top of page

How a Fake "New Client" Used BBB, Windows, and Zoom Scam to Access My Computer

A real scam. A costly mistake. The lessons every entrepreneur needs to know.

Laptop displaying a fake Zoom security file download used in a remote-access scam targeting small-business owners.

As an entrepreneur, getting a message from a potential client usually feels like a win. It means someone found your business, checked out your services, and might want to work with you. But sometimes, that excitement can blind us to hidden dangers. I recently faced a scam where someone pretending to be a bookkeeping client used the meeting setup to gain remote access to my computer. This experience taught me how scammers can cleverly build trust before showing their true intentions.


The First Client Contact That Seemed Legitimate


It started like any other potential client inquiry. There were a lot of green flags before the red flags showed up. Unfortunately, the green flags were waving so enthusiastically that I convinced myself the red flags were probably just decorative.


As a small-business owner, I receive inquiries from people I have never met all the time. That is part of doing business. A stranger finds your company online, reaches out, schedules a consultation and hopefully becomes a paying client. This interaction started exactly that way. It  ended with a stranger inside my computer, restarting it in real time while my IT professional tried to remove him.


So, let me tell you how a promising bookkeeping inquiry turned into a cybersecurity nightmare—and how easily the desire to gain a new client can cause even a cautious business owner to overlook things that do not add up.


Scammers don't always manipulate fear.


Sometimes they manipulate opportunity.


Inside the Story

Here's What happened, step by step


Around 7:00 p.m., I received a text on my business phone from a Florida number with the 941 area code. Since my business is based in Florida, and I often get inquiries from local clients, this didn’t raise any alarms. The message said:


Hi there, I came across your BBB profile and I’m looking for personal bookkeeping services. Can you let me know what you offer and your availability?

Sounds legitimate, right?


This sounded like a typical client inquiry. He referenced my Better Business Bureau profile. I often go to BBB to find legitimate, trustworthy services for myself - so why wouldn't anyone else? He asked about a service I actually provide. He contacted my business number. He used a Florida phone number.


Green flag. Green flag. Green flag.


When I replied, the message appeared blue, which told me he was using iMessage. That is not identity verification, of course, but in the moment it felt like one more normal, familiar detail.


He confirmed that 10:30 a.m. the next day worked for him and said he would send me a Zoom link so we could discuss his needs “at length.”


Professional wording. Scheduled appointment. Clear purpose.


More green flags.


I gave him my email address and introduced myself. He told me his name was "Frank Layton-Field".


The email address he used was Gmail rather than a business-domain email.

That is not automatically suspicious.

Plenty of legitimate small-business owners use Gmail. In fact, I usually see that as a service opportunity.

“Oh, you are still using Gmail for your business? I can help you fix that.” Apparently, I was already mentally upselling a scammer. Still, a personal email address is something to notice, especially when other inconsistencies begin piling up.


The texts remained polite and professional. He said things like:

“Nice speaking with you—see you then :)”

Friendly. Pleasant. Just enough personality to make the conversation feel human.

Trust successfully installed.



Then Came the “Zoom Security Encryption”

Shortly after (maybe 1 hour) after the meeting was confirmed, “Frank” our fake new client texted again.

He said:

“I’m just remembering that my Zoom security encryption will not let you join unless you download and install the Zoom additional file.”

This sentence should have stopped the entire show. The zoom invite he sent came with the link... and I downloaded the file.

HUGE mistake.

The link did not open Zoom. It directed me through Microsoft Phone Link.

Phone Link is a real Microsoft feature, which is part of what made the situation so dangerous. This was not an obvious pop-up with flashing red letters saying:

"HELLO, I AM HERE TO STEAL YOUR INFORMATION."


It looked like legitimate Windows technology because it was legitimate Windows technology—being used for a completely illegitimate purpose.


I followed the instructions because I was focused on the possibility of landing a new client. That is the part entrepreneurs need to understand.


Scammers do not always manipulate fear. Sometimes they manipulate opportunity.



