Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB Cyber Brief: ransomware copycat scams, Microsoft 365 phishing, and credential-stuffing fallout

What small and medium-sized businesses should look out for today.

High Wednesday 22 July 2026, 10:38 UK time
Today’s look-out: Impersonation scams + account takeover (Microsoft 365 phishing and reused passwords)

What to look out for today

  • Ransomware headline-driven scams: criminals often piggyback on widely reported incidents (e.g. big brands) to send fake “security updates”, “delivery holds”, or “invoice re-issues”.
  • Microsoft 365 phishing designed to bypass MFA: even with a policing takedown of a major phishing platform, the techniques and copycat kits persist.
  • Credential stuffing and account takeover: breaches driven by reused passwords can spill over into your business if staff reuse passwords across services.
  • Supplier/contractor risk: any third party with access to your M365, email, payroll, finance systems, or Git repos is a prime target for session theft and login bypass tricks.

Why this matters to smaller businesses

SMEs are often hit through email compromise and stolen logins rather than sophisticated break-ins. If attackers get into Microsoft 365 (or steal an active session), they can read invoices, change payment details, reset other accounts, and send convincing phishing from a real mailbox. Separately, credential stuffing against customer portals and staff SaaS accounts can lead to fraud, data exposure, and operational disruption.

Warning signs

  • Emails or Teams messages urging you to “re-authenticate”, “view a secure document”, or “confirm mailbox settings”—especially if they arrive after a failed login alert.
  • Unexpected MFA prompts, or staff reporting repeated push notifications they didn’t trigger.
  • New or unusual mailbox rules (e.g. auto-forwarding, moving invoices to RSS/Archive, hiding alerts).
  • Supplier emails with bank details changes or “urgent” payment re-routing.
  • Customer complaints about account lockouts or unknown orders (a common credential-stuffing indicator).

How attackers may exploit the situation

  • Session theft phishing: tricking users into entering credentials/MFA in a way that hands over a live session to the attacker (so they can act as the user).
  • Ransomware-themed lures: using big-brand incident news to make fake “statements”, “support tickets”, or “shared files” feel timely and believable.
  • Credential stuffing: using password lists from past breaches to try logins automatically across popular services (customer accounts, staff SaaS, even email).
  • Follow-on fraud: once inside email, attackers target finance processes—invoice interception, mandate fraud, and payroll diversion.

What to do today

  • Send a 2-minute staff note: do not approve unexpected MFA prompts; report them immediately. Don’t “re-authenticate” from links—go directly to Microsoft 365 via bookmarked URLs.
  • Protect finance flows: enforce a call-back process for any new/changed bank details (use known numbers, not the email signature).
  • Check Microsoft 365 for quick wins: review recent sign-ins, investigate impossible travel alerts, and look for new inbox rules/auto-forwarding.
  • Reduce credential-stuffing risk: ensure staff use unique passwords (password manager) and that customer/staff portals have rate-limiting and lockout controls where feasible.

Ask your IT provider

  • Can you show us this week’s list of risky M365 sign-ins and what was investigated/closed?
  • Do we have controls to detect/stop new mailbox forwarding rules and suspicious OAuth app consent?
  • Are we using phishing-resistant MFA (where possible) for admins and finance users, and are legacy sign-in methods blocked?
  • What is our process for business email compromise (who to call, how to contain, what logs are retained)?
  • For customer logins/portals, what is in place for credential stuffing (rate limits, bot detection, monitoring, forced resets)?

Patch watch - only one short paragraph, and only if relevant

No specific patch action is the main story today; the practical risk is account takeover via phishing and reused credentials. If your business uses developer tooling (e.g. code repos/CI), ask your IT/dev supplier how they validate third-party packages and protect build pipelines, as malicious repositories and lookalike packages continue to be used to distribute malware.

One action today

Email staff today: “If you get an unexpected MFA prompt or a ‘re-authenticate Microsoft 365’ link, do not approve or click—report it immediately and sign in only via your bookmark.”

Related Actions On Cyber resource

Actions On Cyber checklist: Business Email Compromise (BEC) & invoice fraud call-back process

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.