Real World Cyber Threat: How Staff Training Stopped An Attack

When the Cyber Attack Threat Isn’t Theoretical

We talk a lot about cyber threats in our blog posts and social media. From abstract statistics, news headlines, and potential worst-case scenarios. But very recently one of our own customers came face to face with exactly the kind of attack we warn people about. The reason we’re telling you this story isn’t to worry you, it’s because it ended well, and the reason it ended well is something every business can replicate – staff training.

What Happened During The Cyber Threat

The targeted organisation, a business we’ve been working with on cyber security awareness training, found itself in the crosshairs of a group known as Black Basta. This is a well-organised, professional ransomware operation that has been making headlines for its increasingly sophisticated approach to breaking into business networks.

The attack didn’t start with a dodgy email attachment or an obvious scam. Rather, several members of staff such as managers and heads of departments suddenly found their inboxes flooded with hundreds of emails. Newsletter sign-ups, subscription confirmations. The sort of overwhelming chaos that might make you want to pick up our phone and call your IT support.

And this is exactly what the attackers were counting on.

Within a short time of the spam wave hitting, those same staff members received calls from someone claiming to be their IT support. The caller was helpful, calm, and convincing. They explained they’d noticed the email issue and wanted to help sort it out remotely, would the staff member just download a quick tool so they can login and take a look.

Why The Cyber Attack Didn’t Work

So, here’s where the story takes a different turn from the ones you usually read about.

The staff members who received those calls didn’t panic, and they didn’t comply. Instead, they paused, recognised the warning signs, and reported the incident through the proper channels. No remote access was granted. No credentials were handed over. The attack was stopped before it got past the first stage.

Those employees had completed cyber security awareness training with us, and they’d taken part in regular phishing simulation exercises.

What Makes This Type of Cyber Attack So Effective

Black Basta and groups like them are successful precisely because they exploit human behaviour rather than purely technical weaknesses. The mass email flood is deliberate because it creates stress, confusion, and a strong desire for someone to come and fix things. The follow-up call feels like relief!

For someone who hasn’t been trained to spot these tactics, the whole sequence feels completely legitimate. There’s no suspicious link to click, no obvious red flag that we normally speak off, instead, it’s just a helpful person on the phone.

The technical side of these attacks, once access is granted, can include deploying remote monitoring tools, harvesting credentials, moving through your private network, and ultimately deploying ransomware. The damage can be severe. But all of that depends on getting that first foot in the door.

 

The Difference Cyber Security Training Makes

We’ve always believed that your people are your strongest line of defence, but only if they’re equipped to act as one.

Firewalls, antivirus software, and email filters are essential, but no technical solution can compensate for a well-executed social engineering attack.

What our customer demonstrated is that awareness training isn’t just a box-ticking exercise. When it’s done properly with realistic simulations, clear guidance, and regular reinforcement it builds resilience. People develop the confidence to question unexpected contact, to slow down when something feels off, and to report rather than react quickly.

In this case, that training directly prevented what could have been a very serious and costly incident.

 

What You Can Do

If your team hasn’t had recent cyber security awareness training, or if your last phishing simulation was more than six months ago, it’s worth taking a fresh look. The threats are evolving, and so should your defences.

We offer tailored training and ongoing phishing simulation programmes that are designed around real-world attack techniques, exactly like the one described above. If you’d like to find out more, get in touch with the team and we’ll be happy to walk you through what’s involved.

Testimonials

Abbie McCahill

“As a small team, time at work can be quite precious so when there’s a glitch with a laptop or a computer, it can really be a nightmare. Prior to us having sfG Software to support us, if one of the laptops was playing up, I’d invariably get asked to look at it and the downtime involved would usually be significant. Now, we pay sfG a very reasonable monthly retainer and if anything goes wrong with any of our equipment, we’re all safe in the knowledge that we can pick up the phone to or raise a ticket with one of the experienced engineers and the problem will be sorted out with minimal disruption. I really wouldn’t hesitate to recommend sfG to any customers or associates and I’m really grateful to have sfG Software as an extended arm of our team! Thanks again for supporting us so well!”

Abbie McCahill, Managing Director
Adder Business Ltd, Inverness

Tony Lister

“Having just signed up to get sfG Software to look after our IT needs, I wanted to thank you and your team for what has been an exceptional onboarding process. Andy is a good listener and has very quickly helped increase our understanding of the benefits of Office 365 and helped set up our systems to work more effectively. We have already agreed a gameplan for further improvements and are delighted with his expertise and knowledge. We are confident that as our company expands, we have the right people in place to look after our systems and would happily recommend sfG Software to anyone wanting assistance with their IT needs. We look forward to working with sfG Software for many years to come.”

Tony Lister, Director
Hamish Homes, Inverness

Highland Hospice

“Your response was great including the swift site response and working through the situation to resolution. You clearly identified the fault, where the issue was and put future mitigations in place. All this reinforces our confidence in sfG providing IT support to the Hospice.”

Highland Hospice

Scott Anderson

“Can I also take this opportunity to say that every time we deal with sfG we are always impressed at the speedy, helpful and efficient response we get. In this post-covid day and age I am finding it increasingly difficult to find suppliers who live up to their word, but sfG always deliver.”

Scott Anderson
Masson Cairns Solicitors and Estate Agents

Freda Newton

“I am often reluctant to give references in case it all goes wrong but I have to say that the support from sfG has been the best that we have had and I feel that our systems are much more robust and professional having listened to their advice.”

Freda Newton, Managing Director
Jacobite Cruises, Inverness

Scott Murray

“We have been working with sfG for a number of years now, and have found their service to be attentive and efficient. Nothing is too much hassle, and if they can’t do something they are happy to make a recommendation for someone who can. Their pricing is great and, unlike some companies, we have never had a bill for “extras” that weren’t discussed before a project. All in all, a great bunch of guys to work with.”

Scott Murray, Managing Director
Cru Holdings

David Brookfield

“My experience of IT support companies was that they were broadly all the same and all very mediocre. Since moving our business to sfG I have changed my view entirely.

The changeover from our previous providers was seamless and since then the support we have received has been excellent. The personnel at sfG are very easy to speak to. We receive almost instant responses to our needs and help is provided even if the issue isn’t directly within their remit.

We are kept up to date with our usage and spend via the monthly activity reports which provide excellent statistics for our Board and all at a very competitive price. sfG are certainly a cut above the norm in the IT Support industry.”

David Brookfield, Head of Finance and IT
Centred

Mike Ayres

“sfG have provided IT support services to HighWater since 2011. The broad range of technical capabilities provided by their patient and dedicated support staff ensures that they are always able to respond to our needs in a timely and efficient manner. The accurate data provided by their support desk system ensures that they are able to provide HighWater with a tailored, cost-effective IT support package designed to suit the size and complexity of our company. sfG’s staff have gone above and beyond the level of support that I have typically experienced from other companies when we have had unforeseen out-of-hours IT problems. In summary, I couldn’t recommend them highly enough!”

Mike Ayres, Managing Director
Highwater

Dan Rose-Bristow

“We have used sfG now since 2015 and have always found the service to be friendly and professional. They cover periodic maintenance, ad hoc issues as well as upgrade installations. They often work with 3rd party suppliers and always facilitate any issues that this can bring. sfG look after our Office 365, server and networking, PC maintenance, switches and access points, wireless infrastructure, EPOS hardware and cyber security. I would highly recommend them as a business to work with and we appreciate the service they provide for us”

Dan Rose-Bristow, Owner
The Torridon

Sarah Fowler

“We’re a small charity that has muddled by without any formal IT support for many years, with frustrations and glitches ever growing! Our IT had really started to hold us back and interfere with our day to day work. It took around a year from us initially contacting sfG for us to finally take the leap and enter into an SLA. During that time they were incredibly patient, understanding and always happy to answer any questions we had. We’ve now made the move to Office 365, supported by sfG every step of the way. There’s lots still to do but they’re happy to work with us, at a pace that suits the team, so everyone can get used to changes gradually and avoid any additional pressures. I have no hesitation in reccommending sfG.”

Sarah Fowler, Chief Officer
Thriving Families

Brenda Dunthorne

“sfG have provided us with IT support for a number of years and we are always very pleased with their response time and the outcome of their advice. In addition sfG have supported us in some complex bespoke software developments which demonstrated their skills and determination to achieve the desired outcome. The sfG staff are always very polite and a pleasure to work with.”

Brenda Dunthorne, Director
In Your Element

Sarah Mackay

“Appointing sfG has been a wise business move for us at Canonbury Interiors. Now sfG handle all our IT issues, we are free to focus on our clients and what we do best.”

Sarah Mackay, Managing Director
Canonbury Interiors

Paul Wood

“We’ve been using sfG software for many years now for our back-office, server and IT support. Their fast, knowledgeable and reliable service has ensured IT failures and niggling computer problems are all, fortunately, a thing of the past!”

Paul Wood, Managing Director
West Highland Publishing Company

Dave McLaughlin

“As with most modern businesses we have become totally dependent on IT systems in all areas. Any break in service has a direct cost impact. We have been working with sfG for many years and their support is critical to our business. I would highly recommend their professional service.”

Dave McLaughlin, Managing Director,
Shandwick Supply Co

Daniel Murdoch

“We have been with sfG for just over a year now and their customer service has been first class from the first minute.  Initially, we probably weren’t their ideal client as we were just starting out, however during the first year of a business, the last thing you want to be worrying about is IT.  With a number of new employees and systems coming in throughout the year, sfG have been on top of all our needs and requirements.  Their response to any issue or query is within minutes and any issues which do arise are resolved well within their SLAs.  Their charging structure is very fair which sees us never overpaying for support which we don’t require or use throughout the year.  The team are all very friendly, personable and are quick to come and see us in person if required.”

Daniel Murdoch, Financial Planner
57 North Financial Planning

Bruce Farrell

“Without the help and support from sfG, I would still be staring at a screen now scratching my head.
The support they offer is above and beyond normal.
Extremely friendly staff, very understanding.
We required a specific bit of work done for our company and Andy was extremely helpful and did work behind the scenes that was outstanding.

The work he did will now save us hours of work.”

Bruce Farrell, Rope Access Technical Authority
Ethos Inspection Solutions