Call UsGet Free Assessment
    Back to Blog
    Small Business Stories7 Min Read

    No Sirens, No Warnings, Just Loss: Janet's Story

    No Sirens, No Warnings, Just Loss: Janet's Story

    We spend a lot of time on this blog explaining threats, defining terms, and listing protections. All of it matters. But sometimes the most useful thing is simply a story, because a story shows you how these things actually happen to real, ordinary businesses run by careful, competent people. So let me tell you about Janet. Her story appears in my book, Operation CyberGuard, and it has stayed with me because it is so quietly, painfully typical. If you have ever thought "that kind of thing happens to other businesses, not mine," Janet probably thought the same.

    A solid business, run well

    Janet ran a commercial cleaning company. It was not glamorous, but it was the kind of business that keeps a community running, offices, buildings, spaces kept clean and orderly by a team she had built and trusted. She was good at what she did. She worked hard, she took care of her clients, and she took care of her people. By every measure that mattered day to day, her business was healthy and well run.

    Janet was not careless with technology, either. She was not reckless or naive. She was simply a busy business owner doing what busy business owners do, running her operation over email, coordinating with clients and vendors, sending invoices, handling payments, keeping the wheels turning. Her email was the center of it all, the way it is for most small businesses. And that, it turned out, was exactly the problem, though she had no way of knowing it.

    The intruder no one saw

    At some point, a criminal got into Janet's email account. We may never know the exact way in, a reused password that had leaked somewhere else, a convincing phishing message, one of the ordinary openings these attacks use. What matters is what the criminal did once inside, which was, at first, nothing at all.

    They did not change her password. They did not send obvious spam. They did not do anything that would trip an alarm or make Janet suspect a thing. They simply watched. For roughly three weeks, this intruder sat quietly inside Janet's email, reading. Learning. They saw how she communicated, who her clients and vendors were, how money moved through her business, what her invoices looked like, and the rhythm of her day. Every single day during those three weeks, Janet ran her business as usual, confident and unaware, while a stranger read over her shoulder.

    This is the part that unsettles people most, and it should. There were no sirens. No warnings. Nothing looked wrong, because from the outside, nothing was wrong. The business ran. The clients were served. The team did their jobs. And underneath all of it, patient and invisible, someone was preparing to take everything they had learned and turn it into a theft.

    The moment it all came due

    When the criminal finally acted, they did so with the precision that three weeks of watching had given them. Using everything they had learned about how Janet's business handled money, they redirected funds, a payment that should have gone one way instead flowing quietly to the criminal. Because the fraud was built on real knowledge of her business, it did not look out of place. It looked like business as usual, right up until it wasn't.

    By the time the truth came to light, about eighteen thousand dollars was gone. For a small cleaning business, that is not an abstract number. That is real money, earned through real work, that simply vanished. And the money was only part of it. What followed was months of rebuilding, not just financially, but rebuilding trust, with the people and partners caught up in the fraud, and rebuilding her own sense of security in a business she thought she had well in hand. As I wrote in the book, it was no sirens, no warnings, just loss.

    What Janet's story teaches

    I do not tell Janet's story to frighten you. I tell it because it is instructive, and because the lessons in it are ones every business owner can act on. A few things stand out.

    First, the most dangerous attacks are often the quiet ones. We picture cybercrime as loud and obvious, the locked screen, the ransom demand. But what happened to Janet, a criminal silently occupying an email account and waiting, is one of the most common and costly scams there is. It has a name, business email compromise, and it drains more money from businesses than the dramatic threats that get the headlines. The absence of any warning sign is not proof that all is well. It can be the very thing the attacker is counting on.

    Second, this was preventable, and that is the hopeful part. A single protection would very likely have stopped it before it started: multi-factor authentication on Janet's email, the extra code on her phone, would have kept the criminal from getting in with a stolen password in the first place. And even if they had gotten in, monitoring that watches for unusual activity could have caught the intruder during those three silent weeks, while there was still time to act. The verify-by-phone habit, confirming payment changes through a known number, could have stopped the final theft even at the last moment. Janet's loss was not inevitable. It sat behind several doors that a few basic protections would have locked.

    Third, being careful and competent is not the same as being protected. Janet did nothing foolish. She was a capable owner running a good business. But capability is not a security control. The protections that would have saved her were specific, concrete things, not a matter of being smart or careful enough. That is actually good news, because it means protecting your business is not about being perfect. It is about having the right locks in place.

    How we think about it

    Janet's story is exactly why we built Red Door Shield the way we did, around a simple framework we call KIT: Keep, Inspect, Trust. Keep what is valuable secure, with the multi-factor authentication that would have kept the criminal out of Janet's email entirely. Inspect what is coming in, with the monitoring that could have caught a silent intruder during those three weeks instead of letting them work unseen. And trust through validation, the verify-before-you-pay habit that stops the theft even at the final step. Everything about how we protect businesses is aimed at making sure another Janet does not have to learn this lesson the hard way, that the quiet intruder is kept out, spotted early, and stopped before the loss.

    What ready looks like

    Picture Janet's story with a different ending. The criminal tries to get into her email, and multi-factor authentication stops them cold, they have her password but not her phone, and they never get in. Or if they somehow did, monitoring flags the strange login within a day, and the intruder is discovered and removed while her money is still safe. Or the fraudulent payment request meets a quick verifying phone call and falls apart. Same business, same busy owner, but the doors are locked, and the story is one she never even knows to tell, because nothing was ever taken.

    That is what ready looks like. Not being smarter or more careful than Janet, she was plenty of both, but having the specific protections in place that turn a silent intruder's patient work into a locked door and a wasted effort.

    Janet's story is one small business among countless others living some version of it right now, quietly, with no idea. You do not have to be one of them. The protections that would have changed Janet's ending are within reach of any business. If you want to make sure a quiet intruder could not do to your business what one did to Janet's, that is exactly what our free Business Security Assessment is for, and it is a conversation worth having today, before the story is yours.

    Learn about business email compromise, read about how to tell if someone is in your email, or see our guide on deepfake voice scams.

    Know Where Your Business Stands

    Our free Business Security Assessment gives you a clear, professional picture of your current security posture in less than 10 minutes. No technical knowledge required.

    Not sure where your business actually stands?

    Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.

    Get My Free Security Assessment
    Share this post:
    Tony Chan, Founder of Red Door Technologies

    Tony ChanFounder of Red Door Technologies LLC and the author of Operation CyberGuard: Protect Your Business, Outsmart Cyber Threats, and Secure Your Future. He has served small businesses across Chicago for 17 years.

    Related Articles

    Free Security Resources

    Employee Security Checklist

    A simple, plain English checklist for your team to prevent the most common email attacks.

    Vendor Risk Assessment

    Questions you must ask your IT provider or software vendors to ensure they aren't your weakest link.

    Operation CyberGuard

    Download a free sample chapter from Tony Chan's 2025 guide: "The 5 Lies Business Owners Believe About Cybersecurity."

    Stay Ahead of the Threats

    Join Chicago business owners who receive our plain-English cybersecurity updates, threat alerts, and practical advice directly in their inbox.

    We respect your privacy. No spam, ever.