It's December, which means two things in cybersecurity: everyone's distracted by holiday parties and year-end deadlines, and threat actors know it.
Our MDR provider flagged a 340% increase in ransomware attempts against their mid-market clients in the first two weeks of December compared to November. We've blocked 17 phishing attempts specifically targeting our organization this month - up from our usual 4-6. One of them was sophisticated enough that it got past our email filters and reached a user's inbox.
This isn't new. Holiday season attacks are a documented pattern going back years. But knowing it's coming and being prepared for it are different things.
Why Holidays Are Prime Time for Attacks
The logic from an attacker's perspective is straightforward:
Reduced staffing. IT teams take vacation. Security operations centers run skeleton crews. The person who would normally notice unusual network activity might be at their kid's Christmas pageant.
Increased pressure to pay. If you're a retailer and ransomware hits the week before Christmas, the pressure to pay and recover quickly is immense. Threat actors price this into their timing.
Year-end urgency creates carelessness. Finance teams rushing to close the books. Sales teams scrambling to hit quotas. Everyone's moving fast and paying less attention to whether that invoice attachment is legitimate.
Holiday-themed phishing is effective. "Your package delivery failed" emails spike in effectiveness when everyone's actually expecting packages. "Holiday bonus notification" emails catch people who are hoping for exactly that.
What We've Seen This Month
The 17 phishing attempts against our organization broke down into these categories:
- Fake delivery notifications (7): Impersonating UPS, FedEx, and USPS with tracking links that led to credential harvesting sites
- Vendor invoice fraud (4): Spoofed emails from actual vendors with slightly modified payment instructions
- Internal impersonation (3): Emails appearing to come from our CEO or CFO requesting urgent wire transfers
- IT support scams (2): "Your Microsoft 365 subscription is expiring" type messages
- Holiday bonus/gift card (1): The classic "HR is sending everyone gift cards" trick
The one that got through was a vendor invoice fraud attempt. The attacker had clearly researched our actual vendor relationships and crafted an email that looked legitimate enough to bypass our filters. The user who received it was smart enough to call the vendor directly rather than clicking the payment link. That phone call saved us potentially hundreds of thousands of dollars.
The Attack That Almost Worked
Let me break down that vendor fraud attempt because it illustrates how sophisticated these attacks have become:
The email appeared to come from a produce vendor we actually use. The sender address was close to legitimate - they registered a domain one character off from the real one. The email referenced an actual PO number (which they likely got from a previous breach or dark web data). The "invoice" PDF was clean - no malware, just updated payment instructions pointing to a fraudulent account.
If our AP clerk had processed this without verification, we'd have wired payment to a mule account. By the time we realized the error, the money would have been laundered through multiple hops and unrecoverable.
The only thing that stopped this was human judgment. Our employee thought something felt slightly off - the tone of the email wasn't quite right - and made a phone call. Technology didn't save us here. Training did.
What We're Doing Differently
Based on this month's activity, we've implemented additional controls:
Mandatory callback verification for any payment instruction changes. If a vendor says "wire payments to a new account," we call the vendor at a known number (not one from the email) to verify. No exceptions, no matter how urgent they claim it is.
Enhanced monitoring during off-hours. Our MDR is on heightened alert through January 2nd. Any suspicious activity triggers immediate escalation rather than waiting for business hours review.
Executive impersonation warnings. We've added banners to emails that appear to come from executives but originate from outside our domain. Users are trained to be suspicious of any urgent financial request, even if it looks like it's from the CEO.
Backup verification. We tested our backup restore process this week - not just confirming backups exist, but actually restoring systems to verify they work. Last thing you want to discover during a ransomware recovery is that your backups are corrupted.
Holiday Security Checklist for CIOs
- Confirm 24/7 security monitoring coverage through the holiday period
- Test backup restoration - don't just verify backups exist
- Remind users about holiday-themed phishing with specific examples
- Implement callback verification for any payment changes
- Review and restrict privileged access during reduced staffing periods
- Ensure incident response contacts are current and reachable
- Brief executives on impersonation attacks targeting them
- Verify cyber insurance coverage and claims process
The Human Factor
I spend a lot of time thinking about security technology - firewalls, EDR, SIEM, MDR, zero trust architecture. But the attack that almost got us wasn't stopped by any of that. It was stopped by an employee who trusted her instincts.
That's not reproducible or scalable. We got lucky that this particular employee was cautious. The next one might not be.
This is why I'm increasingly convinced that security awareness training - the good kind, not the checkbox compliance kind - is the highest-ROI security investment most organizations can make. Not because it will catch everything, but because it creates a culture where people pause before clicking, verify before transferring, and report before it's too late.
What Happens If You Get Hit
Despite our best efforts, ransomware might still get through. Here's what I tell my team about our response posture:
We will not pay ransoms. This is a policy decision we made years ago and have communicated clearly. Paying funds criminal organizations and doesn't guarantee recovery. Our focus is on having backups good enough that we don't need to pay.
We can rebuild from scratch. Every critical system has documented rebuild procedures. We've tested them. They work. It would hurt, but we could recover without paying.
Communication is pre-planned. We have draft communications for customers, employees, and regulators. When you're in crisis mode is not when you want to be wordsmithing press releases.
Legal and insurance are on speed dial. Our cyber insurance carrier and external legal counsel know who we are and how to reach us. First calls in a breach are to them, not to IT vendors.
Looking Ahead
The holiday spike will pass. January will bring different challenges - year-end reporting, audit season, budget planning. But the underlying reality won't change: threat actors are persistent, creative, and patient. They'll find the next window of opportunity.
Our job is to make sure that window stays closed, or at least alarmed.
Stay vigilant out there. And maybe think twice before clicking that "track your package" link.
Planning an ERP modernization?
6 SAP-to-Dynamics conversions with zero business disruption. Let's discuss your project.
ERP Services Book a Call