Phishing in Morocco: the 8 email scams targeting SMBs in 2026
Fake supplier bank details, fake DHL, fake Microsoft, CEO fraud: the 8 phishing scenarios we see every week at our clients, and the habits that stop them.

Nine out of ten security incidents we handle start with an email. Not with a sophisticated technical exploit: with a credible message, received on a Tuesday at 11 am, that pushes someone to click or to pay. Here are the eight scenarios we see most often at Moroccan SMBs, and what stops them.
1. The supplier bank-details change
An email, sometimes from a supplier’s genuinely compromised mailbox, announces a new bank account for future payments. The transfer goes to the fraudsters. Habit: every change of bank details is confirmed by phone, on the number already on file, never the one in the email.
2. CEO fraud
“I’m in a confidential meeting, make an urgent transfer, I’ll explain later.” The message imitates the boss, often with the exact display name. Habit: no transfer is ever triggered by an email alone, whatever the urgency, and the boss applies the rule too.
3. The fake Microsoft 365
“Your password expires today”, “You have 12 messages in quarantine”. The link leads to a perfect copy of the Microsoft sign-in page that harvests username and password, sometimes the MFA code in real time. Habit: never sign in from a received link, always from the app or a bookmark. And deploy phishing-resistant MFA, as we explain in our MFA guide.
4. The parcel on hold
Fake DHL, Amana or Aramex: “customs fees to pay to release your parcel”. The page asks for a card number. Habit: carriers never ask for payment through an SMS or email link.
5. The invoice attachment
A PDF or Office file “Invoice No…” that asks to enable macros or leads to a download. It is the classic ransomware vector, whose defences we detail in ransomware: 7 measures for an SMB. Habit: macros disabled by policy, EDR on every endpoint.
6. The fake HR or payroll department
“Update your bank details for your salary transfer”. The link points to a form that captures personal data. Habit: HR never sends external forms, and IT verifies the sender.
7. The tender or purchase order too good to be true
A supposed large account sends a purchase order, requests a quote, then a booby-trapped “specifications” file. Habit: verify the contact exists on the company’s official website, never through the details in the email.
8. The fake IT support
A call or email “from your provider” asks for a remote connection or a password. Habit: your managed services provider already has its own access and will never ask for your password. When in doubt, hang up and call the number on the contract.
What really protects
- Technology: email filtering with link and attachment analysis, SPF, DKIM and DMARC in reject mode on your domain so nobody can spoof your address, MFA everywhere, EDR on endpoints.
- Procedures: dual approval for transfers, phone confirmation of bank-detail changes, a written rule everyone knows.
- Training: one phishing simulation per quarter, with a kind reminder for those who click. Click rates fall from 30% to under 5% within a year.
We include all three in our business cybersecurity offer, and compliance with Law 09-08, which requires protecting personal data, is covered in our dedicated article.
Frequently asked questions
How do you spot a fake bank-details change email?
The message announces a new bank account, sometimes from the supplier’s genuinely compromised mailbox. Every change of bank details is confirmed by phone, on the number already on file, never the one in the email.
How do you protect against CEO fraud?
With a written rule everyone knows: no transfer ever leaves on an email alone, whatever the urgency, the boss included. Dual approval of transfers completes the setup.
What are SPF, DKIM and DMARC for?
Set to reject mode on your domain, they stop a fraudster from sending email that spoofs your address. They complement link and attachment filtering.
Does anti-phishing training actually work?
Yes: with one phishing simulation per quarter and a kind reminder for those who click, click rates fall from 30% to under 5% within a year.
About the editorial team
ALLSAFE SOLUTIONS
Network, security and cloud engineers
Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.
LinkedIn







































