What to look out for today
Two themes to keep on your radar today:
- More convincing phishing lures and delivery methods (including fake websites and file delivery tricks) designed to get staff to open a document, download a file, or sign in.
- Microsoft 365 account compromise that hides in plain sight, using legitimate Microsoft 365/Graph activity (e.g., Calendar/Events) to blend in with normal business traffic.
Why this matters to smaller businesses
- Microsoft 365 is a single point of failure: if an attacker gets into one mailbox, they can impersonate staff, access files, and target your customers/suppliers.
- It can be hard to spot: activity may look like normal Microsoft cloud usage, so basic “is there malware on the PC?” checks may miss it.
- Business impact is immediate: invoice fraud, payroll diversion, data theft, and account lockouts can disrupt operations fast.
Warning signs
- Emails or messages pushing urgency: “ID check”, “account verification”, “document shared”, “payment overdue”, “HMRC/government lookup”.
- Unexpected sign-in prompts, MFA requests you didn’t initiate, or staff reporting “my inbox looks different”.
- New inbox rules/forwarding set up (e.g., mail auto-forwarding to an external address).
- Calendar oddities (unusual events, strange attachments, or far-future events that no one created).
- Supplier/customer reports that they received unusual requests “from you” (bank change, urgent payment, gift cards, new account details).
How attackers may exploit the situation
- AI-assisted phishing at scale: rapidly testing subject lines, filenames, and templates to find what your staff will click.
- Credential capture: directing users to realistic fake sign-in pages to steal Microsoft 365 usernames/passwords.
- Living-off-the-cloud: once inside Microsoft 365, using standard features and APIs (like Microsoft Graph and mailbox/calendar capabilities) to send commands, move data, or maintain access while appearing legitimate.
- Follow-on fraud: using a compromised mailbox to monitor invoices and then request a “last-minute” bank detail change.
What to do today
- Run a 10-minute staff reminder: don’t open unexpected attachments/links; confirm payment changes by phone using a known number; report strange MFA prompts immediately.
- Check Microsoft 365 basics: review recent sign-ins for key accounts (finance, payroll, senior staff) and look for unfamiliar locations/devices.
- Check for auto-forwarding and suspicious inbox rules on high-risk mailboxes (finance/shared mailboxes).
- Tighten verification for money movement: enforce a two-person check for new payees/bank detail changes.
Ask your IT provider
- Can you show us how you monitor Microsoft 365 for suspicious sign-ins, impossible travel, new inbox rules, and external auto-forwarding?
- Do we have alerts for unusual Microsoft 365 activity that could blend in as “normal” Graph/Cloud traffic?
- Which accounts are treated as high risk (finance, payroll, admin) and what extra controls are enforced on them?
- If a mailbox is compromised, what is the containment playbook (session revoke, token reset, rule clean-up, customer/supplier comms)?
Patch watch - only one short paragraph, and only if relevant
Today’s main risk is still phishing and account takeover, but if your organisation uses 7-Zip widely (especially in finance/admin workflows), ask your IT support to confirm it’s up to date because crafted archives are a common delivery method in real campaigns.
One action today
Brief staff today: any payment/bank-detail change request must be confirmed by phone using a known number (not one in the email).
Related Actions On Cyber resource
Actions On Cyber checklist: “Invoice and payment change scam controls (call-back, dual approval, mailbox compromise response)”
Sources
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign (The Hacker News)
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 (The Hacker News)
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms (BleepingComputer)
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.