Hi. How can we help?

Following security best practices to protect your business online

Provided information is for general informational purposes only and should not be considered legal advice. You should consult with your own legal counsel for requirements governing your specific circumstances.

Most security breaches happen when a user unintentionally compromises the security of their information or access. Understanding common tactics scammers use can help protect you, your staff, and your customers from fraud.

Understanding security threats

A security threat includes:

  • Scammer: A person or group of people looking to commit fraud. Scammers are typically motivated by profit.
  • Strategy: A strategy, such as phishing or another social engineering tactic, that uses fear and urgency to override rational thinking.
  • Vulnerability: A security weakness, such as a simple password or untrained staff.

The more security layers you have in place, the lower your chances of a security breach:

  • Strong passwords.
  • Answers to security questions.
  • Multi-factor authentication (MFA), where supported.
  • Biometric data, such as a fingerprint.

Lightspeed will never call, text, or email asking for your banking information, PIN, password, or verification codes. Keep this information confidential so that only authorized users can access your accounts. If you suspect that an account may be compromised, follow the relevant account-security guidance: Lightspeed Golf, Lightspeed Retail (R-Series), Lightspeed Restaurant (K-Series), or Lightspeed Restaurant (L-Series).

Recognizing social engineering tactics

Social engineering is the strategy of tricking someone into compromising their own security by divulging sensitive information.

Social engineers use pressure tactics to make you act without thinking:

Authority

Claiming to represent an organization you work with, such as Lightspeed, or someone of importance, such as your IT department or bank.

Urgency

Implying or threatening consequences if you don’t act immediately. Legitimate organizations won’t pressure you to act urgently.

Emotion

Invoking emotions such as fear, hope, or curiosity to override rational thinking.

Relevance

Exploiting current events, changes to policies, or specific times of the year, such as tax season.

Scammers may try to contact you by email, text message, instant message, or phone. Phishing emails are one of the most common social engineering strategies because they are low-cost and easy to automate, especially with artificial intelligence. Scammers typically use impersonation to trick targets into:

  • Revealing sensitive information.
  • Downloading malware.
  • Transferring money.

Lightspeed will never ask you to:

  • Move funds or change your settlement account to an unfamiliar account.
  • Share passwords or MFA codes.
  • Act quickly to limit your time to think or verify the request.
  • Keep a security matter confidential from family members or law enforcement.

If you receive a request like this, it is not from Lightspeed. Learn more about impersonation scams, keeping your Retail account secure, keeping your K-Series account secure, and keeping your L-Series account secure.

Protecting yourself from social engineering attacks

Your strongest defense against social engineering attacks is your ability to slow down and think rationally. Scammers rely on panic-based decisions, so pause and consider the situation before taking any action.

If a communication that appears to be from Lightspeed is pressuring you with urgency or other signs of social engineering:

Don’t panic

  • Ask yourself or your staff whether this communication was expected.
  • Verify the sender, especially if an action is involved.
  • Don’t click links or download attachments.
  • Manually navigate to the official Lightspeed login page or the product’s official login page to investigate the situation in your account.

Don’t share

  • Never share personal information during unsolicited contact.
  • Never share passwords or verification codes.

Don’t engage

  • If contacted by email or text message:
  • If contacted by phone:
    • Hang up immediately. You don’t need to give an explanation or worry about appearing rude.
    • Don’t follow any provided instructions.

If you’re unsure about the legitimacy of a communication involving Lightspeed, contact Golf Support or use the official support channel for the relevant product.

Cybersecurity awareness is important year-round, but be extra vigilant around busy periods such as tax season.

Identifying phishing emails

Common warning signs in phishing emails include:

  1. Slight misspellings, hyphens, or unusual characters in sender addresses, particularly in website domain names. Be especially suspicious of generic email addresses, such as @gmail.com, from unknown senders.
  2. Generic greetings may be a sign of fraudulent messages sent in bulk. However, scammers can also use information from social media and other platforms to create personalized messages.
  3. Pressure tactics and unexpected financial requests or “verifications” rely on distraction and trust. Take time to verify and think through actions that could compromise the security of your account.
  4. Links or QR codes may direct you to a fake version of a real site designed to steal your username and password or install malware. Always verify links in emails, text messages, and external websites.

    On a computer, hover over a link without clicking it to view the URL text in the bottom-left corner of your browser window.

    Browser link preview showing the URL for a link.

  5. Spelling errors in the body text, in combination with other warning signs, could indicate a phishing attempt.
  6. Unexpected attachments may contain malware. Don’t open attachments from unknown senders or files you weren’t expecting.

Critical Billing Issue: Update Your Information Now

Lightspeed Billing Support <support@lightpseedhq.com>

Lightspeed logo.

Critical Billing Issue:
Update Your Information Now

Dear Lightspeed Customer

Your most recent payment was declined, and your subscription is now at risk. Failure to act promptly will result in service interruption without further notice.

To prevent your store from going offline, update your payment method immediately.

Common causes of declined payments:

  • Insufficient funds.
  • Bank or Pay pals issue.
  • Incorrect card details.

If you need assistance, reply to this email.

Lightspeed Support.

