Scams: The latest in 2022 Holiday's

Learn how small firms lost billions to holiday scams in 2022. Discover key tactics like phishing and BEC, plus practical steps to protect your business data.
In 2022, the Federal Trade Commission (FTC) reported that consumers lost a staggering $8.8 billion to scams—a 30% increase over the previous year. For the small professional service firms I’ve spent the last 26 years protecting, those aren't just numbers on a spreadsheet; those represent drained operating accounts, compromised client data, and the kind of sleepless nights that keep founders like you and me up until 3:00 AM. As the holiday season approaches, I’m looking back at the 2022 landscape because that year marked a fundamental shift in how criminals target businesses with under 100 employees. They stopped swinging for the fences with big banks and started bunting for singles against small law firms, accounting practices, and engineering groups.
I started Sentree Systems in 1999, and if there is one thing I’ve learned in over two and a half decades, it’s that scammers love the holidays more than a kid loves a snow day. Why? Because you’re distracted. Your controller is trying to wrap up the year-end books, your associates are rushing to finish projects before taking time off, and everyone is clicking on links just a little bit faster than they should. In my experience, a small business is most vulnerable when it is "busy but understaffed," which is the exact definition of a professional service firm in December. According to the IBM Cost of a Data Breach Report 2022, the average cost of a breach for a company with fewer than 500 employees was roughly $2.98 million. For a firm with 20 employees, that isn't just a setback—it’s an extinction-level event.
I’ve seen firms lose their entire reputation over a single clicked link in a "package delivery" email. I’ve sat in offices where the CEO had to explain to their staff that bonuses were delayed because $50,000 was wired to a scammer impersonating a vendor. The 2022 holiday season was a masterclass in psychological manipulation. By understanding these specific threats, we can build a "human firewall" that protects your bottom line. We aren't looking for fancy, expensive AI solutions here; we are looking for practical, direct, and common-sense ways to stop these criminals from ruining your holidays.
Key Takeaways
- Human Error is the Primary Vector: The 2022 Verizon Data Breach Investigations Report (DBIR) found that 82% of breaches involved a human element, including social engineering and phishing.
- Financial Loss is Exploding: Business Email Compromise (BEC) and holiday-themed scams saw a 30% year-over-year increase in reported losses, totaling billions globally.
- Urgency is the Scammer's Best Friend: Almost every holiday scam relies on creating a false sense of "do it now" to bypass your critical thinking skills.
- Verification is Non-Negotiable: Never change payment instructions or buy gift cards based on an email alone, regardless of who it appears to be from.
- Multi-Factor Authentication (MFA) is the Baseline: Implementing MFA can block over 99% of account takeover attempts, yet many small firms still hadn't adopted it by the 2022 season.
- Small Businesses are Targets, Not Afterthoughts: Scammers know that firms with under 100 employees often have less sophisticated security than enterprise giants.
The Rise of Charity and Gift Card Fraud
The Psychological Trap of Fake Charities
In my 26 years in this business, I’ve noticed that scammers are excellent at weaponizing your kindness. During the 2022 holiday season, we saw a massive influx of "urgent relief" funds. Scammers create websites that look nearly identical to legitimate non-profits. They use names that are one letter off from the Red Cross or United Way. I remember working with a boutique consulting firm where a senior partner donated $2,000 to what he thought was a local children’s hospital fundraiser. It turned out to be a phishing site that not only took his "donation" but also harvested his credit card details and his work email password.
The FTC notes that scammers often use high-pressure tactics, asking for donations via wire transfer, cryptocurrency, or gift cards—none of which a real charity would ever do. If you’re a small business owner, I recommend creating a "Pre-Approved Charity List" for your firm. If an employee wants to donate or the firm wants to do a holiday drive, it must come from that list. This removes the "spur of the moment" decision-making that leads to fraud.
The $15,000 Gift Card Mistake
One of the most persistent scams in 2022 was the "Gift Card Request" from the CEO. You’ve probably seen the email: "Hey, I’m in a meeting and I need to get some gift cards for clients. Can you go buy ten $100 Apple cards and text me the codes? I’ll reimburse you by end of day." It sounds ridiculous when you're reading this in a blog post, but in the heat of a busy Tuesday morning, it works. I personally handled a case where a junior accountant at a 15-person law firm spent $1,500 of her own money because she thought the founding partner was asking for a favor. The scammer had spoofed the partner’s name so it appeared correctly on her smartphone.
