Social Engineering Attacks on Perth Small Business -- Perth IT Care
A Perth tradie gets a call mid-morning. The caller knows their business name, their internet provider, and even the rough suburb where they operate. There's a problem with their connection — something technical, something urgent — and the helpful bloke on the other end just needs remote access to sort it out. Four minutes later, the tradie has handed over full control of their computer. No malware was involved. No phishing link was clicked. Just a convincing voice and a manufactured sense of urgency.
That's social engineering. And your firewall had nothing to do with stopping it — because it never got involved.
Why Social Engineering Attacks Work on Small Business
Most Perth small businesses have put something in place on the technical side. Antivirus, maybe a decent router, probably Microsoft 365 with some default security settings. That's not nothing. But social engineering attacks sidestep the technology entirely and go straight for the person.
The logic is straightforward: it's much easier to convince someone to hand over access than to crack a properly secured system. People are helpful by nature. They respond to authority. They don't want to seem difficult or suspicious. Attackers know this, and they script their calls and emails around it.
Perth small businesses are a particularly attractive target. There's no dedicated IT or security staff to escalate to. Decisions get made quickly by one or two people. And because the business feels small and local, owners often assume they're not worth a scammer's time. They are.
The Main Techniques Being Used Right Now
Pretexting: Fake Authority, Real Urgency
Pretexting is when an attacker builds a believable cover story before making contact. The most common versions in Australia involve impersonating the ATO, Microsoft, or a bank.
The call follows a familiar script: there's a problem with your account, a suspicious transaction, a compliance issue, a suspended service. The urgency is engineered to short-circuit your thinking. When someone tells you the ATO has flagged your ABN and you have 30 minutes to respond before your account is frozen, you stop asking whether the call is legitimate and start trying to fix the problem.
The fix is always the same: never act on an unsolicited contact. Hang up, find the organisation's official number yourself, and call back. If it was real, they'll still be there.
Business Email Compromise: The Expensive One
Business Email Compromise (BEC) is one of the costliest cyber threats to Australian businesses, according to the ACSC. The attack is simple: an attacker impersonates a supplier, a director, or a business partner and asks for a payment to be redirected. The email looks legitimate. Sometimes it's sent from a compromised real account. Sometimes it's a lookalike domain that's close enough to miss on a quick read.
The money leaves. It's usually gone within hours.
BEC works because it exploits existing trust relationships. You already pay that supplier. You already follow that director's instructions. The attacker doesn't need to hack your system — they just need to intercept or imitate one email at the right moment. Our post on business partner security risks covers how third-party relationships become attack vectors, which is worth reading alongside this.
For the email security side of BEC — filtering, authentication, what actually catches these before they land — phishing protection for Perth businesses covers the technical controls in more detail.
Vishing: When Caller ID Is Useless
Vishing is voice phishing — the phone call version. The tradie at the start of this post was hit with a vishing attack.
What makes it difficult to defend against: caller ID spoofing means the number on your screen can be made to look like anything. An “unknown number” warning is effectively useless. The call can appear to come from your internet provider, your bank, or a government department.
The only reliable defence is a verification procedure that doesn't depend on trusting the incoming call. If someone calls claiming to be from your ISP, tell them you'll call back on the number on your account statement. A legitimate provider won't object. A scammer will push back hard, because the callback breaks their script.
Quid Pro Quo: The Fake IT Support Call
This one is subtle. An attacker calls claiming to be from IT support — sometimes your provider, sometimes a generic “technical support team.” They've noticed a problem with your system. It needs fixing immediately.
The victim didn't know there was a problem, because there wasn't one until the attacker created it. The attacker manufactures the crisis and sells the solution in the same call. By the time someone grants remote access to “fix” the issue, they're handing over the keys.
The defence here overlaps with vishing: verify who you're talking to before you give them anything. If someone calls you unsolicited offering to fix a technical problem, treat it as suspicious by default.
Three Controls That Actually Reduce Your Exposure
1. Verified Callback Procedures
Set a simple rule: no one authorises a payment, grants remote access, or changes account details based on an incoming call or an email reply. Every request that touches money, credentials, or access gets verified via a separate channel — a phone number your business already has on file, not one provided in the suspicious email.
For payment requests specifically, a quick call to confirm a change of bank details has stopped countless BEC attacks. It feels like extra friction. That's the point.
2. MFA on Everything That Matters
If an attacker socially engineers a password out of a staff member, MFA means that credential alone isn't enough to get in. It doesn't make your accounts unbreachable, but it adds a layer that most opportunistic attackers won't bother pushing through.

