Callback
  • From a market stall to a store

  • -

  • From a store to a retail chain

  • -

  • From retail to manufacturing

Cybersecurity for business: what is phishing and methods to combat it

Andrii Toverovskyi
Andrii Toverovskyi

Expert in tax and legal business matters

Phishing — is an attack in which an employee or business owner is tricked into clicking a malicious link, opening a file, entering a password, confirming a login, or transferring money. For a store, the consequences can be practical: email hacking, theft of bank access, infection of the cashier's computer, encryption of the accounting database, loss of orders, and suspension of sales.

As of July 2026, phishing remains one of the main methods of initial access to businesses. Attacks have become more convincing: emails are written without glaring errors, scammers copy the style of banks, delivery services, marketplaces, government services, suppliers, and even internal company correspondence.

For Ukrainian retail, phishing is dangerous because most workflows pass through email, messengers, internet banking, marketplaces, remote access, PRRO, CRM, accounting software, and Windows computers. One careless click can give an attacker access to the store's entire operating system.

Brief action algorithm

If an employee has already opened a suspicious link or file Do not scold the person or ask them to "see what's there". It is important to quickly stop the spread of the attack, preserve traces, and check backups.

  1. Disconnect the suspicious computer from the internet and local network. Do not force it to turn off if it can be passed to a technical specialist for analysis.
  2. Change passwords to email, banking, Google/Microsoft accounts, marketplaces, PRRO, delivery service cabinets, and accounting systems.
  3. Terminate active sessions in accounts and check connected devices.
  4. Block suspicious payments through the bank if card or bank details were entered.
  5. Check the server, cash register computers, network folders, and backups. Operations can only be restored from a backup created before the infection.
  6. Record the incident: date, time, who received the message, what was opened, which accounts might have been compromised, and what actions were taken.

Why this is relevant for Ukrainian retail

Small and medium-sized businesses often operate without an in-house administrator. A single computer can serve multiple roles: accounting server, owner's workstation, bank access, email, messengers, supplier files, and remote connection for technical specialists. Such concentration is convenient but increases the risk.

The NBU reported that in 2025, the amount of losses from illegal actions and fraudulent operations with payment cards in Ukraine increased to UAH 1.4 billion, although the number of fraudulent operations per million expense operations decreased. This means that a single successful attack is becoming more expensive for the victim.

In 2025–2026, CERT-UA regularly recorded attacks via emails, compromised accounts, attachments, archives, links, fake messages from government agencies, and thematic lures. This does not mean that every store is a state-level target. However, the techniques used against government institutions and large organizations quickly transition into mass fraud against businesses.

How phishing works

Phishing does not hack the system directly. It forces a person to perform an action instead of the attacker: enter a password, open a file, confirm a login, install a program, transfer money, or grant remote access.

ScenarioWhat the employee seesWhat can be compromisedFirst action
Email from the "bank" Message about account blocking, payment verification, or new rules Internet banking, financial phone number, payment data Do not click the link. Log into the bank manually or call the official number
File from a "supplier" Invoice, act, waybill, price list, or a password-protected archive Work computer, accounting database, network folders Verify the sender through a separate channel. Do not open macros and executable files
Message from a "marketplace" Link to payment, delivery, refund, or order confirmation Cards, seller cabinet, customer data Work only through the official marketplace cabinet
Fake email login A page resembling Gmail, Microsoft 365, or corporate email Email, documents, access to services, correspondence with clients Check the website address. Enable MFA and change the password if data has already been entered
Call from "tech support" Asking to install remote access software or dictate a code Computer, bank, accounting program, files End the call. Contact official support independently

Main types of phishing

  • Mass email phishing. Identical emails are sent to thousands of addresses. The goal is to get at least some passwords or infected computers.
  • Spear phishing. The email is tailored to a specific company, employee, or owner. Open information from the website, social networks, vacancies, registries, and previous leaks is used.
  • Messenger phishing. Links are sent via Telegram, Viber, WhatsApp, Facebook Messenger, or Instagram Direct. They are often sent from the hacked account of an acquaintance.
  • QR code phishing. The code leads to a fake login or payment page. This is convenient for the scammer because the user does not see the destination address beforehand.
  • Voice phishing (Vishing). A call on behalf of a bank, security service, supplier, tech support, or manager. The goal is to force the person to act quickly.
  • Phishing with MFA interception. A fake page asks not only for a password but also for a one-time code. Therefore, regular two-factor authentication via SMS or an app code reduces the risk but is not an absolute defense.
  • Phishing via fake apps. A person is offered to install a "bank app", "delivery app", "cabinet update", or "document viewer". In reality, it is malware.

How the attack develops after a click

The danger of phishing does not end with the theft of one password. In many cases, it is the first stage of a broader attack.

