Muffy — you said the phishing started right after you signed up with RICS. I looked into it. Here's the straight answer, what's actually risky, and the short list of what to do. Five minutes.
What happened is normal, it happens to almost every new business, and there are about five things worth doing about it.
The timing feels like RICS caused it. It didn't. I checked for any reported RICS security incident or breach and found nothing — no news, no security advisories, nothing in the breach databases.
What really happened is that you became publicly findable at the same time you signed up. Here's the chain:
Companies buy and sell those lists legally. Scammers buy them too. A brand-new business email address is a fresh target, and they hit it hard for the first few months. It settles down.
RICS runs the point-of-sale for more than 75% of running stores in the country. That makes "RICS" a really attractive name for a scammer to fake — one email template works on almost every running store in America.
So expect to see emails that look like they're from RICS. "Your RICS account is locked." "Action required on your RICS invoice." "Confirm your RICS login."
Getting those does not mean your account has a problem. It means somebody knows you're a running store. If you ever think a RICS message might be real, don't click the link — open RICS the way you normally do, or call them at the number on your contract.
Junk in your inbox is annoying. It isn't what takes people down. This is:
It looks like it came from your Saucony rep, or Brooks, or Kiprun. It might even land inside a real email thread you've already got going. The good ones now copy the exact logo, signature, and writing style.
The FBI's most recent report put this category at $3 billion in losses in one year, averaging about $123,000 per business. It beats every other kind of scam for small businesses, ransomware included.
In order. The first two matter more than the rest combined.
Your email first — that's the master key. If someone gets into your email, they can reset everything else. Then your business bank, then RICS, and later Shopify and the newsletter tool when we set those up.
It's the code-to-your-phone thing. It's twenty minutes of setup and it stops the overwhelming majority of this.
You — I'll walk you through itCovered above, but it's number two on the list for a reason. Make it a store rule, not just your own habit — anyone who might ever pay a bill needs to know it.
You + anyone handling paymentsRight now someone can send email that looks like it comes from your address — to your customers, or to your vendors. There's a setup on the domain that blocks that.
Bonus: it's the same setup that keeps your newsletter out of everyone's spam folder. So this protects you and makes the November newsletter actually land.
Me — nothing for you to doTry not to do banking on the same machine everybody uses for browsing, email, and the register all day. If it's one computer, at minimum use a separate browser just for banking, and don't run day-to-day on an administrator account.
Also: if it came with a pile of preinstalled software you've never used, let me clear it off.
Me — I'll set it upOn real newsletters, sure. On obvious scam mail, clicking "unsubscribe" just confirms a live human reads that inbox and you get more. Mark as spam and delete. It thins out over a few months.
You| 💸 | It's about money or login details. Invoices, payments, bank changes, "confirm your password." That's the whole game. |
| ⏱️ | It's urgent. "Today." "Account will be suspended." Rushing you is the tactic — real vendors give you time. |
| 🔤 | The address is almost right. Look character by character at what's after the @. ricssoftware.co instead of .com. An extra letter. A swapped one. |
| 🆕 | Somebody new introduces themselves. "I'm your new account manager." Verify with your existing contact before you do anything with them. |
| 📱 | A QR code you're told to scan. That's a newer one, and it's specifically designed to move you onto your phone where the warning signs are harder to see. |
When something feels off, forward it to me before you click anything. No such thing as bothering me with too many of these — I'd much rather look at fifty harmless ones than miss the real one.
Once the website is taking orders and you're building the email list, you'll be holding customer information — names, addresses, order history.
Illinois has a law about that. If that information ever got exposed, you'd be legally required to notify every customer affected. That's not something to worry about today; it's the reason we do the two-step login on the newsletter tool and the online store from day one instead of adding it later.
I'll handle the setup side. You just need the two-step codes on your phone.