Forget the Virus. The Hackers Want Your Identity Now

Posted: August 10, 2026Category:

Forget the virus. The hackers want your identity now.

Here’s what’s changed – and why “we’re too small to be a target” is the myth that quietly empties bank accounts in Northland.

A virus breaks your computer. It’s loud, it’s obvious, you know something’s wrong. But your identity – your email login – is worth far more to them. Because with it, they don’t break anything. They just become you.

How it plays out

They get into an email account – usually a stolen password, or a login someone got tricked into handing over. Then they go quiet. They sit there for a week or two and read your emails. They learn how you invoice, who pays you & what your invoices look like.

Then they send a real invoice – from your actual account, in your name, to your actual customer – with one thing changed. Their bank account number.

Your customer has no reason to blink. It’s your email. Your usual amount. So they pay it. The money’s gone before anyone notices – and these hit for tens, sometimes hundreds of thousands.

No virus. No alarm. Nothing “broke”. That’s exactly why it works – and why old-school antivirus never sees it.

The rule that stops it

Now the good news. You don’t stop this with fancy tech. You stop it with a simple rule everyone follows.

It’s actually one of the checks to earn SMB1001 Gold (a cyber security certification) – and yes, we run it on ourselves. In plain English:

  • Any request to change a supplier’s bank details gets treated as high risk – full stop.
  • A second person checks it – not the one who got the request.
  • You ring the supplier to confirm – on a number you already had, NOT the one in the email or on the invoice.
  • You write down the call (who you spoke to, when, what number), and the finance lead signs it off before anything changes.

And the golden rule – you NEVER change a bank account off an email alone. Even if it looks exactly like it came from someone you know.

Then back the habit up with the tech

  • Multi-factor authentication on every account (a code on your phone) – so a stolen password on its own is useless.
  • A conditional access policy that blocks logins from overseas. Most Northland businesses only ever log in from… Northland. Switch that on and it cuts around 90% of attacks dead on arrival – the bots trying to get in from the other side of the world simply can’t.

Do those three things and this whole scam falls over.

We don’t take ourselves too seriously – but we’re deadly serious about protecting your data.

Want to see how you’d score?

Take our free SMB1001 cyber readiness self-check, or get in touch & we’ll send you the exact invoice policy we use – nice and simple.

Contact us today