Scams Are Getting Sneakier

I promise, Janet, that Prince is not actually real…and he doesn’t need money transferred immediately for a life-saving surgery…

What if a Nigerian Price really needs my help?

Hello, July!

We are officially in the second half of the year, which feels both exciting and mildly rude. How are we already here?

July is a great time to pause, review your finances, and make a few adjustments before the busy fall season arrives. Our last few newsletters have been on this check in trend for a reason. For many business owners, summer can bring schedule changes, vacations, slower response times, and shifts in revenue. Taking time now to review your security processes can help you stay proactive instead of getting surprised with an attack.

This month, we are focusing on the phishing scams becoming harder to spot.


Housekeeping

EXCITING NEWS

Kendall will be joining the Charlotte B Corp Collective this Friday, July 17, 2026 at 12:00 PM to discuss our journey through the certification process under the new requirements for B Corp Certification! “Attendees will gain a behind-the-scenes look at what it actually takes to certify today, the biggest shifts in the process, and how to approach the new standards with confidence.”

WOO! Go Kendall! We are so proud of you!

Register Here!

Upcoming tax deadlines (add them to your calendar or add our calendar – more info here).

Extensions for S-Corps and LLC Partnerships: September 15, 2026
Most tax pros will need all your bookkeeping and documentation submitted 3-4 weeks before this, so if this deadline applies to you, this deadline is more like August 15

Phishing Scams are Getting Smarter

Phishing scams are not just suspicious emails from mysterious princes anymore. Today’s scams are more polished, more personal, and much harder to spot.

Attackers are using new tools and tactics to impersonate trusted people, companies, software platforms, and even executives. Small business owners are often targeted because they are busy, moving quickly, and managing a lot of financial information.

Here are a few current phishing tactics to watch for:

QR Code Phishing (aka “Quishing”)

QR Code phishing is becoming a common way for attackers to hide dangerous links. Instead of putting a suspicious link directly in an email, scammers place the link inside a QR code, image or PDF attachment.

That QR code might lead to a fake login page designed to steal your username, password, or payment information.

What to watch for:

*Be cautious with QR codes in unexpected emails, invoices, flyers, or attachments. When in doubt, go directly to the company’s website instead of scanning the code.

Oprah: “You get a phishing email and you get a phishing email.”
Oprah: “You get a phishing email and you get a phishing email.”

“ClickFix” Style Prompts

Some scams now use fake error messages, pop-ups, or verification prompts that tell users to manually copy and paste a command into their computer.

The message may look harmless or technical, but the goal is to get you to run something malicious using legitimate tools already built into your system.

What to watch for:

*If a website or email tells you to copy, paste, or run a command to “Fix” something, pause. That is not a normal request.

Deepfake Audio and Video Impersonation

Scammers are also using AI-generated audio and video to imitate real people. This can include fake calls that sound like a business owner, executive, vendor or client.

These scams often create urgency and pressure, especially around wire transfers, payment changes, sensitive data, or login credentials.

What to watch for:

*If someone asks you to send money, change payment details, or share sensitive information, verify it through a separate trusted method. Do not rely on the call, video, or message you received. Hang up and call the person you think just contacted you, it’s likely they did not place the original call.

Business Email Compromise

Business Email Compromise, or BEC, happens when attackers impersonate someone familiar, such as a business owner, manager, vendor, or client.

What to watch for:

*Be extra careful with requests involving wire transfers, ACH changes, payroll updates, tax documents, or account access. NEVER send this sensitive information via email. Call the vendor/client and get verbal confirmation that the request is legit, then ask for a secure link to safely enter the sensitive information.

Can't fall for phishing if you don't know how to check you email.

Phishing is Moving Beyond Email

Phishing does not only happen in your inbox anymore. Scammers are now targeting people through messaging platforms, collaboration tools, social media, text messages, and phone calls.

That means a suspicious message could show up through Microsoft Teams, Slack, LinkedIn, Facebook, Instagram, or even a text from what appears to be a known contact.