The math on this is simple: Gift cards are essentially untraceable cash. Once you send that code, the money is gone. There is no "chargeback" for a gift card. In 2022, the BBB reported a sharp rise in "empty" gift cards as well—cards where the magnetic strip had been compromised at the store before purchase. My advice is always the same: No legitimate business transaction will ever require a gift card. Period.
Package Delivery and Smishing Threats
The "Unpaid Shipping Fee" Lure
If you're like most small business owners, your office receives 5-10 packages a day during December. Scammers know this. In 2022, "Smishing" (SMS Phishing) became the tool of choice. You get a text that says, "Your FedEx shipment has a pending fee of $1.50. Click here to pay and schedule delivery." It’s a low dollar amount, so your guard is down. But that link doesn't go to FedEx; it goes to a credential harvesting site designed to steal your credit card and your phone’s data.
According to KnowBe4, package delivery lures consistently have the highest click rates in phishing tests, often exceeding 15-20% during the holidays. I’ve seen this lead to full network compromises. A user clicks the link on their phone, which is connected to the office Wi-Fi and synced to their work email. The malware jumps from the personal device to the corporate network, and suddenly I’m getting a call about ransomware at 6:00 PM on Christmas Eve. The cost to remediate a situation like that can easily exceed $20,000 in labor alone, not counting the lost productivity.
Spoofed Tracking Numbers and Malware
Another variation we saw heavily in late 2022 was the "Attached Invoice" or "Shipping Confirmation" email containing a .zip or .html file. These aren't just documents; they are scripts. Once opened, they install a "keylogger" that records every keystroke your employee makes—including their bank login and client passwords. For a professional service firm, this is a nightmare because you have a fiduciary responsibility to protect client data. A breach like this could trigger mandatory reporting requirements under state laws, which costs an average of $164 per compromised record according to IBM’s 2022 data.
| Scam Type | Primary Target | 2022 Trend Severity |
|---|---|---|
| CEO Gift Card Spoof | Admin/Junior Staff | High - Low Technical Skill Required |
| Smishing (SMS Phishing) | All Employees | Extreme - 300% increase since 2020 |
| Fake Airline Tickets | Holiday Travelers | Medium - Focuses on personal loss |
| Invoice Interception | Accounts Payable | Critical - Highest Financial Impact |
Travel Scams and Cryptocurrency Fraud
The Fake Airline Ticket Trap
As post-pandemic travel surged in 2022, scammers pounced on the "revenge travel" trend. They created sophisticated booking sites offering 40% off last-minute holiday flights. For a small business owner trying to fly their family across the country, these deals look like a godsend. However, the Better Business Bureau warned that these sites often just take your money and provide a fake confirmation number. In some cases, they actually book the flight using a stolen credit card, which results in your ticket being canceled by the airline two days before your trip when the fraud is detected.
I always tell my clients: If the price is significantly lower than the airline’s own website, it’s a scam. There are no "secret" portals for 50% off holiday airfare. From a business perspective, if your employees are using work computers to search for these "deals," they are exposing your network to malvertising (malicious advertising). One bad ad on a shady travel site can trigger a background download that bypasses traditional antivirus software.
Cryptocurrency ATMs: The New Money Laundering
By 2022, Bitcoin ATMs were popping up in every gas station and convenience store. Scammers started using them as a way to circumvent the banking system's fraud alerts. They will stay on the phone with a victim, directing them to withdraw cash from their bank and deposit it into a specific crypto wallet via an ATM. They might claim your "Social Security number has been suspended" or that you owe "unpaid holiday taxes."
I once had a client—a very sharp engineer—who almost fell for this. He received a call claiming to be from his bank's fraud department saying his account was compromised. They told him the only way to "protect" his money was to move it to a "secure government-backed crypto locker." Luckily, he called me first. The rule is simple: No government agency or legitimate bank will ever ask you to use a cryptocurrency ATM. These machines are the preferred tool of the modern scammer because the transactions are irreversible and pseudonymous.
Implementation Best Practices: Your Holiday Security Roadmap
Knowing about the scams is only half the battle. The other half is taking direct, practical action to prevent them. You don't need a million-dollar budget to protect your firm; you just need a consistent process. Here is the checklist I give all my professional service clients before the holiday rush starts:
- Mandate "Voice Verification" for Financial Changes: If a vendor emails you saying their wiring instructions have changed, or an employee asks to change their direct deposit, you MUST call them on a trusted, pre-existing phone number to verify. Do not use the phone number in the email. This one rule would have prevented millions of dollars in losses in 2022.
