So, moving on, their second step is to send a spoofed e-mail (one that looks like it comes from a trusted friend or client) to one of your key employees or partners and the e-mail includes an infected attachment.
FORBES: Conversations On Cybersecurity Part 3: Why You Aren't Protected