Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB Cyber Brief: supplier support-system breach scams, fake coding tests, and exposed AI tools hunting cloud keys

What small and medium-sized businesses should look out for today.

High Friday 17 July 2026, 18:30 UK time
Today’s look-out: Supplier incident scams + credential theft via “tests/tools” and exposed services

What to look out for today

  • Supplier/support portal breach ripple effects: a major firm disclosed a breach linked to a third-party support ticket system. Expect copycat scams and targeted phishing that reference “tickets”, “cases”, “support logins”, or “security notices”.
  • Fake job posts and coding challenges: malware being delivered through fake coding tests (including files that look like harmless images/resources) aimed at stealing browser credentials and crypto wallet data.
  • Exposed AI / workflow tools being hunted: attackers are scanning for internet-exposed services (including AI and automation tools) to steal cloud keys and Kubernetes tokens—a shortcut to full cloud compromise.
  • Credential + wallet stealing frameworks: more evidence of multi-payload toolkits focused on harvesting logins and sensitive data.

Why this matters to smaller businesses

SMEs often rely on ticketing/support platforms, MSPs, cloud accounts, and SaaS tools. When any supplier system is breached, attackers frequently use stolen details (names, email threads, ticket numbers, internal jargon) to craft believable messages that lead to:

  • invoice/payment diversion
  • password resets and account takeover
  • malware delivery ("run this fix", "install this update", "open this project")
  • cloud account compromise if keys/tokens are exposed

Warning signs

  • Email or calls claiming to be from a supplier/MSP referencing a specific support ticket, urging urgent action.
  • Requests to reset MFA, “re-enrol” authentication, or approve a new device “to secure your account”.
  • Links to “support portals” that look right but use unfamiliar domains, or ask you to sign in again unexpectedly.
  • Recruitment/job-related messages asking staff to download and run a “coding task”, “take-home test”, or “assessment project”.
  • Unexpected prompts for browser password export/sync, or sudden sign-in notifications from new locations.
  • Any internet-facing AI/workflow tool suddenly slow, crashing, or showing unexplained new users/sessions.

How attackers may exploit the situation

  • Support-ticket impersonation: using details from compromised ticketing systems to send convincing “case updates” with malicious links or attachment lures.
  • Malicious “test projects”: disguising harmful content inside files that appear routine (e.g., project assets/images) to trick users into executing or trusting them.
  • Cloud credential harvesting: scanning the internet for exposed tools and misconfigurations to obtain API keys, access tokens, and then pivoting into email, storage, finance or CI/CD systems.
  • Credential theft at scale: deploying stealers to capture saved browser passwords and session tokens, then logging into payroll, banking, Microsoft 365/Google, and accounting platforms.

What to do today

  • Brief staff (especially finance, HR, ops and anyone job-hunting/recruiting) to treat “support ticket” and “assessment task” messages as high risk.
  • Out-of-band verification: if any supplier/MSP asks for urgent changes (bank details, password resets, MFA changes, remote access), verify using a known phone number—not details in the email.
  • Lock down public exposure: check whether any internal tools (automation, AI model runners, dashboards, admin panels) are accessible from the internet. If unsure, assume yes and ask IT to confirm.
  • Review admin access: ensure MFA is enabled for email, cloud and finance systems; remove stale accounts; confirm break-glass/admin accounts are protected and monitored.
  • Harden ticketing/support workflows: require approvals for credential resets, supplier bank changes, and new remote-access tools.

Ask your IT provider

  • Do we use any third-party ticketing/support platform where support threads might contain sensitive info? What data is stored there and how is access controlled?
  • Can you confirm whether any of our internal tools (including AI/automation/workflow tools) are internet-exposed? If yes, why, and what protections are in place (MFA, IP allow-listing, SSO, logging)?
  • What monitoring do we have for new mailbox rules, suspicious logins, impossible travel, and mass export of contacts/emails?
  • How quickly can we revoke and rotate cloud keys/tokens if we suspect exposure? Do we have an agreed runbook?

Patch watch - only one short paragraph, and only if relevant

If you operate industrial/manufacturing systems, note an ICS advisory for Rockwell Automation FactoryTalk DataMosaix (Private Cloud). For most office-based SMEs this won’t apply, but if you have OT/industrial environments, ask your provider to confirm whether you use it and whether mitigations are in place.

One action today

Send a same-day staff note: “Do not act on supplier/support ‘urgent’ emails or run any ‘coding test/assessment project’ files—verify via a known number and forward to IT first.”

Related Actions On Cyber resource

CTA: Use the Actions On Cyber “Supplier payment-change & support-ticket verification checklist”

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.