Zoom Was Not Zooming

After completing the steps, Zoom still did not open.


At that point, I texted him and said I would simply create and send my own Zoom link.

Suddenly, Mr. Professional became unavailable. He did not respond.


When it was time for our scheduled meeting, I called him. He did not answer. Instead, he texted that he was “on a call” and asked me to give him “one sec.”

Excuse me?

Why are you on another call during the time we scheduled for our call?

That was strange. It was also annoying.

But I pushed it aside because my brain was still whispering:

New client. New client. New client.


Half the day passed, and I still did not hear from him.

I texted again and called again.

This time, he answered.


I asked whether he wanted to reschedule or simply discuss his bookkeeping needs by phone. We did not need Zoom. I just needed to ask a few questions and learn more about what him and his businesses.


His spoken communication was noticeably different from the polished, professional text messages he had sent.

His English was choppy. He said the service was bad where he was and that he would call me later.


At that point, the details stopped feeling random. The Gmail address. The strange Zoom file. The refusal to use my meeting link. The missed appointment. The excuse about being on another call. The disconnect between his written and spoken communication.

The red flags were no longer waving.

They were doing choreography.



He Was Inside My Computer in Real Time

I immediately contacted my IT Team and explained what had happened.


Sure enough, “Frank” had gained access to my computer. And here is what made this especially disturbing: He had not used some obvious piece of malware that my laptop would necessarily recognize and block. He had used legitimate Windows technology to gain remote access.


He was also attempting to gain access to my phone (as Windows requests you to scan the QR code to sync)

I had not downloaded a cartoon virus. I had unknowingly handed him the keys, opened the door and probably asked whether he wanted coffee.


My IT professional connected remotely to remove him and secure the computer.

While he was working, “Frank” repeatedly restarted my laptop. Let me say that again -

The scammer was inside my computer, in real time, restarting it while my IT professional was trying to remove him. That was the moment the situation became very real. I was furious. I was embarrassed. I felt violated. And I was angry with myself because I am usually good at recognizing scams. But that is exactly why I am sharing this. These scams do not only work on people who are careless. They work on people who are busy, optimistic, accommodating and eager to grow their businesses.



Thankfully, My IT Solutions Team Was Faster Than “Frank”

Fortunately, I have an excellent IT team!


They were able to remove the unauthorized access, secure the device and get me operational again in under an hour.


Afterward, I took additional precautions:

  • I changed all important passwords.

  • I changed my Amazon password too, because at that point everybody was getting a new password.

  • I forced my accounts to sign out on other devices.

  • I reviewed active sessions and connected devices.

  • I secured accounts that may have been open.

  • I confirmed that sensitive accounts were not set to automatic login.


I have never liked allowing bank accounts, email accounts and other sensitive platforms to log in automatically. For once, my distrust of convenience may have helped me.

Anything that was already open could potentially have been viewed, but important financial and email accounts still required separate logins (with two-factor authentication).


Why Small-Business Owners Are Perfect Targets

Entrepreneurs are especially vulnerable to this kind of scam because we deal with strangers all day.

We answer unknown numbers.

We reply to inquiries.

We schedule consultations.

We send contracts.

We accept meeting invitations.

We try to be helpful.

And when someone says they found us through the BBB, Google, Instagram, a referral or our website, we naturally think:


"Great. The marketing is working"!


Scammers know this.

They know we do not want to lose a potential client by appearing difficult.

They know we want to respond quickly.

They know we may ignore something unusual because we are trying to provide good customer service.

They know that one business laptop may contain access to email, websites, payment platforms, contracts, bookkeeping records, client files and cloud storage.

They are not only targeting technology.

They are targeting ambition.



The Green Flags That Lowered My Guard


This scam worked because it contained several believable details:

  • He contacted my business phone.

  • He used a Florida area code.

  • He referenced my BBB profile.

  • He requested a service I actually provide.

  • He scheduled a consultation during normal business hours.

  • He gave me a name.

  • He communicated professionally.

  • He sent a meeting invitation.

  • He was friendly without being overly aggressive.

