversation about the document.

The fix: Admin-level OAuth app consent policy that requires approval for any app requesting more than basic profile scopes. Quarterly audit of granted permissions.

6. The “invoice overdue” callback phishing

What the email looked like: A plain text email — no links, no attachments — saying “Your GeekSquad subscription of $489.99 has renewed. To cancel, call 1-888-…” The From address was a throwaway Gmail account.

Why it worked: Email filters had nothing to block — no URL, no attachment. The panicked user called the number. The “support agent” walked them through installing AnyDesk for “a refund,” then used it to deploy ransomware over the weekend.

Red flags missed: Unexpected invoice from a service the company didn’t use, refund process that required installing remote access software.

The fix: Training that specifically covers callback phishing (“TOAD” attacks), and endpoint policy requiring admin approval for remote-access tool installation.

7. The QR code on the “parking ticket”

What it looked like: A physical flyer left on employees’ windshields in the company parking lot — a fake parking violation with a QR code “to pay the fine.” Scanning the QR led to a credential harvesting page that mimicked the company’s login portal.

Why it worked: Physical delivery bypassed every email control. Parking lot flyers felt authoritative. Most phones scanned QR codes without any security filtering.

Red flags missed: The flyer wasn’t from the actual parking vendor, and the URL preview on most phones would have shown a non-company domain.

The fix: MDM-pushed DNS filtering on mobile devices, and awareness training that extends to physical-world social engineering.

Pattern recognition: what every example has in common

AttackTrust hijackUrgencyBypasses one control
DocuSignBrand familiarityExpired agreementStandard MFA
Fake CFO SMSAuthority“I’m in a meeting”Email filters
Vendor ACH changeKnown relationship“Effective immediately”DMARC/SPF
Teams voicemailPlatform familiarityMissed messageURL scanners
Google OAuthGoogle UI trustShared documentMFA
Callback invoiceFinancial anxietyAuto-renew chargeEmail filters (no links)
Parking QRPhysical authority“Fine” framingAll digital controls

Every one of these attacks succeeds by combining three elements: a trusted context, an urgent trigger, and a control gap. Address any one of the three and the attack usually fails.

Related services

Want to test your team with realistic examples like these? ClearMax runs targeted phishing simulations tuned to the attacks your industry actually sees. Book a free phishing posture review and we’ll send you your baseline phish-prone rate and a prioritized improvement plan.

Related ClearMax Services

Ready to Protect Your Business?

Get a free consultation with our team. We’ll assess your needs and build a custom IT solution — no obligation, no pressure.

Book Free Assessment Call 833-306-3168

Leave a Reply

Your email address will not be published. Required fields are marked *