Top 5 Cyber Scams We Are Seeing Now
The email came in at 11pm. A red warning had taken over the entire screen of a client’s iPhone, telling her that her device was compromised and she needed to act immediately.
What bothered me most was the fear and anxiety replacing what should have been a peaceful evening, when a CEO was finally taking time for herself.
Instead, she was wondering whether we could get to her quickly enough before a catastrophe unfolded.
I messaged her back right away: Ignore it. Close the page. Everything is fine.
And everything was fine because we took a quick look.
That is usually how these situations end. Someone sees something alarming, asks us, and we tell them to close the tab. Not a big deal on our end.
But the threat is still real. It only takes a few more clicks from someone who decides it is too late to ask us for help, or that it looks urgent enough to handle alone.
That is exactly what the bad guys are counting on.
This kind of scam does not need you to be careless to succeed. It only needs you to be polite about the time of day and try to handle it alone.
I Do Not Actually Like Writing About This
I avoid writing about cybersecurity. Our job is to stay in charge and guard the doors so you never have to think about it.
But there is one part of this no tool or IT provider can solve for you: knowing when something does not look right.
Nobody Flipped a Switch
Most of us started with technology through simple experiences: a light switch, the play button on a VCR, and a keyboard that simply put the letter you pressed onto the screen.
On or off. Working or broken. Nothing in between.
That training runs deep, and it shows up in how people think about security. There is an assumption that somebody flipped a switch, security is now on, and the subject is closed.
I understand the appeal. It would be a much nicer world.
But the switch model is exactly what these five scams exploit. Most people assume they are covered, so if something lands asking them to act, chances are it must be clean and safe to trust.
Unfortunately, cybersecurity on does not mean scams are off.
Knowing what to look out for is an important part of staying safe. And no, this is not one of those articles listing a hundred things to be afraid of.
Here are the top five sneakiest scams we are actually catching this year at interior design studios, architecture firms, and other project-based businesses, explained plainly enough that you can recognize them the moment one shows up.
The Five We Keep Pulling Out of Real Offices
1. The fake error page
You are browsing on your phone or laptop, click something ordinary, and a warning takes over the screen. It matches the device you are holding: iPhone, Windows, or Mac.
These are careful copies. Same fonts, same colors, same calm official tone.
Then comes the ask: Call this number. Download this tool. Let someone in so they can help you fix it.
This is the one we see most often, and it is the only one on this list that has actually cost our clients something.
The fix is simple: close the browser and restart the computer. If the warning does not go away, or you are not certain it is fake, contact your IT partner before clicking, calling, or downloading anything.
2. A file shared from a platform you trust
Someone opens a free account on QuickBooks Online, PayPal, Dropbox, or OneDrive, then uses that platform’s own sharing tools to send you a document.
The notification genuinely comes from the platform. It clears every filter because there is nothing wrong with the email itself.
The problem is waiting inside the file, not in the message that carried it.
The fix: Before you open the file or act on the request, confirm it through a separate channel. Call, text, or start a new email with the person who supposedly sent it. Do not reply to the original message.
3. The login page that is not the login page
“A message was held back. Log in to release your email queue.”
“There is an unauthorized charge on your card. Log in to review it.”
The page they send you to is a pixel-for-pixel copy of the real one. You type your password, sometimes your verification code too, and it gets handed straight to the real site while someone else keeps the keys.
Your login works perfectly.
It just works for them, too.
The fix: Never use the link in the warning to investigate the warning. Go directly to the service instead.
If it claims there is a problem with your American Express card, type americanexpress.com into your browser and log in as you normally would. If it is about your email, open your email directly and check there.
If the issue is real, you will find it there.
4. The vendor whose inbox got taken over
This one is quiet, and it is the one that moves the most money.
An attacker gets inside a real inbox at a company you already work with: an accountant, supplies, or subcontractor you have used for years.
They read email threads. They wait. Then they reply inside a conversation you have been having for weeks and ask you to update the payment details on an invoice.
Nothing about that email is fake. The account is real, the history is real, and the person writing back is not who you think.
The fix: Treat any unexpected payment or account change as something to confirm outside the email thread. Call your vendor using a phone number you already have on file and ask whether the request is real.
5. Homework, done by machine
AI did not just make the writing flawless. It made the research instant.
Anything public about you or the people around you, from social media and professional networks to data brokers who sell this information for a living, can be gathered and combined in seconds.
Then it gets shaped into a request that names a real project, a real colleague, or a real detail from last month.
That is what makes it land.
The old advice was to look for bad grammar. There is no bad grammar left.
The fix: Assume that some details about you, from your home address to the make and model of your car, may be public information.
Do not let a message’s familiarity alarm you or earn your trust. Slow down, evaluate the request, and confirm it before taking any action.
What This Costs a Project-Based Business
Unfortunately, over the last couple years, a few people clicked a bad link. They followed the instructions on a fake error page and gave a stranger full access to their computer.
We caught it fairly quickly and handled it. We keep backups for the day something truly goes sideways.
None of our clients have had to deal with ransomware. But on a few occasions, someone had to step away from their technology for a day while we made sure the machine was clean.
A day. During a deadline week, with a client presentation on Thursday.
That is billable time gone, plus the anxiety of not knowing how far it went, plus the awkwardness of explaining to everyone why you had to step away.
The Part We Truly Need You For
We guard the doors, and we are good at it. Most of this never reaches you at all.
But when a convincing warning appears on your screen at 10pm, no product or service can decide for you whether it is safe to act on. That is the moment awareness matters.
That gap is the whole game, and awareness is the only thing that counters it.
Which is why the five examples above are worth more than any product you can buy or any promise someone can make. Recognition is the last defense. If you have seen or heard of the shape of what’s on your screen, you pause.
And the pause is where it dies.
When you are not sure, ask. The question you feel silly asking at 11pm may be the off-ramp that keeps you out of trouble.
You Were Trained on Light Switches
None of this is a failure on your part. We were all raised on technology that was either working or broken.
What we have now has layers, and layers are harder. I am not going to pretend otherwise.
But there is no running away from it either. Technology is how you design, present, bill, and get paid.
So having a trustworthy and fast IT partner to turn to is not a luxury. It is a necessity.
If something looks off and you want a second set of eyes before you act on it, send it over. That is what we are here for, and it takes us about a minute.
The scams will keep getting better.
Being aware of their shape to recognize them falls on you.
And it is the part that works at 11pm.