OV Cyber Weekly

Staff Edition · Week of Sep 21, 2026 · No. 1 · from Chris Blair Internal · Olympus Ventures

Start here

Real cases worth knowing, and why they matter for us

Some good news: our filters blocked about 215 phishing emails aimed at OV this week, and no accounts were compromised. But around 97 still slipped into inboxes. Those are the ones where you're the last check. If something looks off, you're probably right. Send it my way and I'll take a look.

For the finance team

"Update my direct deposit" or a vendor's "new bank account." Confirm any direct-deposit or vendor bank change by phone, on a number from your own records. Not the email, and not the invoice.
Rushed "boss" payments, gift cards, quarantine releases. Confirm odd payment requests with the person directly. Never buy gift cards off an email. If a held message is one you wanted, send it to me before releasing it.

For the investments team

Fake capital calls. Real-looking notice, tight deadline, a "new" account. Verify every capital call and any wire-instruction change with the GP or fund admin on a number from your own records, before anything moves.
Deal and data-room "opportunity" emails. Links can lead to a fake login page. Don't sign in from the email. Go to the portal directly, and be extra suspicious of unsolicited offers.

For the real estate team

Wire fraud around closings. Fake "updated wiring instructions" that look like the title company or lender. Follow our verification steps every time, confirm on a known number, and be most careful right before a closing.
Fake "review and sign this document" emails. DocuSign, Adobe, or SharePoint lookalikes with a button to a fake login page. Go to the service directly instead of clicking, and check the sender is real.

Spot it and flag it

If you see this…It might be…Do this
A rushed, secretive request from a "boss" or partnerImpersonation / BECConfirm directly (call or ask in person)
A capital call or fund wire to a "new" accountInvestment fraudVerify the GP (a number you already have)
A login-approval push you didn't startStolen passwordDeny it and tell Chris
"Update my direct deposit" / "our bank account changed"Payroll or vendor fraudVerify the person (on a known number)
"Buy gift cards and send me the codes"Always a scamNever do it and flag it
"A document is ready to review / sign"Fake-login phishingDon't use the link (go to the site directly)
A QR code leading to a sign-in pageQuishingDon't scan (type the address yourself)
"Your wiring / payment details have changed"Wire fraudFollow the wiring steps (verify, don't shortcut)
Anything that just feels "off"Trust that instinctAsk Chris (no question is too small)

To flag something: in Outlook use the Report button and choose Report phishing, or just forward it to me. You won't be blamed for flagging something harmless. And if you think you already clicked a link or typed a password, tell me right away. The sooner I know, the more I can do.