The Most Dangerous Risks in Your Business Do Not Swim on the Surface

Three Ways Cybercriminals Are Circling Oregon Businesses This Summer

On the surface, the water looks calm.

That is what makes Shark Week compelling every year. The danger is never visible from above. It is already moving underneath, quietly, before anything breaks the surface.

Cybercriminals operate the same way.

The threats businesses face right now are designed to blend into normal operations, appearing as a routine invoice, a familiar login request, or a message from a trusted vendor, until the moment something breaks, money moves, or systems go down.

During summer months, when schedules shift, employees travel, and oversight gets thinner, attackers know businesses are often paying less attention. They plan around it.

Here are three ways they are circling right now.

1. Fake Invoices and Vendor Impersonation

Attackers do not always need to break into your systems.

In many cases, they just need to send one believable email.

This is called business email compromise, and it works by impersonating a vendor, supplier, or executive your team already trusts. The email arrives looking completely normal. Someone on your team pays the invoice. By the time anyone realizes the request was not legitimate, the money is gone.

These attacks spike during summer for a simple reason. When the person who normally approves payments is on vacation, requests get rerouted to people who do not always know what normal looks like. Temporary stand-ins are less likely to question urgency. Attackers design around exactly that.

FBI Internet Crime Complaint Center: Business Email Compromise

What is business email compromise and how does it work?

Business email compromise is a type of cyberattack where criminals impersonate a trusted contact, such as a vendor, supplier, or executive, to trick employees into transferring money or sharing sensitive information. These attacks rely on social engineering rather than technical exploits, which makes them harder to catch with software alone.

The fix is straightforward to implement. Build a verification step for any financial request that arrives via email. A quick confirmation call to a known number, not the number listed in the email, stops most of these before they go anywhere.

According to the FBI's Internet Crime Complaint Center, business email compromise remains one of the costliest cyber threats facing organizations of all sizes.

2. Phishing Attacks That Target Distracted Employees

Phishing works because it is engineered around how people behave when they are busy.

A distracted employee sees a password reset notification and clicks the link without examining it. Someone gets a text that appears to come from IT. An email arrives right before a meeting asking for urgent approval on a wire transfer. Nobody stops to verify because stopping feels like losing time.

That urgency is intentional. Speed is a weapon attackers use against you. Slowing down is how you take it away from them.

CISA — Phishing Guidance

Why do phishing attacks increase during summer?

Summer creates more opportunities for phishing because work routines become less consistent. Employees are covering for coworkers, managing family schedules, and responding to requests outside their normal workflow. Attackers know that distracted people make faster decisions with less scrutiny and they design their attacks around exactly that behavioral window.

The most effective protection is not just a software solution. It is culture.

Employees need to feel comfortable slowing down when something seems off… an unexpected login request, a payment instruction that arrived out of nowhere, a link in an email they were not expecting. That comfort does not come from a one-time training session. It comes from a workplace where taking an extra thirty seconds to verify something is treated as the right call, not an inconvenience.

Learn more about Managed Cybersecurity: https://10dtech.com/services/managed-cybersecurity

3. Third-Party Risks That Travel Fast

When a vendor with access to your systems gets compromised, the threat does not stay contained.

It travels directly into your environment through whatever connection they have to your business.

This is supply chain exposure, and most businesses have significantly more of it than they realize. Software tools connected to your network. Service providers holding credentials. Contractors whose access was never removed after a project ended. Each of these represents a path that most business owners have never fully mapped.

NIST supply chain risk management

What is supply chain cybersecurity risk?

Supply chain cybersecurity risk refers to the exposure created when vendors, contractors, or software providers with access to your systems are compromised. Because these connections are often trusted by default, attackers can use them to move into your environment without triggering the same alerts as a direct attack.

Outsourcing a service does not outsource accountability.

Getting clear on your supply chain exposure means being able to answer three questions:

  • Which vendors can access your data or systems?
  • What specifically are they connecting to?
  • Who inside your organization is responsible for managing those relationships?

If those answers are not clear, the exposure is already there. The only question is whether you find it first.

For credit unions, healthcare organizations, CPA firms, and law firms, vendor risk management is also a compliance requirement. Regulators expect organizations to know who has access to sensitive systems and data, and to demonstrate active oversight of those relationships.

Learn more about IT Assessments & Strategy Consulting: https://10dtech.com/services/it-assessments-consulting

By the Time You See It, It Is Already Moving

Sharks do not announce themselves.

Neither do the cybercriminals targeting your business right now.

The organizations that get hit are not always the ones that ignored obvious warning signs. They are often the ones that assumed everything was fine because nothing looked wrong. Summer is when schedules get loose, attention drifts, and the water looks the calmest. It is also when attackers are most active.

The good news is that these are not unsolvable problems. Clear verification processes, a culture that supports slowing down when something feels off, and a current picture of who has access to what … those are practical steps that meaningfully reduce exposure without requiring a complete technology overhaul.

2026 marks 10D Tech's twentieth year serving organizations throughout Oregon and Southwest Washington. We help businesses get a clear picture of where they are exposed before something goes wrong.

Learn more about Managed Cybersecurity: https://10dtech.com/services/managed-cybersecurity

Learn more about Emergency IT Support & Incident Response: https://10dtech.com/services/emergency-it-support

Ready to Get a Clear Picture of Where You Stand?

Schedule a complimentary 15-minute assessment and get a straight answer on where your technology stands today.

Schedule yours at 10dtech.com/15min-assessment or call us directly.

Albany, Corvallis, Eugene, Bend: 541-243-4103

Portland, Salem: 971-915-9103

No pressure. No scare tactics.

Just a practical conversation about how technology can help your organization move forward with confidence.

What is business email compromise?

Business email compromise is a cyberattack where criminals impersonate a trusted contact to trick employees into transferring money or sharing sensitive information. It relies on social engineering rather than technical exploits, which makes it harder to catch with software alone and more dependent on employee awareness and verification processes.

Why do cyberattacks increase in summer?

Summer creates more opportunities for attacks because work routines become less consistent. Employees are covering for coworkers, managing vacations, and responding to requests outside their normal workflow. Attackers specifically design phishing and social engineering campaigns around these behavioral windows.

What is supply chain cybersecurity risk?

Supply chain cybersecurity risk is the exposure created when vendors, contractors, or software providers with access to your systems are compromised. Because these connections are often trusted by default, attackers can move into your environment without triggering the same alerts as a direct attack.

How can businesses reduce phishing risk?

The most effective approach combines employee awareness with security controls. This includes multi-factor authentication, email filtering, a workplace culture that supports pausing to verify unusual requests, and managed cybersecurity monitoring that identifies suspicious activity before it becomes a breach.

How does 10D Tech help businesses manage cybersecurity?

10D Tech has served organizations throughout Oregon and Southwest Washington for twenty years. We help businesses identify exposure across vendors, employee behavior, and day-to-day operations before something goes wrong. Schedule a complimentary 15-minute assessment at 10dtech.com/15min-assessment. Albany, Corvallis, Eugene, Bend: 541-243-4103. Portland, Salem: 971-915-9103.