Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SME cyber lookout: Zimbra ‘zero-click’ phishing warning + Microsoft 365 outage disruption scams

What small and medium-sized businesses should look out for today.

High Thursday 23 July 2026, 18:44 UK time
Today’s look-out: Email compromise risk and cloud disruption scams

What to look out for today

  • Targeted “zero-click” phishing aimed at Zimbra email users (per UK NCSC and US partners). This is about stealing mail access and sensitive information, not just nuisance spam.
  • Microsoft 365 service outage affecting Teams, SharePoint and other services. Expect knock-on disruption (missed messages, delayed approvals) and an increase in outage-themed phishing.

Why this matters to smaller businesses

Email is still the front door to invoices, bank changes, contract negotiations and payroll. If an attacker gets into a mailbox, they can quietly watch conversations, then jump in at the perfect moment to redirect payments or harvest customer data.

Separately, cloud outages create operational pressure. When people are rushing, they’re more likely to fall for “urgent” links, fake support calls, or requests to “re-authenticate” to restore access.

Warning signs

  • Unexpected prompts to re-login to email, Teams, SharePoint or the Microsoft 365 admin centre.
  • Emails claiming to be from “Microsoft Support” or “IT Admin” with links to “fix the outage” or “restore access”.
  • Mail rules or forwarding you didn’t set up (e.g., invoices forwarded externally, or messages marked read automatically).
  • Users reporting they were logged out, or seeing sign-in alerts they don’t recognise.
  • Suppliers/customers suddenly sending “new bank details” or “updated payment instructions” during disruption.

How attackers may exploit the situation

  • Mailbox takeover to monitor conversations and send believable payment diversion requests.
  • Outage-lure phishing: fake “service status” pages and “account verification” pages while staff are frustrated by downtime.
  • Fake IT support calls/messages offering to “get Teams back” or “fix SharePoint access”, aiming to capture passwords or MFA codes.

What to do today

  • Send a 2-minute staff warning: “No one should click ‘restore access’ links or share codes because of an outage. Use only our normal bookmarks and known support channels.”
  • Verify payment changes out-of-band (call a known number, not the one in the email). Treat any change during disruption as high risk.
  • Check mail forwarding and rules on shared mailboxes (finance@, accounts@, payroll@, office@) and remove anything unexpected.
  • Monitor sign-in alerts and quickly disable accounts that show suspicious access until verified.
  • Capture evidence: if you suspect compromise, keep the email, headers if available, times, affected accounts, and any sign-in alert screenshots for your IT provider.

Ask your IT provider

  • Do we run Zimbra anywhere (including hosted instances), and do you have enhanced monitoring for suspicious mailbox access and new forwarding rules?
  • What’s our process to detect and remove malicious inbox rules and mail forwards across key accounts?
  • How are you alerting us to impossible travel / unusual sign-in events and risky logins?
  • During Microsoft 365 disruption, what’s our approved support route and how do staff verify genuine IT messages?
  • Do we have a tested procedure for temporary comms if Teams/SharePoint is down (e.g., phone/SMS tree, alternative file-sharing process)?

Patch watch - only one short paragraph, and only if relevant

Today’s warning includes Zimbra-focused activity and mentions exploitation alongside phishing in reporting. If you use Zimbra, treat this as an urgent supplier/IT hygiene check: confirm with your provider that security updates are being applied promptly and that mailbox access and forwarding changes are being actively monitored.

One action today

Send a short internal alert telling staff not to click “restore access/outage fix” links or share login/MFA codes, and to verify any payment or bank-detail changes by phone to a known number.

Related Actions On Cyber resource

Actions On Cyber: Payment change (invoice/bank details) verification checklist

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.