compo.nents
Security Note · Prepared by Paragon Cyber

Why you're getting
all those emails.

Muffy — you said the phishing started right after you signed up with RICS. I looked into it. Here's the straight answer, what's actually risky, and the short list of what to do. Five minutes.

Short version: RICS didn't leak you. And you're not being singled out.

What happened is normal, it happens to almost every new business, and there are about five things worth doing about it.

1

What actually happened

The timing feels like RICS caused it. It didn't. I checked for any reported RICS security incident or breach and found nothing — no news, no security advisories, nothing in the breach databases.

What really happened is that you became publicly findable at the same time you signed up. Here's the chain:

  • You registered muffysloungecomponents.com. Domain registrations are public, and they get scraped automatically within days.
  • You registered the business in Illinois. That's a public record too.
  • Your Google listing went live with a real address, phone, and email attached to it.
  • You opened accounts with the brands, so you started showing up on dealer and vendor lists.

Companies buy and sell those lists legally. Scammers buy them too. A brand-new business email address is a fresh target, and they hit it hard for the first few months. It settles down.

So no — don't leave RICS over this. Switching your point-of-sale would cost you real money and time and would not stop a single one of these emails.

2

The one thing that IS specific to you

RICS runs the point-of-sale for more than 75% of running stores in the country. That makes "RICS" a really attractive name for a scammer to fake — one email template works on almost every running store in America.

So expect to see emails that look like they're from RICS. "Your RICS account is locked." "Action required on your RICS invoice." "Confirm your RICS login."

Getting those does not mean your account has a problem. It means somebody knows you're a running store. If you ever think a RICS message might be real, don't click the link — open RICS the way you normally do, or call them at the number on your contract.


3

The one that actually costs money

Junk in your inbox is annoying. It isn't what takes people down. This is:

The email that gets small stores
"Hi Muffy — heads up, we've switched banks. Please send this month's payment to the new account below. Sorry for the hassle!"

It looks like it came from your Saucony rep, or Brooks, or Kiprun. It might even land inside a real email thread you've already got going. The good ones now copy the exact logo, signature, and writing style.

The FBI's most recent report put this category at $3 billion in losses in one year, averaging about $123,000 per business. It beats every other kind of scam for small businesses, ransomware included.

Your rule, forever: nobody changes bank details by email. If any vendor asks you to send money somewhere new, you call them first — at the number you already have, not one from the email. Every time, even when it looks obviously real. Especially when you're paying for fall inventory.

4

The five things to do

In order. The first two matter more than the rest combined.


5

How to spot one in three seconds

💸It's about money or login details. Invoices, payments, bank changes, "confirm your password." That's the whole game.
⏱️It's urgent. "Today." "Account will be suspended." Rushing you is the tactic — real vendors give you time.
🔤The address is almost right. Look character by character at what's after the @. ricssoftware.co instead of .com. An extra letter. A swapped one.
🆕Somebody new introduces themselves. "I'm your new account manager." Verify with your existing contact before you do anything with them.
📱A QR code you're told to scan. That's a newer one, and it's specifically designed to move you onto your phone where the warning signs are harder to see.

When something feels off, forward it to me before you click anything. No such thing as bothering me with too many of these — I'd much rather look at fifty harmless ones than miss the real one.


6

One thing coming down the road

Once the website is taking orders and you're building the email list, you'll be holding customer information — names, addresses, order history.

Illinois has a law about that. If that information ever got exposed, you'd be legally required to notify every customer affected. That's not something to worry about today; it's the reason we do the two-step login on the newsletter tool and the online store from day one instead of adding it later.

I'll handle the setup side. You just need the two-step codes on your phone.

That's it. You're fine.
You got noticed because you're real now — new domain, real storefront, real brand accounts.
Let's lock the doors and get back to selling shoes.
Michael Bass · Paragon Cyber
Bring any questions Monday.