  • His texts appeared through iMessage.

None of these things verified his identity.

They simply made the interaction feel familiar.

That is an important distinction.

A scammer does not need to prove that they are legitimate.

They only need to create enough comfort that you stop verifying.


The Red Flags I Should Have Taken More Seriously

The biggest red flag was the claim that his Zoom security required me to download an additional file. That alone should have ended the conversation.

Other warning signs included:

  • He used a personal Gmail account instead of a business-domain email.

  • The meeting process did not open Zoom.

  • He directed me through Microsoft Phone Link.

  • He insisted that his security settings required action on my device.

  • He became difficult to reach after the download.

  • He refused to use a Zoom link that I offered to create.

  • He was allegedly on another call during our scheduled appointment.

  • His behavior changed once I questioned the process.

  • His spoken communication did not match the professional persona created through text.


Again - a Gmail account alone is not proof of fraud.

A missed call alone is not proof of fraud.

A scheduling issue alone is not proof of fraud.

But when several small inconsistencies appear together, stop treating them like isolated quirks.

Patterns matter.


New Rule: I Host the Meeting!

Going forward, my virtual-meeting policy is simple:

  • I create the meeting.

  • I send the link.

  • I do not download software sent by a prospective client.

  • I do not install security files, encryption add-ons, compatibility tools, browser extensions or mystery “Zoom updates.”

  • I do not connect my phone to my computer because a stranger says Zoom requires it.

  • And I definitely do not give remote access to someone I met through a text message the night before.


A legitimate prospective client should be able to do one of the following:

  • Join the meeting link I send

  • Speak by telephone

  • Use Google Meet, Teams or Zoom through an official platform

  • Reschedule while I independently verify the request


If none of those options work for them, then we probably do not need to work together.

What to Do if This Happens to You

If you believe someone has gained remote access to your device:


Disconnect the computer from the internet immediately.

Contact a trusted IT or cybersecurity professional. Honestly, we have the BEST team. So - contact Anhinga IT-Solutions team and/or who you trust!


From another secure device:

  • Change important passwords.

  • Enable multifactor authentication.

  • Sign out of active sessions.

  • Review connected devices.

  • Check recovery email addresses and phone numbers.

  • Review email forwarding rules.

  • Review recent account activity.

  • Contact financial institutions if necessary.


Do not assume that deleting the software solves the problem.

Do not assume antivirus software will catch everything.

Some scammers use legitimate tools that may not look like malware at all.



The Real Lesson

I am normally cautious. That is what made this experience so upsetting. But this scam did not begin with a ridiculous story about winning the lottery or owing the IRS money.

It began with a believable client inquiry. The person knew how to sound professional.

He knew how to build trust. He knew how to use familiar technology.

And most importantly, he knew exactly what every entrepreneur wants:

A new client.

That desire made me overlook things I would normally question.


So here is my warning to every small-business owner:

Do not let the excitement of a new opportunity override your instincts.

Do not download software because someone uses the words “security” or “encryption.”

Do not assume a professional tone means a professional person.

Do not assume a familiar area code, iPhone or BBB reference proves anything.


And do not worry about appearing difficult when your cybersecurity is involved.

A real client may be mildly inconvenienced by your security procedures - A scammer will be stopped by them.


That is a trade I am now very happy to make.


Protect Your Business - Share This Post

In today's fast-paced business environment, safeguarding your enterprise is crucial. Here are some key strategies to consider:

  • Implement Strong Cybersecurity Measures: Protect sensitive data with robust security protocols.

  • Invest in Insurance: Ensure you have the right insurance coverage to mitigate risks.

  • Develop a Business Continuity Plan: Prepare for unexpected events to minimize disruption.

  • Educate Your Employees: Train staff on best practices for security and risk management.

  • Regularly Review Policies: Keep your business policies up to date to adapt to changing circumstances.


Sharing this post can help raise awareness about the importance of protecting your business. Let's work together to create a safer business environment!


Subscribe to our newsletter

 
 
 

Comments


bottom of page