The Phishing Scam That's Quietly Costing You Clients
A scam built to look like your best client can cost more than a password. Here's the one tell that gives it away, and what protects the business you're building.
By Luna

You recognize the name before you even open the email. It's a client who's been booking with you for months, the same name sitting on next week's calendar. Attached is a document marked confidential and locked with a password. The password sits right there in the email, so you don't even have to ask for it.
That's the whole trick, and it's the setup behind a phishing scam currently working through the inboxes of small service businesses.
It works precisely because it targets busy owners and front-desk staff who already trust the names they recognize. A med spa, a law firm, or a vet clinic runs almost entirely on exactly that kind of trust.
Lunova is a growth marketing agency, not a cybersecurity company. But we build and manage the email and local-presence systems this exact scam is built to exploit, and that's exactly why it's worth a few minutes of attention before it costs more than a password.
Why Service Businesses Are an Easy Mark for Phishing Scams
Most phishing advice assumes a company with a dedicated IT team and someone whose job is reviewing suspicious email.
A ten-person vet clinic or a two-partner law firm doesn't have that person. Whoever opens the inbox that morning, whether it's the owner, the office manager, or a groomer between appointments, makes the call alone in the middle of a full day.
These businesses also run on tight, appointment-packed schedules, which leaves little room to slow down and scrutinize an email that looks routine. A front desk juggling calls, walk-ins, and a full book of appointments doesn't have the luxury of treating every message as a potential threat, and attackers know it.
Service businesses also run on something this exact scam exploits: real, current client relationships.
A med spa's front desk recognizes actual client names because those names are on the schedule every week. A personal injury firm's intake staff expects emails from real clients about real cases.
That familiarity is normally an asset. But here, it's the opening.
What This Looks Like in Different Verticals
The exact version of this scam changes slightly by vertical, but the pattern holds. A few more examples like these live on the blog.
At a med spa, the email might look like it's from a regular client asking about a treatment plan, or from a supplier confirming a product order. The front desk recognizes the name instantly, because that client has been on the books for two years.
At a law firm, especially a personal injury practice, the email might reference an actual case number or claim to be from opposing counsel with a settlement document attached. Intake staff, trained to respond quickly to anything case-related, are exactly the audience this version of the scam is built for.
At a vet clinic, it might arrive as a records request from a pet owner, or an invoice from a supplier the clinic already orders from every month. The urgency lands because the names and the pattern both look normal.
At a wellness studio or a grooming business, the margins are thinner and the staff smaller, which means there's rarely anyone whose job is to double-check an attachment before it gets opened. That makes the habit further down this article matter even more, not less.
A consultant or a local service business often runs everything, marketing, invoicing, and client conversation, from a single inbox with no separation between roles. That convenience is exactly what a well-aimed phishing scam takes advantage of.
The One Detail That Gives the Scam Away
The mechanics are simpler than they sound. A locked file, usually a PDF but sometimes a Word document or a compressed folder, slips past most spam filters because the filter can't scan what it can't open.
The email includes the password to unlock it, framed as a courtesy.
That's the tell. A real client, a real vendor, or a real bank doesn't send a locked file and the key to open it in the same message. If a password shows up anywhere near the attachment, in the same email, that's reason enough to stop and verify before opening anything.
A few other details are worth a second look, even without the password issue. A sender address that's close to correct but not exact, often swapping a letter or using a different domain ending. A generic greeting like "Dear Customer" from someone who normally calls you by name. Urgent, all-caps language pushing for immediate action.
None of these prove anything on their own, but two or three together are a strong signal to stop and verify.
Once someone opens the file and enters the password, the range of what happens next is wide: a fake login page built to steal a password, or a hidden script that quietly installs software giving an outsider ongoing access to the computer. None of it requires the person who opened the file to do anything else wrong. The damage is done at the click.
What Actually Protects a Small, Busy Team
None of this needs a security budget or a new piece of software. It needs one habit, applied consistently, by everyone who opens the inbox, whether that's the owner first thing in the morning or whoever's covering the front desk at closing time.
- Verify unexpected attachments out of band. If a client, vendor, or partner sends something unusual, call them using a number already on file, never the number sitting in the email signature, before opening anything. A thirty-second call catches almost every version of this scam.
- Treat a password included in the same email as a hard stop. Legitimate senders don't lock a file and hand over the key in one message. If that pattern shows up, don't open it, and flag it to whoever manages your accounts or your website.
- Slow down on urgency. These emails work by creating pressure: an invoice that's suddenly overdue, a document that needs review today, a client who sounds upset. A moment of hesitation is usually enough to catch the mismatch.
A simple line covers most of it as a standing rule: "If an attachment feels unexpected, we call before we click, every time, no exceptions." Posting that near the shared inbox, or just saying it once in a team meeting, does more than any software subscription.
If a shared inbox, a booking system login, or a review-platform account gets compromised, treat it the same way as a stolen key to the front door.
Change the password immediately, check for any new email-forwarding rules that might quietly be sending copies of client emails somewhere else, and let clients know if anything client-facing was affected. A quiet compromise that goes unnoticed for weeks does more damage than the original email ever could.
We build and manage email marketing for a lot of the businesses we work with, which means we spend real time in the same inboxes this scam targets. The fix isn't complicated. It's a habit the whole front desk follows, not a piece of software.
Protecting the Trust You've Already Built
A service business runs on the relationships already sitting in its system: the client who rebooks every six weeks, the case that came in through a referral, the regular who leaves a five-star review. Phishing scams like this one work because they aim directly at that trust.
The cost of one successful scam isn't only the immediate one, a drained account or a locked computer. Clients notice when a business's systems feel shaky, when a follow-up email never arrives because an account got locked down, or when a booking confirmation goes missing. For a business built on repeat visits and referrals, that quiet erosion of trust often costs more than the scam itself.
Catching one takes less effort than most owners expect. A verification call, a second look at a password sitting next to the file it unlocks, and a team that knows to pause before clicking, that covers most of it.
Protecting client trust is as much a marketing question as a security one, and it's close to what a lot of our own work comes down to: the email, the reviews, and the local presence that make a business worth trusting in the first place. If it's time for a wider look at how those pieces are holding up, our free Growth Audit is a good place to start.
Frequently Asked Questions
What is a password-protected PDF phishing scam?
It's a phishing tactic where an attacker sends a locked file, usually a PDF but sometimes a Word document or compressed folder, along with the password to open it in the same email. The locked file slips past most automatic security scans, since a scanner can't inspect what it can't open, and the password makes the file feel more legitimate to the person receiving it.
How can I tell if an email from a client is really from that client?
Check whether the request matches how that client normally reaches out, and look at the full email address rather than just the display name. If anything feels off, especially an unexpected attachment or a request tied to urgency, call the client on a number you already have on file instead of replying to the email.
Why do service businesses get targeted by this kind of scam?
Med spas, law firms, vet clinics, and similar businesses run on real, ongoing relationships with clients whose names and contact details sit in an accessible booking system. That familiarity is exactly what a spoofed known-client email is built to exploit, and most of these businesses don't have a dedicated IT team screening every message that comes in.
What if the scam email includes something that looks like a real invoice or case file?
Treat realistic details as a reason for more caution, not less. Attackers often pull real names, real case types, or real product categories from public information or an unrelated data breach, which makes the email look convincing without meaning it's actually from that person. The verification call still applies regardless of how legitimate the details look.
What should my team do if someone already opened a suspicious attachment?
Disconnect the device from the network right away and stop using it until it's been checked. Don't try to fix it directly. If a password or login was entered anywhere, treat those credentials as compromised and change them from a different, unaffected device.
Does a small service business really need a formal policy for this?
It doesn't need to be complicated. One clear rule, followed consistently, covers most of it: verify unexpected attachments by phone before opening them, and treat a password sent alongside the file as an automatic stop. A five-minute conversation with the whole team is usually enough to put that habit in place.