Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB cyber lookout: smarter phishing and stealthy Microsoft 365 misuse

What small and medium-sized businesses should look out for today.

High Monday 20 July 2026, 19:18 UK time
Today’s look-out: Phishing themes and Microsoft 365 account takeover with ‘normal-looking’ cloud activity

What to look out for today

Two themes to keep on your radar today:

  • More convincing phishing lures and delivery methods (including fake websites and file delivery tricks) designed to get staff to open a document, download a file, or sign in.
  • Microsoft 365 account compromise that hides in plain sight, using legitimate Microsoft 365/Graph activity (e.g., Calendar/Events) to blend in with normal business traffic.

Why this matters to smaller businesses

  • Microsoft 365 is a single point of failure: if an attacker gets into one mailbox, they can impersonate staff, access files, and target your customers/suppliers.
  • It can be hard to spot: activity may look like normal Microsoft cloud usage, so basic “is there malware on the PC?” checks may miss it.
  • Business impact is immediate: invoice fraud, payroll diversion, data theft, and account lockouts can disrupt operations fast.

Warning signs

  • Emails or messages pushing urgency: “ID check”, “account verification”, “document shared”, “payment overdue”, “HMRC/government lookup”.
  • Unexpected sign-in prompts, MFA requests you didn’t initiate, or staff reporting “my inbox looks different”.
  • New inbox rules/forwarding set up (e.g., mail auto-forwarding to an external address).
  • Calendar oddities (unusual events, strange attachments, or far-future events that no one created).
  • Supplier/customer reports that they received unusual requests “from you” (bank change, urgent payment, gift cards, new account details).

How attackers may exploit the situation

  • AI-assisted phishing at scale: rapidly testing subject lines, filenames, and templates to find what your staff will click.
  • Credential capture: directing users to realistic fake sign-in pages to steal Microsoft 365 usernames/passwords.
  • Living-off-the-cloud: once inside Microsoft 365, using standard features and APIs (like Microsoft Graph and mailbox/calendar capabilities) to send commands, move data, or maintain access while appearing legitimate.
  • Follow-on fraud: using a compromised mailbox to monitor invoices and then request a “last-minute” bank detail change.

What to do today

  • Run a 10-minute staff reminder: don’t open unexpected attachments/links; confirm payment changes by phone using a known number; report strange MFA prompts immediately.
  • Check Microsoft 365 basics: review recent sign-ins for key accounts (finance, payroll, senior staff) and look for unfamiliar locations/devices.
  • Check for auto-forwarding and suspicious inbox rules on high-risk mailboxes (finance/shared mailboxes).
  • Tighten verification for money movement: enforce a two-person check for new payees/bank detail changes.

Ask your IT provider

  • Can you show us how you monitor Microsoft 365 for suspicious sign-ins, impossible travel, new inbox rules, and external auto-forwarding?
  • Do we have alerts for unusual Microsoft 365 activity that could blend in as “normal” Graph/Cloud traffic?
  • Which accounts are treated as high risk (finance, payroll, admin) and what extra controls are enforced on them?
  • If a mailbox is compromised, what is the containment playbook (session revoke, token reset, rule clean-up, customer/supplier comms)?

Patch watch - only one short paragraph, and only if relevant

Today’s main risk is still phishing and account takeover, but if your organisation uses 7-Zip widely (especially in finance/admin workflows), ask your IT support to confirm it’s up to date because crafted archives are a common delivery method in real campaigns.

One action today

Brief staff today: any payment/bank-detail change request must be confirmed by phone using a known number (not one in the email).

Related Actions On Cyber resource

Actions On Cyber checklist: “Invoice and payment change scam controls (call-back, dual approval, mailbox compromise response)”

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.