Phishing in the Comox Valley rarely looks like a cartoon scam. It looks like a normal Tuesday.

A clinic front desk in Courtenay opens a PDF that seems to come from a familiar lab supplier. A trades office in Comox gets an Interac request “from the owner” while the owner is on a job site. A church volunteer in Cumberland clicks a Microsoft sign-in link because choir practice starts in ten minutes and the shared calendar “needs attention.”

None of those people are careless. They are busy. Attackers write emails for busy people.

Human Touch IT works with small businesses, clinics, churches, and professional offices across Courtenay, Comox, Cumberland, and nearby Valley communities. This guide is the playbook we wish every Valley team already had printed next to the front desk: what phishing looks like here, what to do in the first minute, and how to harden Microsoft 365 so one click is less likely to become a bad week.

What phishing looks like for Comox Valley businesses

Local teams tell us the same stories:

Fake invoices and payment changes. The logo matches a real vendor. The amount is almost right. The “new banking details” or Interac request is the trap. Construction, clinics, and small professional firms that pay suppliers by email are frequent targets.

Fake Microsoft or Microsoft 365 login pages. The message says your password expired or a shared mailbox needs attention. The page looks polished. If someone types a password, the attacker can walk into email, OneDrive, and Teams under that person’s name.

CEO or pastor fraud. “I’m in a meeting — please send this payment.” The name is familiar. The urgency is the weapon. Valley organizations with one shared inbox and light approval habits get hit hardest.

Shipping and delivery lures. “Your Canada Post / courier package needs a fee.” These are common everywhere; they still work when staff are juggling phones and counter traffic.

You do not need to be a big Vancouver company to be worth attacking. You need an inbox, a bank account, and a busy morning.

The first 60 seconds: a staff playbook

Print this. Share it in Teams. Practice it once at a Monday huddle.

  1. Stop. Do not click links. Do not open unexpected attachments. Do not reply with passwords, codes, or banking details.
  2. Verify out of band. Call the vendor, coworker, or boss on a phone number you already have — not the number in the email. Confirm the invoice, the payment change, or the login request.
  3. Check the basics. Hover (don’t click) to see where a link really goes. Look for odd spellings, brand-new sender domains, and “reply-to” addresses that don’t match the display name.
  4. If anyone entered a password or opened a bad attachment: disconnect from sensitive work if instructed by IT, change the password from a known-good device, turn on or re-check MFA, and tell your IT support immediately so mailbox rules and sent items can be reviewed.
  5. Report internally. One quiet near-miss teaches the whole office. Shame helps attackers; quick reporting helps your neighbours at the next desk.

This is not about perfection. It is about buying time before money or mail access walks out the door.

Harden Microsoft 365 so the next email has a harder job

Training matters. Controls matter more when someone is tired.

For Comox Valley organizations on Microsoft 365, we typically prioritize:

  • MFA that actually stays on for every user — including shared workflows that used to rely on one password on a sticky note.
  • Safer links and attachment handling so the obvious junk is filtered before it reaches the front desk.
  • Mailbox rule reviews after any suspicious login, because attackers love silent forwarding rules.
  • Clear admin ownership so licences, aliases, and ex-staff accounts don’t linger.
  • Short, plain-English coaching for the people who answer the phone and open the mail — not a 40-page policy nobody reads.

Remote fixes cover a lot. When you need hands on a workstation or a calm walkthrough with your team in Courtenay or Comox, we come onsite.

Why Valley clinics, trades, and churches are worth protecting

You hold patient details, job quotes, donor records, and supplier relationships. Downtime on a Monday morning is not an abstract IT metric — it is a full waiting room, a crew standing around, or a Sunday service that can’t play the slides.

Good email security is not fear. It is stewardship: protect the people you serve so one clever PDF doesn’t rewrite your week.

How Human Touch IT helps

Human Touch IT is a local managed IT partner for the Comox Valley. We help with day-to-day support, Microsoft 365 hardening, practical cybersecurity, and clear next steps when something feels off — WhatsApp-friendly when you need a fast human reply, onsite when the problem is sitting on a desk in the office.

If your team has almost paid a fake invoice, or you want a short review of MFA, mailbox rules, and email safety settings, reach out. We’ll keep the conversation practical and local.

Next step: Email support@humantouchit.com, message WhatsApp/phone +1 250-792-0190, or visit https://humantouchit.com — ask for a Comox Valley email-security check.