- Enable Multi-Factor Authentication (MFA) Everywhere: If you aren't using an app like Microsoft Authenticator or Duo, you are leaving your front door unlocked. A password alone is not enough in 2026, and it certainly wasn't enough in 2022. Ensure MFA is on your email, your accounting software (QuickBooks/Xero), and your remote access tools.
- Conduct a "Holiday Huddle": Take 15 minutes in your next staff meeting to show examples of holiday scams. Mention the gift card scam and the package delivery texts specifically. When people know what to look for, they are 70% less likely to click.
- Review Your Cyber Insurance Policy: Does your policy cover "Social Engineering" or "Funds Transfer Fraud"? Many basic policies don't. In 2022, many firms found out too late that their insurance wouldn't pay out for a gift card scam because the employee "voluntarily" gave away the codes.
- Standardize Shipping Procedures: Use a single corporate account for all shipping and tell your employees that the firm will never text them about a package. If they get a text, it’s a scam. Period.
- Implement DNS Filtering: Tools like Cisco Umbrella or Cloudflare Gateway can block employees from reaching known scam and phishing websites even if they do click the link. This is a low-cost "safety net" that works 24/7.
Frequently Asked Questions
What is the most common scam for small businesses?
Business Email Compromise (BEC) remains the king of scams. This is where a scammer gains access to a business email account or spoofs one to trick employees, customers, or vendors into transferring funds. According to the FBI’s Internet Crime Complaint Center (IC3), BEC caused over $2.7 billion in adjusted losses in 2022 alone. In a professional service setting, this often looks like a spoofed invoice sent to a client that appears to come from your firm.
How can I tell if a charity is real?
Always use a third-party validator. Before you or your firm donates, check the organization on Charity Navigator or the BBB Wise Giving Alliance. If they pressure you to give immediately or ask for payment via non-standard methods (like gift cards or wire transfers), it is 100% a scam. Legitimate charities are happy to take a check or a standard credit card payment through their verified website.
Our firm is only 10 people. Why would a scammer target us?
Scammers target small firms because they are "soft targets." A 1,000-employee company has a dedicated IT security team and sophisticated monitoring. A 10-person firm usually has one person who "knows a lot about computers" handling things on the side. Scammers use automated tools to scan thousands of small businesses at once. To them, your $50,000 wire transfer is just as spendable as a million-dollar transfer from a big corporation, and much easier to get.
What should I do if an employee clicks a suspicious link?
First, don't panic or punish the employee. If you punish them, the next person who clicks will hide it, and that’s when the real damage happens. Immediately disconnect the device from the Wi-Fi/network, change the employee’s email password from a different, clean device, and contact your IT provider. The faster you act, the lower the cost of recovery. In 2022, the average "dwell time" (how long a hacker stays in your system before being caught) was about 16 days. You want to shrink that to minutes.
Are QR code scams a real threat?
Yes, "Quishing" (QR Phishing) emerged as a significant threat in late 2022. Scammers place stickers with malicious QR codes over legitimate ones at parking meters, restaurants, or on "missing pet" posters. When you scan it, it takes you to a site that captures your payment info or installs a malicious profile on your phone. Tell your staff to be wary of any QR code that looks like a sticker applied over an original sign.
Conclusion
The 2022 holiday season taught us that cybersecurity isn't just a technical problem—it's a human one. As the founder of Sentree Systems, I’ve watched the landscape evolve from simple viruses to sophisticated psychological operations. But here is the good news: You don't need to be a tech genius to stay safe. You just need to be a little more skeptical and a little more disciplined.
Think of security not as a "cost" but as an investment in your firm's continuity. The ROI of preventing a $50,000 wire fraud or a $100,000 ransomware attack is infinite. By implementing simple checks—like voice verification and MFA—you are protecting your employees' livelihoods and your clients' trust. Don't let the holiday rush blind you to the risks. Stay alert, stay skeptical, and let's make sure the only thing you're giving away this holiday season is gifts to your loved ones, not your hard-earned revenue to a scammer. If you’ve been putting off these security basics, there is no better time than right now to fix them. After 26 years in the trenches, I can tell you that the best defense is a proactive one.
Watch: $450,000 Vanished: The 3 PM Email That Ended a Title Firm
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment