Call NowFree Quote
Cybersecurity

Black Friday & Cyber Monday Scams: A Perth Business Guide

Black Friday and Cyber Monday get treated as a consumer shopping event, but for Perth businesses they're also one of the riskiest windows of the year. Inboxes fill with order confirmations and shipping notices, finance teams process extra invoices, and staff are distracted, which is exactly the combination attackers rely on. Here's what to actually watch for, and what to fix before the season starts.

Why the Shopping Season Raises Business Risk

Attackers don't need to invent anything new for this period, they just ride the wave of email traffic that's already expected. A fake shipping notice or order confirmation blends into a crowded inbox far more easily in late November than in a quiet month, and staff open more links out of habit. At the same time, finance teams are handling a higher volume of legitimate purchase orders and supplier invoices, which gives business email compromise scams more cover than usual. If you've never reviewed how invoice fraud actually happens, this is a good time to.

Fake Invoices and Supplier Impersonation

The most costly version of this scam is a fake supplier email requesting a change to bank details, timed to land alongside a genuine flurry of end-of-year purchasing. It rarely looks suspicious on its own, the email address is close enough, the tone matches, and the amount is plausible for the season. The fix isn't better spelling detection, it's process: any change to supplier payment details should require a verbal callback on a known number before funds move, no exceptions for year-end urgency.

Phishing Disguised as Orders and Deliveries

"Your delivery couldn't be completed" and "confirm your order" emails are some of the highest-performing phishing templates during this period, precisely because almost everyone is expecting a real one. The tactics themselves aren't new, see our breakdown of common phishing email tactics, but the click-through rate goes up when staff are tired, distracted, and receiving more of these than usual. A short reminder in the week before Black Friday is worth more than training run months earlier.

Staff Shopping on Business Devices

If personal shopping on work laptops or the office network is going to happen regardless of policy, unmanaged is worse than managed. At minimum, staff shouldn't save company card details in personal retail accounts, and browser extensions promising deal alerts or cashback are a common malware vector worth blocking outright. Our guide to BYOD policy for Perth businesses covers how to set boundaries without pretending the behaviour doesn't exist.

Protecting Company Cards and Procurement

Genuine end-of-year purchasing, software renewals, hardware refreshes, stock for the new year, means company cards see more use and more people requesting them. Keep spending limits tight on cards used for online purchases, and confirm any unfamiliar charge with the requester directly rather than approving it because the timing seems plausible. If credentials tied to a company card or account have ever been exposed, a quick check with dark web monitoring is worth doing before, not after, the season's spending picks up.

A Pre-Shopping-Season Checklist

Before the last week of November, run through this: confirm MFA is enforced on email and finance systems, remind staff (briefly, not a full training session) what a fake delivery or order email looks like, lock down the callback process for changing supplier bank details, set or review spending limits on cards used online, and block known deal-alert and cashback browser extensions at a device level. All five take an afternoon and close most of the gaps attackers rely on this time of year.

Frequently Asked Questions

Why does Black Friday and Cyber Monday increase business risk, not just consumer risk?

Order confirmations, shipping updates, and receipt emails flood inboxes over this period, which gives attackers cover to slip fake versions past staff who are used to seeing dozens of similar legitimate emails. Finance teams also process a higher volume of purchase and supplier invoices, which is exactly the window business email compromise scams are built for.

Should staff be allowed to shop online on business devices at all?

That's a policy decision for each business, but if it's going to happen anyway, it's safer to set clear rules (personal accounts only, no saved company card details, no browser extensions from unknown sources) than to ban it and have it happen unmanaged regardless.

What's the single highest-impact thing we can do before the shopping season starts?

Confirm with your finance team, in person or by phone, not email, that any process for changing supplier bank details requires a verbal callback before payment. That one control stops the majority of successful invoice fraud attempts.

Is this any different from normal phishing awareness we already run?

The underlying advice is the same, but volume and urgency both spike in late November, which measurably increases how often tired or distracted staff click through. It's worth a short, timed reminder rather than relying on training staff received months earlier.

We can run the pre-shopping-season checklist for you before things get busy.

Cybersecurity Services →

Want it sorted before Black Friday hits?

Call 0433 087 091 for a free, no-obligation IT health check that covers email, finance systems, and device policy in one visit.

Book a Free IT Health Check

For related reading, see Business Email Compromise: How Perth SMBs Can Stop Invoice Fraud, Common Phishing Email Tactics Targeting Perth Businesses, and Cyber Security Awareness Month: A 4-Week Action Plan.

Share this article