  1. Initial access. The employee enters a password, opens a file, or runs a program.
  2. Persistence. The attacker adds a new device, creates an email forwarding rule, installs remote access, or steals session cookies.
  3. Internal reconnaissance. They review correspondence, documents, folders, server names, access to banks, marketplaces, PRRO, and accounting systems.
  4. Privilege escalation. They try the same passwords on other services, look for administrator access, open RDP, VPN, network folders, and permanently connected drives.
  5. Main action. They steal money, change details in invoices, delete or encrypt files, download client databases, or block access.
  6. Covering tracks. They delete emails, forwarding rules, logs, backups, or login notifications.

Typical business mistakes

  • One password is used for email, banking, marketplaces, and work services.
  • Two-factor authentication is not enabled for email, Google/Microsoft, banking, hosting, marketplaces, and remote access.
  • The cashier or manager works with Windows administrator privileges.
  • The server or main computer is used for email, browsing, messengers, and downloading files.
  • RDP is exposed directly to the internet.
  • Remote support programs are installed permanently and accessible without the owner's control.
  • The backup is stored on the same computer or on a permanently connected drive.
  • Backups are created, but they have never been restored for testing.
  • Employees do not know whom to notify about a suspicious email.
  • After an incident, the computer is immediately "cleaned up" without recording the traces of the attack.

What to do during an incident

  1. Stop the operation of the suspicious device on the network. Disconnect the Ethernet cable or Wi-Fi. If it is a cash register, switch sales to a backup scenario.
  2. Notify the responsible person. The owner, administrator, or contractor must know about the incident immediately, not at the end of the day.
  3. Do not re-enter passwords. If a page "rejected the password," it could be a sign of phishing.
  4. Change passwords from a clean device. Do not change the password from a computer that might have been infected.
  5. Check email rules. Especially auto-forwarding, filters, delegated access, and connected apps.
  6. Check banking operations. Contact the bank immediately if necessary.
  7. Check backups. You need a copy created before the incident, ideally one that was not permanently accessible from the infected computer.
  8. Record the timeline. This will help understand exactly what was compromised.

What NOT to do

  • Do not pay a "fine," "commission," "customs fee," or "unlock fee" via a link from an email or messenger.
  • Do not reopen a suspicious file "to check."
  • Do not forward a suspicious email to other employees asking them to take a look.
  • Do not enter a password on a page whose address you haven't verified.
  • Do not provide codes from SMS, a banking app, or an authenticator over the phone.
  • Do not connect an infected computer to network folders and backup drives.
  • Do not restore operations from the first found backup without checking its date and integrity.
  • Do not assume the antivirus will solve the incident entirely on its own.

Technical recovery procedure

Recovery must proceed from critical processes to secondary ones. For a store, the priority is sales, inventory tracking, cash register, banking, orders, customer database, and documents.

  1. Define the scope of the incident. Which devices, accounts, folders, and services might have been affected.
  2. Isolate infected devices. Do not reconnect them to the network until verified.
  3. Check accounts. Email, Google/Microsoft, banking, marketplaces, PRRO, hosting, delivery services, remote access.
  4. Check backups. The copy must have been created before the attacker's infiltration. If the attack started a week ago, yesterday's backup might already contain the problem.
  5. Restore the system in a clean environment. Do not deploy the database on a computer that has not yet been verified.
  6. Update Windows, browsers, office applications, antivirus, and remote access tools.
  7. Revoke unnecessary access. Delete old employee accounts, temporary contractor access, unknown programs, and connected devices.
  8. Conduct a brief post-mortem. What caused it, which actions worked, what needs to be changed.

Protecting the store's Windows server

If the server or main computer with the accounting program runs on Windows, it must be treated as a critical business element. It should not be used to read emails, open attachments, chat in messengers, browse random websites, install third-party programs, or be used as the owner's regular computer.

  • Create separate Windows accounts for the administrator, cashiers, managers, and contractors.
  • Regular employees should not work with administrator privileges.
  • Enable automatic updates for Windows and core programs.
  • Use an antivirus or Microsoft Defender protection with regular updates.
  • Separate guest Wi-Fi from the work network.
  • Limit access to network folders: an employee should only see what is necessary for work.
  • Do not store passwords in text files, in the browser on the server, or on the desktop.

Remote Access

Remote access is necessary for support, but it often becomes a weak point. Direct RDP from the public internet should not be used. If remote connection is necessary, it must be organized via VPN, separate accounts, strong passwords, connection logs, and multi-factor authentication if supported.

AccessRiskHow to make it safer
RDP exposed to the internet Password guessing, vulnerability exploitation, server encryption Close direct access. Use VPN and MFA
One password for all contractors Impossible to trace who connected Separate account for each contractor
Permanently active remote support program Access can be used by someone it wasn't intended for Enable access only during work and monitor the session
Administrator access for a cashier Malware gains more privileges Separate roles and minimum privileges

Backup

A backup only makes sense if it can be restored. A copy on the same server or a permanently connected drive might be encrypted along with the primary files. Therefore, different types of backups are needed: local for quick recovery, cloud or isolated to protect against hardware failure, and a separate copy inaccessible to regular work accounts.

  • Daily, create a backup of critical data: accounting database, documents, orders, integration files.
  • Weekly, verify that the backup was actually created and contains no errors.
  • Monthly, perform a test restoration on a separate computer or in an isolated environment.
  • After an incident, do not overwrite old backups until you understand the date of infiltration.
  • Separately, store passwords to the backup storage and restrict access to it.
How this relates to Torgsoft

For Torgsoft users, the option Cloud Data Archive | 1-Year License is appropriate. It creates an archive of the database or program directory and sends it to Google Drive on a schedule. In the settings, you can select the task type: database archive, program directory, or photo synchronization. For the database archive, file compression, an execution log, backup retention period, and a TORGSOFT_CLOUD folder in the cloud storage are available.

It is important to understand the limits of such an option. A cloud archive does not stop an employee from entering a password on a phishing site, and it does not decrypt infected files. Its value lies elsewhere: if the database is corrupted, the computer breaks down, or data is lost, the business has a chance to restore operations from a valid backup.

Multi-Factor Authentication (MFA)

Multi-factor authentication means that logging in requires not only a password but also an additional factor: an app code, a hardware key, or confirmation on a trusted device. For business, it must be enabled at a minimum for email, Google/Microsoft, banking, hosting, marketplaces, CRM, PRRO, VPN, and remote access.

The best option for critical accounts is phishing-resistant authentication, such as hardware security keys or passkeys, if the service supports it. SMS is better than just a password, but an SMS code can be lured out or lost via SIM swapping.

Employee Training

Training shouldn't just be a "don't click suspicious links" lecture. An employee must know the specific procedure: what to consider suspicious, to whom to forward a message, how to verify a supplier, what to do with an archive, when to stop a transaction, and who to call.

  • Conduct a brief briefing for new employees before granting access to email, the cash register, and the accounting system.
  • Repeat the briefing at least once a year.
  • Separately train employees working with the bank, marketplaces, delivery, refunds, and supplier documents.
  • Do not punish for reporting a mistake. If an employee is afraid to speak up, the business will learn about the attack too late.

Distribution of Responsibility

Who is responsibleArea of responsibilityFrequency
Owner Access rules, security budget, responsible persons, backup operation scenario Review quarterly and after an incident
Administrator or IT contractor Updates, antivirus, VPN, RDP, accounts, backups, logs Monthly; critical updates — immediately
Store Manager Compliance with rules by employees, reporting suspicious situations Continuously
Cashier or Manager Do not open suspicious files, do not enter passwords on unknown sites, report incidents Daily
Accountant or Financier Verification of details, payments, emails from banks and contractors Before every payment

Practical checklist for the owner

  • All work emails have unique passwords and MFA.
  • Passwords are stored in a password manager, not in a spreadsheet or notepad.
  • Employees do not have Windows administrator privileges unnecessarily.
  • RDP is not exposed directly to the internet.
  • Remote access is provided via separate accounts and only for the duration of the work.
  • The accounting server is not used for email, messengers, or browsing.
  • Customer Wi-Fi is isolated from the work network.
  • Backups are created automatically.
  • There is a backup inaccessible to an infected work computer.
  • A test restoration was performed within the last month.
  • Employees know whom to notify about a suspicious email or call.
  • There is a brief instruction in case of phishing: computer isolation, changing passwords, banking check, backup check.

Sources

  1. CERT-UA — notifications about current cyberattacks, phishing campaigns, and malware in Ukraine.
  2. State Service of Special Communications — methodological recommendations on cyber hygiene and employee training.
  3. Cyberpolice of Ukraine — recommendations regarding phishing, fake accounts, and fraudulent links.
  4. National Bank of Ukraine — statistics on payment card fraud in 2025.
  5. NCSC: Phishing attacks — defending your organisation — a multi-layered approach to phishing defense.
  6. NIST Small Business Cybersecurity: Phishing — recommendations for small businesses on recognizing and responding to phishing.
  7. CISA StopRansomware Guide — backups, MFA, updates, remote access, and responding to ransomware.
  8. ENISA Threat Landscape 2025 — European overview of current cyber threats.
  9. Verizon Data Breach Investigations Report — data on the role of phishing, social engineering, stolen credentials, and ransomware in breaches.
  10. Google Mandiant M-Trends — data on initial intrusion vectors, including vulnerability exploitation, phishing, and voice social engineering.
  11. Law of Ukraine "On Personal Data Protection" — general requirements for processing and protecting personal data.
  12. Law of Ukraine "On Payment Services" — general rules for the payment market and authentication of payment service users.