Back to Blog
CybersecurityAug 25, 2026

The Fake RFQ Email That Almost Got Us: AI Phishing Defense for Northeast Ohio SMBs

LNS Engineer

By LNS Engineer

The Fake RFQ Email That Almost Got Us: AI Phishing Defense for Northeast Ohio SMBs

Last week, an email landed in our own inbox that looked like a standard request for quotation. The sender name matched a real manufacturing firm in the Cleveland area. The logo was right. The signature block included a direct phone number and a physical address. The message asked whether we could quote on a large networking hardware order for a new facility.

It was a fake RFQ email.

The giveaway was small. A reply-to address that differed from the sender domain by one character. A PDF attachment named "RFQ_Details.pdf" that had no legitimate reason to arrive unsolicited. A mild pressure tactic: "We need this quote by end of day to move forward with procurement."

We did not open the attachment. But the email got far enough that it could have fooled a busy office manager, a purchasing agent, or a sales lead working through a full inbox. That is exactly the point.

We are sharing this because it reflects what we see across Northeast Ohio every week. Phishing is no longer the misspelled, grammatically broken email from a decade ago. AI has changed it. And the fake RFQ has become one of the most effective business-to-business scams targeting small and mid-sized companies.

The fake RFQ email is engineered for business

A quote request is a normal part of doing business in manufacturing, distribution, professional services, and construction. That normality is the weapon. Attackers use publicly available information, company websites, LinkedIn profiles, and industry directories to build a message that looks like it belongs in your workflow.

The mechanics of the RFQ email scam usually follow a pattern:

  • A legitimate-sounding company name, often a real business the attacker is impersonating
  • A plausible project or purchase, sized to feel urgent but not absurd
  • An attachment or link, labeled as specs, drawings, or terms, that delivers malware or opens a credential harvesting page
  • A deadline that pushes the recipient to act before verifying

In some cases the goal is malware delivery, often a loader for ransomware. In others it is invoice fraud, where the conversation shifts to changing payment details after trust is built. The common thread is that the initial email looks like an opportunity, not a threat.

AI changed the economics of phishing

For years, phishing had a tell: bad grammar, awkward phrasing, generic greetings. That is no longer a reliable defense. Generative AI lets attackers write clean, localized, personalized emails at scale and in near-perfect English, Spanish, or any other language they choose.

This matters for small businesses for a simple reason: phishing is already the most common way attackers get in. The Verizon 2024 Data Breach Investigations Report found that 68% of breaches involved a human element, meaning social engineering, errors, or misuse. Phishing remains a top action in those incidents.

The FBI's Internet Crime Complaint Center reported roughly $2.9 billion in losses tied to Business Email Compromise in 2023. That figure eclipses reported ransomware losses and shows how profitable email-based deception has become.

Proofpoint's 2024 State of the Phish research found that 71% of organizations experienced at least one successful phishing attack during 2023. The successful ones are not always loud. They are the quiet credential thefts, the changed routing numbers, the invoice that went to the wrong account.

AI raises the ceiling. Attackers can now generate dozens of variations of a fake RFQ in minutes, tailor each one to a specific company, and reference real contacts pulled from public data. The cost of a convincing email has collapsed, which means small businesses are no longer protected by obscurity. In fact, SMBs are attractive targets because they often have fewer dedicated security staff and rely on a patchwork of tools.

A layered email security approach for Northeast Ohio SMBs

No single tool stops every phish. We design email security as a layered system where each control covers the gaps of the one before it.

1. Filtering that catches threats at the gateway

The first layer is the filter. Modern email security for small business should include:

  • Domain-based authentication such as SPF, DKIM, and DMARC to reduce spoofing of your own domain and flag impersonation attempts
  • Attachment sandboxing that detonates suspicious files in an isolated environment before they ever reach an inbox
  • URL protection that rewrites and checks links at click time, because a link that was clean in the morning can be malicious by afternoon
  • Impersonation and anomaly detection that flags display-name spoofing, lookalike domains, and unusual sending patterns

The fake RFQ we received was caught by this combination. The attachment was quarantined before anyone could interact with it. But filtering alone is not enough, because the attack only needs one email to slip through.

2. Security awareness training for employees

The second layer is people. Security awareness training for employees works best when it is continuous, specific, and tied to real-world threats rather than a once-a-year video.

Effective programs include:

  • Simulated phishing campaigns that mirror actual scams, including fake RFQ emails, so employees learn to spot pressure tactics and lookalike domains
  • Short, frequent micro-lessons that fit into a workday without disrupting production
  • Clear reporting paths, so a suspicious email can be flagged in seconds and reviewed by IT
  • Reinforcement for the behavior you want, reporting a phish, not punishment for clicking

A workforce that reports suspicious messages is an early warning system. When one employee flags a fake quote request, our team can pull the email from other mailboxes before it becomes a breach. That speed matters.

3. Verified backups as the ransomware last line of defense

Some phishing emails are designed to steal credentials. Others are designed to start a ransomware attack. When ransomware lands, the question shifts from "can we stop this?" to "how fast can we recover?"

This is where verified backups become essential ransomware protection for small business. A backup is only useful if it actually restores. We follow a few non-negotiables:

  • The 3-2-1 principle: three copies of data, on two different media types, with one copy offsite or offline
  • Daily verification, because an untested backup is a hope, not a plan
  • Immutable or air-gapped copies that attackers cannot encrypt or delete even if they compromise the network
  • Tested recovery playbooks, so the team knows the restore order, the dependencies, and the expected time to recover before an incident happens

The Cybersecurity and Infrastructure Security Agency, known as CISA, consistently ranks offline, tested backups among the most important defenses against ransomware. We agree, with one addition: the backup has to be verified, not assumed.

What we see in Cleveland, Akron, Canton, and Youngstown

The fake RFQ we received was not an exotic attack. It was aimed at the everyday workflows of Northeast Ohio businesses. Manufacturing firms get requests for quotes on components and materials. Professional services firms get requests for proposals and invoice-related documents. Healthcare offices get patient-adjacent correspondence. Higher education and financial services get vendor and partner emails.

The industries vary. The pattern does not. A message that looks like business, arrives with an attachment, and carries a deadline.

We have spent more than a decade serving Northeast Ohio, and we built our six service pillars specifically to remove the gaps that fragmented vendors leave behind. Email security does not exist in a vacuum. It connects to network infrastructure, cybersecurity monitoring, and backup and disaster recovery. When one vendor owns the whole stack under one SLA, there is no finger-pointing about which tool failed.

A prevention-first posture

The best phishing response is the one you never have to execute. That means filtering that blocks the message, training that catches the one that slips through, and backups that make the worst-case scenario survivable.

We would rather catch a fake RFQ before it reaches your purchasing manager than help you clean up after a credential theft or a ransomware event. Both are possible. Only one protects your revenue, your reputation, and your operations.

If you want to know how phishing protection for business fits into a complete IT infrastructure, we are happy to walk you through it. Reach us at hello@localnetworksolutions.com or call (216) 658-6988 to schedule your consultation. We will review your current email defenses, run through what a layered approach looks like for your team, and help you close the gaps before an attacker finds them.

Related LNS Services

Managed security services in Cleveland & Northeast Ohio

24/7 threat detection, ransomware protection, and incident response for your business.

Have IT Questions?

Our team is here to help. Schedule a free consultation and get answers from Northeast Ohio's IT experts.

Schedule Your Consultation

Free consultation. No obligation. No hard sell.