Answer extracted from the Young and Profiting with Hala Taha (Entrepreneurship, Sales, Marketing) podcast — listen to the full episode below.
An attacker starts with reconnaissance on LinkedIn and Instagram to map the entire organization, identifying employees and the SaaS tools your company uses. They then craft phishing emails mimicking your legitimate email format, search the dark web for vulnerabilities in those tools, target busy founders or vulnerable individuals, or gain access by purchasing your product and requesting a Zoom call with support—exploiting the elevated privileges that customer-facing staff typically hold.
Attackers follow a predictable sequence because small teams present low resistance. First comes public reconnaissance through social media—LinkedIn, Instagram, company websites—to build an accurate organizational chart without raising any alarm. They identify job titles, team size, departments, and which products or services the company relies on.
Next, they craft personalized phishing emails. A convincing phishing email mimicking your company domain can be coded in about five minutes, and when targeted at busy founders or rushed employees, the click-through rate climbs dramatically. As Abed Hamdan explains in the episode, attackers look for telltale signs of chaos: a team that just went live and is handling ten times more clients than expected will be stretched thin, making them far more likely to skip security checks.
Parallel to phishing, attackers scan the dark web for known vulnerabilities in the SaaS applications your company publicly uses—Slack, Zoom, Google Workspace, or any other cloud tool mentioned in your team's communications or job postings. A single unpatched vulnerability in one tool can open the door to your entire network.
The fourth vector targets human psychology directly. Attackers may identify vulnerable individuals—elderly parents, junior staff, or anyone with a weak digital footprint—whose email account or social media can be compromised to contact employees with authority. Alternatively, they purchase your company's product and request a sales or customer support call via Zoom, using social engineering to trick support staff into clicking a malicious link or downloading a "document."
Why target support staff? Customer-facing and support roles typically hold elevated network privileges by design—they need access to billing systems, customer data, product configurations, and deployment tools. One compromised support employee becomes a beachhead for lateral movement throughout your infrastructure, discussed at length in this podcast.
"They always target the vulnerable. They always target the young. It is a problem and we need some kind of a strict regulation."
Abed Hamdan — Founder of GRC Mastery, cybersecurity advisor with more than two decades of experience in risk management. Known online as "the Unix guy," Hamdan began his career in the late 1990s and early 2000s through IRC chat rooms and self-directed learning. His early website, unixsky.com, launched a few months before Google.com, establishing his deep roots in internet security culture. He now consults with organizations across multiple sectors on cybersecurity assessments and strategy.
One often-overlooked detail Hamdan shares in the full discussion is how attackers use emotional triggers—announcing a major milestone or rapid growth—to identify moments when your team is most distracted and least likely to question a suspicious email or unexpected Zoom request.
Mid-size companies occupy a unique vulnerability sweet spot. They're large enough to have valuable data and systems worth attacking, but too small to afford dedicated security teams. Founders are typically stretched across product development, sales, and operations—there is no security-first mindset, and often no budget for professional security assessments until after a breach occurs.
Attackers recognize that common business tools create a false sense of security. Because LinkedIn, Zoom, and Gmail are ubiquitous and trusted, employees let their guard down. A Zoom call from a "customer" looks legitimate. A LinkedIn message from an account impersonating a colleague appears authentic. An email from "support@yourcompany.com" (spoofed with a slightly altered domain) feels official, especially when it's addressed to you by name with project-specific context gathered from your public website.
Phishing is a social engineering attack where an attacker impersonates a trusted entity—a company, person, or institution—through email, message, or call to trick a recipient into revealing sensitive information (passwords, credentials, financial data) or clicking a malicious link that installs malware or grants unauthorized access. Phishing succeeds because it exploits trust and urgency rather than technical vulnerability.
The most common way attackers gain foothold in small businesses is through social engineering, where the attacker pretends to be someone the business owner or team member trusts, making phishing and impersonation the dominant attack vectors across all company sizes.
Small businesses are easier targets because entrepreneurs are usually focused on getting products out, are overworked, and often underfunded, leaving fewer resources and less formalized security defenses compared to large enterprises with dedicated security teams.
Entrepreneurs typically make two extreme assumptions about attackers: either they think hackers are someone in a hoodie in a basement, or they believe attackers are highly sophisticated nation-state actors—missing the reality that most successful attacks are simple, low-cost, and rely on human error.