What to watch for:

*Treat unexpected messages with links, attachments, payment requests, or login prompts carefully, even if they come through a platform you use every day.

Bought a book "how to scam online." The book never arrived.

Cloud and Brand Impersonation

Microsoft remains one of the most commonly spoofed brands in phishing attacks, but scammers also use familiar tools like OneDrive, ShareFile, DropBox, DocuSign, and other cloud platforms to make fake pages look legitimate.

What to watch for:

* Before logging in, open a new browser tab and go directly to the platform yourself instead of clicking from the email or message.

Discovery Call Scam

This just happened to Kendall a few weeks ago. An unknown booked a discovery call off the website and emailed 30 minutes before to confirm the meeting was still on. Five minutes after the meeting started, they emailed to say they were having a problem getting into the meeting. They included a link to what looked like a Teams call. Kendall clicked it, and it prompted a Microsoft download – an app Kendall already had on her computer. She denied the prompt, responded to the potential client/scammer that a phone call worked better and never heard back.

I don’t know what you call this and I don’t have confirmation that it was a phishing attack, but it sure seems phishy, preying on the desire to close a new client with a link to click.

What to watch for:

* Treat unexpected links with caution. You DO NOT have to open every link you receive. Offer alternatives that you trust and know if you don’t feel comfortable.

A Simple Rule for Protecting Your Business

When money, passwords, payroll, tax documents, or banking information are involved, slow down.

A few extra minutes of clarification can protect your business from a very serious expensive headache.

Before acting on a request, ask:

  • Was I expecting this?
  • Does the request feel urgent or unusual?
  • Is there a link, attachment, QR Code, or payment change involved?
  • Can I verify this through a separate trusted method?

When in doubt, do not click. Do not scan. Do not send payment. Verify first.

I never opened a wells farge checking account...doesn't mean I don't have one.

Client Highlight

Strata Project Management Group

Amy Johnson is Owner and Principal of Strata Project Management Group, where she leads strategy, client partnerships, and project delivery across a diverse portfolio of commercial real estate and workplace environments. Amy’s background in architecture and design coupled with over a decade working in project management for large commercial real estate firms in Charlotte lead her to starting Strata Project Management Group in 2021. With nearly three decades of experience, Amy is known for her collaborative leadership style and ability to navigate complex projects with clarity and empathy. She has helped shape projects that contribute to Charlotte’s evolving landscape while building a culture grounded in trust, accountability, and meaningful relationships.

Strata Project Management Group partners with clients to streamline every layer of project delivery — bringing clarity, efficiency, and strategic guidance from early planning through execution. As a woman owned and operated firm, we combine global experience with a highly personal, client-centered approach, helping organizations navigate complex projects with confidence while building trusted relationships along the way.


CONCLUSION

July is the perfect time to tighten up your processes, and protect your business from avoidable surprises.

Review your reports. Keep your bookkeeping current. Watch for suspicious requests. And please, for the love of clean financial records, do not approve a surprise wire transfer because “the boss” sent a weirdly urgent message from a new email address.

If this newsletter was helpful, forward it to another business owner who could use a mid-year money check-in or a friendly reminder not to scan mysterious QR codes like they are collecting Pokemon cards.

Kendall is ready and available to discuss your current bookkeeping strategies and needs here (I know this is a link, but I promise it is safe!).

~ Alecia

IQ Bookkeeping

P.S. If a message says “urgent,” “kindly,” and asks you to buy gift cards, change banking info, or scan a random QR code… congratulations, you have proudly met a scammer in the wild. DO NOT FEED IT.

P.P.S. did you scan the QR code?

VIEW ON SUBSTACK – Originally posted on July 13th, 2026.

Leave a Reply

Spam-free subscription, we guarantee. This is just a friendly ping when new content is out.

← Back

Thank you for your response. ✨

Discover more from IQ Bookkeeping

Subscribe now to keep reading and get access to the full archive.

Continue reading