• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Hackers Are Now Breaking Into Your Purchase Orders

By
Jeremy Quittner
Jeremy Quittner
Down Arrow Button Icon
By
Jeremy Quittner
Jeremy Quittner
Down Arrow Button Icon
August 10, 2016, 10:27 AM ET
The word 'password' is pictured on a computer screen in this picture illustration taken in Berlin
The word 'password' is pictured on a computer screen in this picture illustration taken in Berlin May 21, 2013. The Financial Times' website and Twitter feeds were hacked May 17, 2013, renewing questions about whether the popular social media service has done enough to tighten security as cyber-attacks on the news media intensify. The attack is the latest in which hackers commandeered the Twitter account of a prominent news organization to push their agenda. Twitter's 200 million users worldwide send out more than 400 million tweets a day, making it a potent distributor of news. REUTERS/Pawel Kopczynski (GERMANY - Tags: CRIME LAW SCIENCE TECHNOLOGY) - RTXZUYOPhotograph by Pawel Kopczynski — Reuters

Business owners beware: hackers are finding new ways to use your email against you.

As financial institutions have gotten smarter about fraudsters conducting account takeovers, cybercriminals are going directly after businesses, breaking into their email accounts and manipulating purchase orders.

The attacks, reported last week by the Wall Street Journal, are more sophisticated than previous efforts. As it is, businesses still fall prey to email scams that involve hackers using phony email accounts to pose as company executives and suppliers.

In the new breed of attacks, cybercriminals gain access to an entire email chain by hacking into either a buyer or seller’s email account. They scan for high-value transactions, according to network security firm SecureWorks, which first documented the trend, and then set up an automatic relay that forwards all new correspondence between a buyer and a seller to the fraudsters first. Ultimately, hackers alter legitimate purchase orders as they are emailed, instructing the buyer to wire payment to a fraudulent bank account.

Such attacks are on the rise as criminals have shifted their tactics, moving away from targeting banks, which have gotten better at detecting fraud, to smaller businesses, which typically are poor at detecting hack attacks, says Julie Conroy, research director for Aite Group, a research and advisory firm specializing in financial services.

 

The attacks are exacerbated by a general small business reliance on Webmail, cloud-based email programs that are cheaper than dedicated email servers, and easier to compromise, SecureWorks says.

“As long as they can get access to one side’s email, they can pull this off,” says Joe Stewart, director of malware research for SecureWorks, based in Atlanta.

In the U.S. alone, more than 14,000 businesses have lost close to $1 billion since 2013, according to a June report from the Federal Bureau of Investigation. There has been a 1,300% increase in reports of such crimes since 2015, the FBI says.

Here are five things that experts says small-business owners can do to protect themselves.

1. Create strong passwords for all of your accounts and never reuse them for other accounts. Hackers have been able to compromise business accounts following break-ins at sites with lots of users, such as Twitter, where they snag usernames and passwords, and then try them elsewhere.

2. Double-check any emailed request for payment. The best way to do that is pick up the phone and call to verify the payment request or purchase order, Conroy says. Don’t use email, as that may already be compromised. Often the emails relayed by the hackers differ from the real ones by only one letter or symbol, which makes it difficult to spot them as fraudulent. “When you do see a new set of payment information via email, take the time to pick up the phone and call the person that sent it,” Conroy says.

3. After an attack, act fast. If your computers have been compromised by malware, you may need to call in a forensics team to find out how it’s affected your network. That can be a costly endeavor, costing upwards of $15,000, Conroy says.

4. Install business grade malware and spyware software. Symantec, McAfee and Webroot all offer products that can help spot suspicious behavior, security experts say.

5. Use a virtual private network (VPN) or require two-factor authentication for your email server. VPN software provides a secure connection into your network. Two-factor authentication requires users to provide an extra layer of identifying information when logging in. You might also consider changing to a dedicated email server. A dedicated server would cost upwards of $5,000 to purchase outright, says Stewart, who adds such servers can also be rented from providers for between $5 and $100 a month. “[These things] will go a long way toward keeping out low-level hackers,” Stewart says.

Another resource business owners may want to consider is the Small Business Administration, whose website has a free tutorial page about cybersecurity.

 

 

 

About the Author
By Jeremy Quittner
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Meta’s threat to quit New Mexico ‘is showing the world how little it cares about child safety,’ AG says
LawMeta
Meta’s threat to quit New Mexico ‘is showing the world how little it cares about child safety,’ AG says
By Catherina GioinoApril 30, 2026
2 hours ago
Moreno gestures with his hand
PoliticsU.S. Senate
A ‘no-brainer’: Senate unanimously bans members and staff from using prediction markets
By Mary Clare Jalonick and The Associated PressApril 30, 2026
3 hours ago
Kevin Warsh, nominee for chairman of the Federal Reserve.
BankingFederal Reserve
Former Fed economist raises alarm on Warsh after historically partisan vote: ‘this is not normal is going to be a theme’
By Eva RoytburgApril 30, 2026
3 hours ago
Landry speaks a podium wearing a white cowboy hat.
PoliticsSupreme Court
Two days before early voting starts, Louisiana suspends its congressional primaries after SCOTUS knocks majority-minority districts
By Sara Cline, Jack Brook, David A. Lieb and The Associated PressApril 30, 2026
3 hours ago
A banner depicting portraits of Iran's late Supreme Leader Ayatollah Ali Khamenei and Ayatollah Mojtaba Khamenei
PoliticsIran
Iranian supreme leader says the only place Americans belong in the Gulf is ‘at the bottom of its waters’
By Jon Gambrell, Aamer Madhani and The Associated PressApril 30, 2026
3 hours ago
Mike Johnson speaks at a podium.
PoliticsDepartment of Homeland Security
After warnings that funding could ‘run out’ for TSA workers, House approves bill to fund DHS, leaves out ICE
By Lisa Mascaro and The Associated PressApril 30, 2026
5 hours ago

Most Popular

Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
3 days ago
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
Big Tech
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
By Alexei OreskovicApril 29, 2026
22 hours ago
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
Banking
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
By Eva RoytburgApril 29, 2026
1 day ago
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
Economy
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
By Eleanor PringleApril 29, 2026
2 days ago
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
AI
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
By Sasha RogelbergApril 28, 2026
3 days ago
With no end in sight, Trump considers new options in Iran war—including the ‘Dark Eagle’ hypersonic missile
Big Tech
With no end in sight, Trump considers new options in Iran war—including the ‘Dark Eagle’ hypersonic missile
By Jim EdwardsApril 30, 2026
14 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.