One attachment

📄 info.exe Download

You can contact Golf Support to confirm whether a Lightspeed email communication is legitimate. Always navigate to the official website or app to sign in.

Phishing emails may or may not include warning signs, and tactics are becoming more sophisticated every day. Stay vigilant and act cautiously when managing your business online. Learn more about keeping your Lightspeed Golf account secure, Retail account secure, K-Series account secure, and L-Series account secure.

Identifying fraudulent phone calls

Common warning signs of social engineering over the phone include:

  • Fear and urgency-based pressure tactics, which may be presented as helpful or advantageous.
  • Unexpected financial requests or verification of sensitive information. Never share passwords or security codes with anyone.
  • Bypassing procedures or requesting confidentiality.

Scammers can use technology to alter the number they appear to be calling from, so that a legitimate business number shows up on your caller ID. They may even ask you to visit the official source to verify the number. Don’t redial or call back any provided numbers.

Unless you’re expecting a scheduled callback from Lightspeed:

  1. Hang up.
  2. Manually navigate to the official support page for the relevant product and use its published contact options.

Scammer

Hello, am I speaking to [name]?

Business owner

Yes, this is [name]. How may I help you?

Scammer

I’m calling from Lightspeed about a very important matter regarding your subscription. A billing error has led to your account being overcharged by $2,000. I have opened a Support ticket for you, but because of the upcoming bank holiday, I cannot process the refund unless we can confirm your banking information by the end of the day. Could you please confirm your bank branch and business account number?

Business owner

*hangs up and contacts the relevant Lightspeed Support team*

Following security best practices

Cybersecurity is a continuous process, not a one-time event. To help protect your business from scammers, build a multi-layered security strategy.

Be prepared

  • Stay informed and vigilant: Consider which threats and vulnerabilities may affect your business, and follow security best practices to help prevent security incidents. Critically analyze all communication, especially if you’re asked to click a link, share a code, move funds, or change your settlement account to an unfamiliar account.
  • Train your staff: Cybersecurity is everyone’s responsibility. Provide regular training to ensure that everyone with access to Lightspeed Golf, Lightspeed Retail, or Lightspeed Restaurant follows cybersecurity best practices.
  • Plan for realistic business risks: Regularly evaluate risks, such as phishing, callers impersonating Lightspeed, and physical device theft. Identify ways to reduce these risks, create a plan for security breaches, and practise role-specific procedures with your staff.

Secure your setup

  • Follow networking best practices: Secure your network and physical setup to help prevent misuse or theft. Review the relevant guidance for Retail (R-Series), Restaurant (K-Series), or Restaurant (L-Series).
  • Keep device software updated: Ensure that important security patches are installed on your computers, tablets, POS devices, and other equipment.
  • Use strong and unique passwords, implement MFA where supported, and manage and monitor access.

Using unique passwords and implementing MFA for all supported accounts, including email, Lightspeed products, and financial institution accounts, helps ensure that if one account is compromised, other accounts remain secure. Learn more about MFA for Retail (R-Series), Restaurant (K-Series), and Restaurant (L-Series).

Manage your online presence

  • Click with caution: Only click links, scan QR codes, or download files, apps, plugins, and software updates from trusted sources. Untrustworthy sources may contain hidden malware.
  • Review settings: Regularly review your privacy settings on social media and other channels.
  • Manage what’s shared: Be mindful of what you and your employees share online, especially information about your organization and customers. This includes information shared with AI tools.

Protect customer data

As a business owner, you have a responsibility to protect sensitive customer data, such as credit card and cardholder details. Consult your legal counsel about requirements governing your specific circumstances. All businesses should:

  • Maintain PCI compliance: Adhere to industry standards designed to protect cardholder data. Maintaining PCI compliance can reduce the risk of a data breach or fraud involving your customers’ personal information.
  • Obey data privacy laws: Privacy laws, such as the General Data Protection Regulation (GDPR) in the European Union or the California Consumer Privacy Act (CCPA) in California, control how businesses handle customer data. Research and follow all relevant laws in your area. This includes information shared with AI tools.
  • Train your employees: Implement a formal security awareness program so employees understand the importance of data security, consent for data collection, and applicable laws.

Connecting with Lightspeed

To sign in or contact Lightspeed, use the official page for the product you use:

To contact Support, use the official page for the relevant product:

Always navigate to the official website or app to sign in. Do not use links or phone numbers provided in suspicious messages.

What’s next?

Keeping your Lightspeed Golf account secure

Identify fraudulent communications and manage suspected unauthorized access to Lightspeed Golf.

Learn more

Keeping your Lightspeed Retail account secure

Identify fraudulent communications and manage suspected unauthorized access to Retail (R-Series).

Learn more

Keeping your Lightspeed Restaurant account secure

Identify fraudulent communications and manage suspected unauthorized access to Restaurant (K-Series).

Learn more

Keeping your Lightspeed Restaurant account secure

Identify fraudulent communications and manage suspected unauthorized access to Restaurant (L-Series).

Learn more

Setting up multi-factor authentication

Add an extra layer of security to supported user accounts.

Retail MFA K-Series MFA L-Series MFA

Was this article helpful?

0 out of 0 found this helpful