Issue #1 · June 25, 2026 · 7 min read
Issue #1 — Fake invoices, a note-taker that keeps listening, and one 15-minute fix
Welcome to the first issue. This week: the fake-invoice trick that's getting past small vendors, what your free AI meeting note-taker actually does with the recording, and the one setting that blocks most account takeovers.
All guidance checked against current FTC, CISA, and NIST small-business resources; no unsupported statistics used.
9 sources cited across this issue
top story The Big One: fake-invoice emails are getting past small vendors
If you pay other businesses by email — a supplier, a contractor, a landlord — you’re a target for one of the oldest scams that’s still working: the fake invoice. It looks like routine business mail: a familiar vendor name, a real-looking invoice attached or linked, sometimes a note that “our bank details have changed.” The email account it comes from might even be a real vendor’s account that got broken into, which is why it’s so convincing.
What makes this version effective isn’t technical trickery — it’s patience. Scammers increasingly study a business’s actual email threads first, so the fake invoice arrives at a plausible time, references a real project, and uses the vendor’s actual tone. A busy bookkeeper with ten other things to do has no reason to be suspicious.
What it means for you: the danger isn’t a virus, it’s a wire transfer to the wrong account that you can’t get back. Any invoice with new payment details deserves a second channel of confirmation — a phone call to a known number, not a reply to the email.
What to do: before paying any invoice with changed bank details, call the vendor using a phone number you already have on file (not one from the email) and confirm verbally. Make that a standing rule for anyone in your business who pays bills.
Sources
Checked 2026-06-25 — confirmed against current FTC and CISA small-business guidance; no invented figures used.
cyber Threat Radar: ‘callback phishing’ calls that sound like your bank
This one starts with an email or text that looks like a receipt or fraud alert — “a charge of $412 was made on your account” — with a phone number to call if you didn’t authorize it. There’s no link to click, which is the point: it’s designed to feel safer than a typical phishing email. Call the number, though, and you reach a scammer posing as a bank or tech-support agent, who then talks you through “verifying your identity” in a way that actually hands over account access or payment details.
Why it works on business owners specifically: the fake alerts are often written to look like they’re from payment processors or software vendors businesses actually use, and the phone conversation feels like normal customer service, not an attack.
What it means for you: treat any “call this number” prompt in an unexpected email or text the same way you’d treat a suspicious link — don’t use the contact info in the message. Look up the real number yourself.
Sources
Checked 2026-06-25 — pattern matches current FTC consumer alert guidance on “callback phishing”; no specific incident or statistic claimed.
ai AI at Work: what your free AI note-taker does with the recording
AI meeting assistants that join your calls and produce a transcript or summary are genuinely useful for a small business — nobody has to take notes anymore. But “free” AI tools have to make money somehow, and for several popular note-takers that has included using call recordings and transcripts to train their underlying AI models, unless you specifically opt out.
That matters more than it sounds like: your sales calls, client consultations, or contract negotiations may contain information you wouldn’t want stored indefinitely or used outside the room it was said in — pricing you gave one client and not another, details about a dispute, anything a client told you in confidence.
What it means for you: before you invite an AI note-taker to a call, especially with a client, check two things — the tool’s settings for an option like “do not use my data for training,” and whether your paid tier (versus free tier) handles data differently. It usually does.
What to do: open your note-taker’s privacy or data settings this week and turn off any “use my content to improve the product” option. If you can’t find one, that’s itself useful information — ask before your next client call whether it’s being recorded and by what tool.
Sources
Checked 2026-06-25 — described as a general pattern across popular AI note-taking tools’ published privacy settings, not a claim about any single named product.
privacy Privacy Watch: browsers are phasing out third-party tracking cookies
For years, ads followed you around the web using small files called third-party cookies — placed by an ad network, not the site you’re actually visiting, so it could recognize you site to site. Browser makers have been steadily shutting this off by default. If you run ads for your business, or use website analytics that rely on this older tracking, you may notice your numbers shifting even though nothing about your business changed — it’s the measurement changing under you.
What it means for you: if you advertise online, expect your ad platform’s audience and conversion numbers to become less precise over time, not because your ads are performing worse, but because less cross-site tracking data is available. If you just run a normal business website, this change is a net win — fewer companies quietly building a profile of your customers as they browse.
Sources
Checked 2026-06-25 — describes the general, publicly documented direction of major browsers’ tracking-cookie policies, not a specific date or vendor commitment.
action Do This Now (15 min): turn on multi-factor authentication for email
Your email is the master key to your business — it’s how most other accounts (banking, vendors, social media) get reset if a password is forgotten. Multi-factor authentication (MFA) means that logging in requires your password and a second proof, usually a code from an app on your phone. It’s the single most effective thing a small business can do against account takeover, and it takes about 15 minutes.
- Open your email account’s security settings (search “[your email provider] two-step verification” if you’re not sure where).
- Choose an authenticator app (built into most phones, or a free app) rather than text message codes where the option exists — it’s harder for a scammer to intercept.
- Follow the setup steps: scan a QR code with the app, then enter the 6-digit code it shows you to confirm.
- Save the backup codes it gives you somewhere safe (not in your email itself) — you’ll need them if you lose your phone.
- Repeat for any other account holding sensitive business or financial information.
Sources
Checked 2026-06-25 — steps reflect current CISA and NIST guidance; authenticator apps recommended over SMS codes per current best practice.
explainer Plain English: what ‘phishing’ actually means
Phishing is any message — email, text, or social media — that pretends to be from someone you trust in order to get you to hand over information (passwords, account numbers) or take an action you wouldn’t otherwise take (click a link, pay an invoice, download a file). The name is a play on “fishing”: cast a wide net, see who bites. It’s not about the technology being sophisticated — it’s about the message being convincing.
Variants have their own names: “spear phishing” targets one specific person with details that make it personal; “smishing” is phishing by text message; the “callback phishing” above is a variant where the trap is a phone number instead of a link. The defense is mostly the same for all of them: don’t act on urgency alone, and verify through a channel the message didn’t give you.
Sources
Checked 2026-06-25 — definition matches current CISA usage.
roundup Quick Hits
- FTC small business hub — a running list of current scam alerts written specifically for small businesses, worth a bookmark.
- CISA free cybersecurity services — several basic security scans and services CISA offers at no cost, including to small organizations.
- NIST small business cybersecurity corner — plain-language checklists if you want a fuller security review than we can fit in one newsletter.
Sources
- FTC small business hub
- CISA small and medium business resources
- NIST small business cybersecurity corner
Checked 2026-06-25 — all three are official, currently maintained government resources for small businesses.