top of page

The Scam That Comes In Asking to Buy From You

Most security advice trains you to watch for threats. Watch for the urgent invoice. Watch for the password reset you did not request. Watch for the angry message about your account being suspended.


Almost none of it trains you to watch for good news.


Last week a message landed in our inbox at Asheville Computer Company from someone who had "come across" our company and wanted a quote. Professional tone, no urgency, no threats, no spelling errors. It was a scam, and it was aimed at the one inbox in a small business that nobody wants to filter too aggressively: the one where new work comes from.


We want to walk through it, because the shape of this one is worth knowing.


Why a fake quote request works so well


Every piece of security training you have ever sat through is built around suspicion. A fake RFQ neatly sidesteps all of it, because it does not ask you for anything. It offers you something.


Think about what happens inside a small business when a request for a quote arrives. Nobody says "let me verify this before I respond." Somebody says "great, a lead." The message gets a fast, friendly reply, often from the owner. It gets forwarded to whoever prepares pricing. It skips every instinct you have carefully built, because responding quickly to a potential customer is not carelessness. It is good business.


That is the whole trick. The attacker is not fighting your judgment. They are recruiting your sales reflex to do the work for them.


It also explains why this lands hardest on small businesses. In a larger company, an RFQ goes to a purchasing process, a portal, or a person whose job is procurement. In a ten person business in Arden or Hendersonville, it goes straight to the owner's phone, and the owner is standing in a parking lot between jobs.


The five tells


Individually, none of these prove anything. Any two together are enough to stop and verify.


1. The reply comes from a different domain than the first message


This is the strongest single signal, and it is easy to miss because most people never look at the full address on a reply. The opening message arrives from one company's domain. When you respond, the answer comes back from something else entirely, often a generic sounding name built around words like "proposals," "sourcing," or "procurement."


Legitimate businesses occasionally have messy email setups. But a company that contacts you from one domain and answers from an unrelated one deserves a look before you send anything.


2. There is no actual project in the project


Read the request again and ask what you are being asked to price. A real quote request has specifics: a location, a quantity, a timeline, a piece of equipment, a building, a problem. A fake one is written to fit any business that receives it, so it stays at the level of "project scope, service requirements and material specifications."


If you could send the identical message to a roofing company, a print shop, and an IT provider without changing a word, it was probably sent to all three.


3. The ask is a meeting, not a conversation


Notice how quickly it pushes toward a scheduled call. A genuine buyer usually has a question first. They want to know if you do the thing, if you cover their area, roughly what it runs. The fake version skips all of that and moves to a meeting invitation, because the meeting is the pretext for sending you a file or a link.


4. The document arrives as a "one time" download link


Here is the heart of it. You are told a document is attached or shared, and the link is described as single use, expiring, or secure. Often it is dressed up in Microsoft branding, a SharePoint or OneDrive style page, which is exactly the point.


A link is not trustworthy because it looks like Microsoft. Anyone can build a page that looks like a Microsoft sign in page in an afternoon. What that page wants is for you to type your email and password into it, and the "one time" framing exists to make you act before you think.


If your credentials go into that box, the attacker now has your real mailbox. What follows is not usually dramatic. They read quietly, learn who pays your invoices, and wait for a real payment conversation to hijack.


5. You did not go looking for them


The message opens by explaining how they found you. "We came across your company while searching for providers in your area." It sounds like a compliment and it functions as an explanation, heading off the natural question of why a stranger is contacting you.


Real inbound leads happen constantly, so this is the weakest tell on its own. Paired with any of the four above, it stops being a compliment.


A note on the company being named


One detail worth understanding: the business named in the opening message may be completely real and completely innocent.


Scammers borrow the identity of legitimate companies, often well known regional or national brands, because a name you can look up creates instant credibility. You search the company, find a real website and real reviews, and relax.


This matters for how you respond. If you decide to block something, block the specific sending address and the unrelated reply domain. Do not blanket block the impersonated company's domain, because you may simply be cutting off a real business that had nothing to do with it, and that has a habit of causing problems later.


What actually matters if you already engaged


A confession first, because it makes the point better than a warning would. In our case the PDF was opened. On a phone, by the owner of an IT company, in the middle of a workday. It was obvious what it was within a second or two of it loading, nothing in it was clicked and no password was typed anywhere, but we are not going to pretend the attachment went untouched.


That is exactly why we can be precise about what comes next, and this is the part most articles get wrong. They either skip the question or answer it with a wall of panic.


Opening a message is not a breach. Replying to a message is not a breach. Even opening an attached PDF, by itself, is very unlikely to be a breach on a current, updated phone or computer.


The attack in this pattern is credential theft. The document is a wrapper. Its entire job is to get you to click through to a sign in page and type your password. That means the question that determines whether you have a problem is narrow and specific:


Did you enter your email address and password into anything?


If the answer is no, you are almost certainly fine. Block the sender, delete the message, and move on. Wholesale password resets and a day of anxiety are not a proportionate response, and treating every near miss as a crisis mostly teaches people to stop reporting things.


If the answer is yes, or you are not certain, then act, and it is still a short list:


  • Change the password on that account immediately, from a device you trust.

  • Confirm multi-factor authentication is switched on for that account.

  • Check your mailbox rules and forwarding settings. Attackers commonly add a quiet rule that copies or hides certain messages, and this step is the one people skip.

  • Tell whoever handles your IT, so they can check sign in activity for logins from unfamiliar locations.


There is one real consequence even when nothing is clicked. Responding tells the sender that a live human reads that address. Expect more attempts, and expect the next one to reference the earlier conversation to sound familiar. Recognition is the defense there, not cleanup.


The habit that covers all of it


You do not need new software for this. You need one rule, applied to inbound business as readily as you apply it to suspicious invoices:


Verify the entity before you produce anything of value for it.


Before you write a quote, before you take the meeting, before you open the document, spend ten minutes. Ask for the legal business name, a physical address, and a website. Look the company up independently rather than through any link in the message. Call a number you found yourself, not one they supplied.


A real buyer will answer those questions without friction, because a real buyer wants the quote. The ten minutes costs you almost nothing when the lead is genuine, and it ends the scam entirely when it is not.


Final Thoughts


The uncomfortable part of this scam is that the instinct it exploits is a good one. Responding fast to a potential customer is how small businesses win work. Nobody should train that out of their team.


What you can do is put one small step in front of it. Verify who you are dealing with before you invest time, pricing, or a click. That single habit handles fake RFQs, fake vendor invoices, and most of what will replace them next year, because it targets the con rather than the costume.


If you want a second opinion on a message that feels slightly off, or you clicked something and want a straight answer about whether it matters, we are happy to look. We work with small businesses across Asheville, Arden, Fletcher, Hendersonville, and Western North Carolina, and we would rather take a two minute question than a two day recovery.


Call Asheville Computer Company at (828) 290-9092, or reach us through our site.

bottom of page