Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SME cyber look-out: supplier platform breach scams + AI tool permissions

What small and medium-sized businesses should look out for today.

Moderate Wednesday 22 July 2026, 18:41 UK time
Today’s look-out: Supplier incident scams, shared-platform data exposure, and over-permissioned AI tools

What to look out for today

A ransomware gang has reportedly breached a data exchange platform shared with a supplier in an attack affecting Swiss rail manufacturer Stadler. Incidents like this often trigger a wave of follow-on scams (fake invoices, fake “updated bank details”, and “urgent document share” emails) that target customers and suppliers.

In parallel, many businesses are rolling out GenAI tools quickly. If AI assistants/agents are given broad access (mailboxes, file shares, finance folders), a single compromised account can turn into rapid data access and ransomware impact.

Why this matters to smaller businesses

  • Supplier ripple effects: even if you weren’t attacked, your supplier (or a shared portal) might be, and criminals exploit the confusion.
  • Payment diversion risk: attackers frequently use breach news to make “plausible” payment-change requests.
  • Shared-platform dependency: document exchange portals, logistics portals, payroll/HR platforms, and MSP tools are high-trust pathways into day-to-day operations.
  • AI access sprawl: AI tools connected to email and cloud drives can accidentally widen who/what can access sensitive data.

Warning signs

  • Emails referencing a supplier incident with pressure tactics: “new secure link”, “re-issue invoice”, “confirm bank details today”, “download the updated contract”.
  • Messages that move you off normal processes: asking to pay faster, bypass approvals, or use a new account “just for this payment”.
  • Unexpected “shared file” notifications (especially if you don’t normally use that portal) or requests to log in again.
  • Internal signs: staff reporting unusual MFA prompts, lots of password reset emails, or sudden lockouts.
  • New AI tools appearing in workflows without clear approval (e.g., staff connecting an AI assistant to company email or cloud storage on their own).

How attackers may exploit the situation

  • Supplier impersonation: criminals pretend to be the breached supplier/partner and request payment changes or resend “corrected” invoices.
  • Portal lure: “Here’s the new data exchange link” leading to credential harvesting.
  • Account takeover & lateral access: once one mailbox or cloud account is compromised, attackers use existing access (not necessarily malware) to find invoices, banking details, and sensitive files.
  • AI over-permissions: if an AI tool has broad access, a compromised user (or misconfigured AI integration) can speed up discovery of valuable data and increase ransomware leverage.

What to do today

  • Re-brief finance and office teams: no bank detail changes via email. Always verify using a known phone number (from your own records, not the email).
  • Check your supplier comms process: confirm who is authorised to request invoice/bank changes and how those requests are validated.
  • Review third-party portals you rely on: list them (accounts payable portals, file exchange sites, logistics, payroll) and ensure MFA is enabled where available.
  • AI tool sanity check: inventory any AI assistants connected to Microsoft 365/Google Workspace/file storage; remove unnecessary integrations and reduce access to “need-to-know”.
  • Backups: ensure you have an offline/immutable copy for key business data and confirm you can restore (not just that backups exist).

Ask your IT provider

  • Do we have a list of the shared portals/SaaS our business relies on, and are they all protected with MFA and strong admin controls?
  • What monitoring do we have for unusual mailbox rules, mass file downloads, and risky sign-ins?
  • Do we have an agreed process for handling supplier breach notifications (who decides, who communicates, what we change temporarily)?
  • What’s our policy on GenAI tools: which are approved, how access is limited, and how we detect unsanctioned connections to email/file storage?

Patch watch - only one short paragraph, and only if relevant

If you use industrial/operational kit (factories, building management, monitoring devices), note that CISA issued advisories this week for certain Rockwell Automation and Tycon Systems devices. For most office-based SMEs this won’t apply, but if you have on-site control/monitoring equipment managed by a contractor, ask them to confirm whether any affected devices are present and how they’re being protected.

One action today

Send a 2-minute note to finance/admin staff: “No bank-detail or payee changes via email—verify using a known phone number from our records before paying.”

Related Actions On Cyber resource

CTA: Use the Actions On Cyber ‘Payment change / invoice fraud callback checklist’ for finance teams

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.