OV Cyber Weekly

Staff Edition · Week of Sep 28, 2026 · No. 3 · from Chris Blair Internal · Olympus Ventures

Start here

Finance, investments, and real estate all move money, and family offices like OV are a deliberate target. Wire fraud is still one of the most common ways firms like ours lose money, so keep using our payment-verification steps every time. Here are a few real cases from the last few months worth knowing.

414
Phishing emails aimed at OV this week
-76
Fewer than the week before (490 the prior week)
Payment lures
What's pushing hardest right now: fake ACH and transfer-approval notices, plus "review and sign" and voicemail emails spoofing an OV address

For the finance team

"Update my direct deposit" or a vendor's "new bank account." Confirm any direct-deposit or vendor bank change by phone, on a number from your own records. Not the email, and not the invoice.
Rushed "boss" payments, gift cards, quarantine-release traps. Confirm odd payment requests with the person directly. Never buy gift cards off an email. If a held message looks like one you wanted, send it to me before you release it.

For the investments team

Fake capital calls and look-alike portals. Real-looking notice, tight deadline, a "new" account, and sometimes a web address one letter off. Verify every capital call and any wire-instruction change with the GP or fund admin on a number from your own records, before anything moves.
Deal and data-room "opportunity" emails. The link leads to a fake login page. Don't sign in from the email. Go to the portal directly, and be extra careful with unsolicited offers.

For the real estate team

Wire fraud around closings and loan payoffs. Fake "updated wiring instructions" that look like the title company, lender, or escrow officer. The money is gone in hours. Follow our verification steps every time, confirm on a known number, and be most careful right before a closing.
Fake "review and sign this document" emails. DocuSign, Adobe, or SharePoint lookalikes, some sent through the real service and some showing an olympusventures.com sender. Go to the site directly instead of clicking, and check the sender and the deal are real before you type a password.

Spot it and flag it

If you see this…It might be…Do this
A rushed, secretive request from a "boss" or partnerImpersonation / BECConfirm directly (call or ask in person)
A capital call or fund wire to a "new" accountInvestment fraudVerify the GP (a number you already have)
A login-approval push you didn't startStolen passwordDeny it and tell Chris
"Update my direct deposit" / "our bank account changed"Payroll or vendor fraudVerify the person (on a known number)
"Buy gift cards and send me the codes"Always a scamNever do it and flag it
"A document is ready to review / sign"Fake-login phishingDon't use the link (go to the site directly)
A QR code leading to a sign-in pageQuishingDon't scan (type the address yourself)
"Your wiring / payment details have changed"Wire fraudFollow the wiring steps (verify, don't shortcut)
Anything that just feels "off"Trust that instinctAsk Chris (no question is too small)

To flag something: in Outlook use the Report button and choose Report phishing, or just forward it to me. You won't be blamed for flagging something harmless. And if you think you already clicked a link or typed a password, tell me right away. The sooner I know, the more I can do.