Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / Cybersecurity

Cybersecurity

Hackers Are Targeting Small Construction Companies And Other Invoice-Heavy Businesses

The blog post highlights the rising trend of cyber-attacks on small construction companies and other invoice-heavy industries. It details how attackers exploit these businesses through business e-mail compromise (BEC) and invoice fraud, particularly targeting companies with numerous vendors, frequent mobile sign-ins, and high-pressure environments. To combat these threats, the post emphasizes the importance of using multifactor authentication (MFA), verifying supplier information, keeping employees trained on common attacks, and maintaining strong cybersecurity practices. Implementing these strategies can help small businesses protect themselves from becoming easy targets for hackers.

Randy Hall By Randy Hall Updated Sep 2024 5 min read Share

From 2023 to 2024, attacks on construction companies doubled, making up 6% of Kroll’s total incident response cases, according to the 2024 Cyber Threat Landscape report from risk-advisory firm Kroll. Experts at Kroll note that the uptick could be driven by how work is carried out in the industry: employees work with numerous vendors, work remotely via mobile devices and operate in high-pressure environments where urgency can sometimes trump security protocols. All of these factors make the construction industry ripe for a cyber-attack.

Ripe For Hackers

 

Business e-mail compromise (BEC) – fake e-mails designed to trick employees into giving away money or sensitive information – made up 76% of attacks on construction companies, according to Kroll. These e-mails look like document-signing platforms or invoices to socially engineer users into giving away information.

 

These tactics are having a higher success rate in smaller construction companies for a few reasons:

 

  • They deal with a lot of suppliers and vendors. Construction companies work with many suppliers and vendors, and each vendor can be a weak spot that hackers can exploit. For example, if a hacker gets control of a vendor’s e-mail, they can send fake invoices that look real, tricking businesses into sending money to the hacker’s account instead. Multiply that by the number of vendors you work with, and that’s a lot of potential entry points for a hacker.
  • They use frequent mobile sign-ins. As truly remote workers, construction employees rely on mobile devices to sign into accounts and communicate from anywhere. This mobile accessibility, while convenient, also increases the risk because mobile devices are typically less secure than desktops or laptops.
  • They work in a high-stakes, high-pressure environment. In industries where delays can be costly, such as construction or health care, employees may rush to process invoices or approve transactions without thoroughly verifying their legitimacy. This urgency is precisely what attackers count on to get around standard security checks.

Your Industry Could Be Next

 

Construction companies are not the only ones experiencing more attacks. Small manufacturing companies, higher education institutions and health care providers that lack the robust security infrastructure of larger industry players are also examples of industries seeing a rise in cyber-attacks. These industries, like construction, deal with numerous vendors and urgent invoices, making them prime targets for business e-mail compromise and invoice fraud.

How To Protect Against BEC And Invoice Fraud

 

  1. Use Multifactor Authentication (MFA)

Accounts that use MFA are 99% less likely to be attacked, according to the Cybersecurity and Infrastructure Security Agency. MFA requires multiple forms of verification before granting access to sensitive information. Even if hackers obtain log-in details, they can’t access accounts without the second credential, typically a mobile device or a biometric scan.

 

  1. Always Verify Supplier Information

One of the simplest yet most effective measures is to verify the authenticity of invoices and supplier information. Establish a protocol where employees are required to double-check the details of any financial transactions directly with the supplier through a known and trusted communication channel, such as a phone call.

 

  1. Keep Employees Trained On Common Attacks

Employee training is a vital component of a comprehensive cyber security strategy. Regular training sessions on recognizing social engineering and phishing attempts and understanding the importance of following verification protocols can empower employees to act as the first line of defense. The Information Systems Audit and Control Association recommends cyber security awareness training every four to six months. After six months, employees start to forget what they have learned.

 

  1. Maintain Strong Cyber Security Practices

Cybercriminals regularly exploit outdated software to gain entry into systems. Small businesses can close these security gaps by keeping software up-to-date. Investing in robust antivirus and anti-malware solutions can help detect and stop attacks before they get into your systems.

 

You’re A Target, But You Don’t Need To Be A Victim

 

Hackers are increasingly targeting small, invoice-heavy industries like construction, manufacturing and health care due to their inherent vulnerabilities. By understanding the reasons behind these attacks and implementing robust cyber security measures, small business leaders can protect their organizations from becoming easy targets. Utilizing MFA, maintaining strong cyber security practices, verifying supplier information and training employees are essential to stopping attacks.

Don’t leave your security to chance. Book your FREE Cybersecurity Assessment now.

Tagged Under Cybersecurity

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime