Your staff use social media every day, often on the same computers they use to log in to the bank, payroll and email. But social media is also where criminals learn who works for you, who approves payments, and what kind of link your bookkeeper might click. Pair that with a keylogger on one office computer and a small mistake can become a very expensive one.
Social media: the information and the opening
Social platforms are built for sharing, and attackers use that in three ways.
Research. Job titles, team photos, “excited to start my new role in accounts payable” posts and out-of-office vacation pictures tell a criminal exactly whom to target and when. A convincing fake email from “the owner” asking for an urgent wire transfer is much easier to write when you know the owner is on a fishing trip.
Delivery. Messages, ads and posts carry links to fake login pages, fake software downloads and “you have to see this” files. Sophos has reported that criminals promote password-stealing malware through ads, search results and social media posts disguised as popular business apps. One click on a work computer is all it takes.
A voice to go with it. A few seconds of someone speaking in a posted video can be enough for AI tools to imitate their voice. The FBI has warned about AI-generated voice messages impersonating senior officials, and the same trick works on a bookkeeper who hears “the owner” on a voicemail. In its 2025 Internet Crime Report, released April 2026, the FBI included a section on artificial intelligence for the first time: 22,364 complaints and nearly $893 million in losses, with scammers using fake profiles, voice clones and believable videos.
This is not a distant problem. According to the FBI’s Anchorage office, Alaskans reported about $7 million in business email compromise losses in 2025 (fraud that uses hijacked or faked email and other messages to redirect payments).
Keyloggers: the quiet part
A keylogger is software that secretly records every key pressed on a computer and sends it to the attacker: usernames, passwords, email drafts and account numbers. Modern “information stealers” go further: they also copy passwords saved in the browser and the cookies that keep you logged in to websites.
Keyloggers arrive the same way most malware does: an email attachment, a fake update, a bad download, or a compromised website. The computer keeps working normally, so the user usually notices nothing.
With the right keystrokes, a criminal can sign in to online banking, change the payee on an invoice, read email to learn how payments are approved, or quietly copy customer data.
Why two-factor codes are not the whole answer
Two-factor authentication (2FA), also called multifactor authentication (MFA), asks for a second proof of identity on top of a password. Every business should use it.
But it has limits against this particular threat. If a keylogger is watching in real time, it can capture the six-digit code from your text message or app as you type it, and the attacker can use it within seconds. Information stealers that copy browser session cookies can sometimes skip the login step entirely, because the site thinks you are already signed in.
That is why CISA describes phishing-resistant MFA, based on the FIDO standard, as the strongest form. Security keys and passkeys work this way: nothing is typed that could be recorded and replayed, and the key only answers the real website. CISA also notes that any MFA is better than none, so do not switch off codes while you plan the upgrade.
The industry is moving this way. Microsoft began rolling out passkeys as the default sign-in method for Microsoft 365 work accounts (Entra ID) on September 1, 2026, and plans to retire its own text-message and voice-call codes from February 1, 2027. If your office runs on Microsoft 365, plan the change rather than be surprised by it.
What to do about it
- Use stronger MFA where the money is. Start with email, banking, payroll and administrator accounts. Move them to security keys or passkeys where the service supports them.
- Verify payment changes by calling back. Any request to change bank details or send an urgent transfer gets a call to a known number, not the one in the message. A familiar voice on a voicemail or video call is no longer proof on its own. This one habit stops a lot of fraud.
- Agree on a code word for urgent money requests between owners and whoever pays the bills, as the FBI suggests for families.
- Keep banking on a clean machine. Where practical, do online banking from a computer that is not used for social media or general browsing.
- Use a password manager, not the browser, to store passwords.
- Set a sensible social media policy. You do not need to ban it. Agree on what staff should not post (org charts, travel plans, photos of screens and whiteboards) and whether personal social media belongs on work computers at all.
- Run endpoint protection that looks for behavior, not only known files, and keep it centrally monitored so alerts reach someone.
- Train people briefly and often. Short, regular reminders about fake login pages and urgent money requests work better than one long annual session.
- Log out and lock up. Signing out of banking and admin sites at the end of the day limits what a stolen session is worth. See Log out at the end of the day.
How FTI helps
We manage Sophos endpoint, email and firewall protection for our clients and keep systems patched through Kaseya. AI watches security logs and alerts around the clock and puts the full picture in front of our engineers, who decide what to do, with a help desk available 24/7. We also help move accounts to passkeys, set up password managers and write simple policies that fit how your office works. Read more about our security services.
No single tool closes every gap. Layers, good habits and someone watching reduce the risk.

