The catering company's payroll run left the operating account and never reached a single employee.
A regional catering company used a payroll vendor named in a public job listing. An actor who read that listing targeted the vendor portal, harvested the company login, changed direct deposit routing for all twenty three staff, and let one full cycle process. The company account was debited sixty seven thousand four hundred dollars in a single run. None of those funds went to the people who had worked the week.
The job listing was not written as a security document. It named the payroll platform as a tool the new hire would use. That field told anyone reading it which third party system held the money movement. The small business owner had posted the listing to fill a seat. The same listing identified the door.
Recovering diverted payroll from a bank that processed a transfer that looked legitimate is a dispute with no guaranteed return. The small business owner still has to pay staff a second time while that dispute sits. Closing the vendor login, reversing the routing, and documenting the public listing that advertised the vendor are three different tracks. They do not wait for each other. Missing a node leaves the next cycle exposed to the same change.
A small business owner who treats every public document as marketing copy has left a map to the accounts that move wages. Cleaning one vendor login does not remove the listing, and it does not tell the owner how many other public pages still name the same platform.
Look back at what happened in this post. One decision started the chain. The RuleDraft Small Business Isolation Manual walks Small Business Owners through the same sequence we use to stop that chain before it reaches them.