What to look out for today
Expect a rise in payment fraud and “security update” lures as criminals use more realistic identity signals (like residential IPs and device fingerprints) and as public chatter about software flaws drives opportunistic phishing.
- Card-not-present fraud that looks more like a real customer (harder to spot with basic checks).
- Phishing emails pushing urgent “update now” messages (especially around popular tools and website platforms).
- Website takeover attempts against organisations running WordPress, followed by fake invoices, SEO spam, or malware delivery.
Why this matters to smaller businesses
SMEs often rely on automated fraud checks, outsourced IT, and a small number of key SaaS tools. Criminals are adapting: “clean” residential connections and richer device identity signals can make fraudulent transactions and logins look legitimate. At the same time, when widely-used software issues are in the news, attackers frequently pivot to mass phishing (posing as your IT provider, hosting company, or “WordPress support”) to gain access quickly.
Warning signs
- A sudden change in fraud patterns: more chargebacks, more “authorised but disputed” card payments, or unusual refund requests.
- New admin logins or password resets on website/SaaS accounts that nobody initiated.
- Emails claiming “critical update required” with pressure tactics (today, within 1 hour, service will be suspended) or links to “security scans”.
- Website behaviour changes: unexpected redirects, new pages you didn’t create, or unexplained spikes in traffic.
How attackers may exploit the situation
- Fraud evasion: criminals use “clean” residential proxies plus browser/device fingerprints to look like genuine customers and slip past basic anti-fraud rules.
- Credential theft: phishing pages collect Microsoft 365/Google/website admin logins; attackers then add forwarding rules, change bank details on invoices, or steal customer data.
- Website compromise: attackers target commonly-used site platforms and plugins, then use the site to host scams, deliver malware, or intercept payments.
What to do today
- Brief staff (especially finance, reception/admin, and anyone who updates the website): do not act on “urgent update” emails—confirm via a known support channel.
- Review payment controls: tighten refund approval, re-check chargeback handling, and ensure large/first-time orders get a manual sense-check.
- Harden access: confirm MFA is on for email, accounting, website admin, and payment portals; remove unused admin accounts.
- Check logs quickly: look for new admin users, password resets, and unusual sign-in locations on key systems (email, website, e-commerce, payroll).
Ask your IT provider
- Can you show me which of our business-critical systems have MFA enforced (not optional) and which accounts are exempt?
- Do we have alerting for suspicious sign-ins, new mailbox forwarding rules, and new admin creation on our website platform?
- What’s our plan if our website is compromised: how fast can you restore, and from what backups?
- For online payments/e-commerce, what fraud checks are enabled (velocity limits, AVS/3DS settings where applicable), and who reviews exceptions?
Patch watch - only one short paragraph, and only if relevant
If you run a WordPress site, treat “update” messaging with care: attackers often exploit the news cycle. Ensure your WordPress core and key plugins/themes are maintained by someone accountable, and that updates are carried out via your normal admin process (not links in emails). For endpoint tools like archivers, remind staff not to open unexpected compressed files from email, even if they look like invoices or scanned documents.
One action today
Send a same-day internal note to finance and admin staff: ‘No urgent update links from email—verify via our usual IT/support contact before logging in or installing anything.’
Related Actions On Cyber resource
Actions On Cyber: Payment change & invoice fraud call-back checklist
Sources
- Inside the Search for "Clean" Residential Proxies for Carding (BleepingComputer)
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now (BleepingComputer)
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.