What to look out for today
- Ransomware headline-driven scams: criminals often piggyback on widely reported incidents (e.g. big brands) to send fake “security updates”, “delivery holds”, or “invoice re-issues”.
- Microsoft 365 phishing designed to bypass MFA: even with a policing takedown of a major phishing platform, the techniques and copycat kits persist.
- Credential stuffing and account takeover: breaches driven by reused passwords can spill over into your business if staff reuse passwords across services.
- Supplier/contractor risk: any third party with access to your M365, email, payroll, finance systems, or Git repos is a prime target for session theft and login bypass tricks.
Why this matters to smaller businesses
SMEs are often hit through email compromise and stolen logins rather than sophisticated break-ins. If attackers get into Microsoft 365 (or steal an active session), they can read invoices, change payment details, reset other accounts, and send convincing phishing from a real mailbox. Separately, credential stuffing against customer portals and staff SaaS accounts can lead to fraud, data exposure, and operational disruption.
Warning signs
- Emails or Teams messages urging you to “re-authenticate”, “view a secure document”, or “confirm mailbox settings”—especially if they arrive after a failed login alert.
- Unexpected MFA prompts, or staff reporting repeated push notifications they didn’t trigger.
- New or unusual mailbox rules (e.g. auto-forwarding, moving invoices to RSS/Archive, hiding alerts).
- Supplier emails with bank details changes or “urgent” payment re-routing.
- Customer complaints about account lockouts or unknown orders (a common credential-stuffing indicator).
How attackers may exploit the situation
- Session theft phishing: tricking users into entering credentials/MFA in a way that hands over a live session to the attacker (so they can act as the user).
- Ransomware-themed lures: using big-brand incident news to make fake “statements”, “support tickets”, or “shared files” feel timely and believable.
- Credential stuffing: using password lists from past breaches to try logins automatically across popular services (customer accounts, staff SaaS, even email).
- Follow-on fraud: once inside email, attackers target finance processes—invoice interception, mandate fraud, and payroll diversion.
What to do today
- Send a 2-minute staff note: do not approve unexpected MFA prompts; report them immediately. Don’t “re-authenticate” from links—go directly to Microsoft 365 via bookmarked URLs.
- Protect finance flows: enforce a call-back process for any new/changed bank details (use known numbers, not the email signature).
- Check Microsoft 365 for quick wins: review recent sign-ins, investigate impossible travel alerts, and look for new inbox rules/auto-forwarding.
- Reduce credential-stuffing risk: ensure staff use unique passwords (password manager) and that customer/staff portals have rate-limiting and lockout controls where feasible.
Ask your IT provider
- Can you show us this week’s list of risky M365 sign-ins and what was investigated/closed?
- Do we have controls to detect/stop new mailbox forwarding rules and suspicious OAuth app consent?
- Are we using phishing-resistant MFA (where possible) for admins and finance users, and are legacy sign-in methods blocked?
- What is our process for business email compromise (who to call, how to contain, what logs are retained)?
- For customer logins/portals, what is in place for credential stuffing (rate limits, bot detection, monitoring, forced resets)?
Patch watch - only one short paragraph, and only if relevant
No specific patch action is the main story today; the practical risk is account takeover via phishing and reused credentials. If your business uses developer tooling (e.g. code repos/CI), ask your IT/dev supplier how they validate third-party packages and protect build pipelines, as malicious repositories and lookalike packages continue to be used to distribute malware.
One action today
Email staff today: “If you get an unexpected MFA prompt or a ‘re-authenticate Microsoft 365’ link, do not approve or click—report it immediately and sign in only via your bookmark.”
Related Actions On Cyber resource
Actions On Cyber checklist: Business Email Compromise (BEC) & invoice fraud call-back process
Sources
- Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak (BleepingComputer)
- Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA (The Hacker News)
- Police dismantle Kratos phishing platform, arrest developer (BleepingComputer)
- Chick-fil-A discloses data breach after credential stuffing attacks (BleepingComputer)
- FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware (BleepingComputer)
- Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.