Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SME cyber brief: Microsoft 365 disruption fallout + Teams/Zoom impersonation phishing

What small and medium-sized businesses should look out for today.

High Friday 24 July 2026, 18:50 UK time
Today’s look-out: Cloud disruption and supplier-impersonation scams (Microsoft 365/Azure) plus Teams/Zoom phishing lures

What to look out for today

Two practical risks are front-and-centre today:

  • Cloud/service disruption knock-on: after widely reported Microsoft 365/Azure disruption, expect confusion, delays and “urgent support” messages targeting staff.
  • Teams/Zoom impersonation phishing: realistic emails and web pages pretending to be Zoom or Microsoft Teams, used to steal sign-ins or push malware.

Why this matters to smaller businesses

  • Dependency risk: if you rely on Microsoft 365 for email, files, meetings, finance approvals or customer comms, even a short outage can pause operations.
  • Scam follow-on: attackers routinely exploit high-profile outages by sending fake “Microsoft support” calls/emails and bogus “re-login” links.
  • Credential theft = business compromise: a single staff login can lead to mailbox takeover, invoice fraud, data theft and ransomware.

Warning signs

  • Emails/messages claiming your Microsoft 365 account will be suspended or you must “re-verify” after an outage.
  • Meeting invites or “missed chat/voicemail” notifications that push you to sign in to Zoom/Teams via a link.
  • Unusual requests to install a “Zoom/Teams update”, browser add-on, or remote support tool to “fix access”.
  • Staff reporting they can’t access Microsoft 365 and then receiving external helpdesk numbers via email/text.
  • New inbox rules, unexpected MFA prompts, or colleagues receiving odd replies “from you”.

How attackers may exploit the situation

  • Outage-themed impersonation: “Microsoft incident ticket”, “route issue fix”, “reset your session” messages to harvest credentials.
  • Typosquatted lookalike domains: fake Zoom/Teams pages that appear legitimate to rushed users.
  • Malware delivery via ‘fix’ steps: once trust is gained, victims are nudged into opening a file or running an ‘update’.
  • Target selection and follow-up: modern malware campaigns increasingly profile victims to prioritise higher-value targets (e.g. finance/admin users).

What to do today

  • Send a 2-line internal note to staff: “Outage scams are common. Don’t click ‘re-login’ links or install ‘fix’ tools. Use our normal support route.”
  • Reinforce the rule: access Microsoft 365, Teams and Zoom via bookmarks or known apps, not links in emails.
  • Protect finance workflows: pause/confirm any supplier bank detail changes or urgent payment requests with a call-back to a known number.
  • Check for account takeover signals in Microsoft 365: suspicious sign-ins, new forwarding rules, or unexpected MFA re-registrations.
  • Make sure you have an outage workaround: a plan for customer comms and document access if Microsoft 365 is degraded.

Ask your IT provider

  • What’s our standard process for verifying Microsoft support messages and service advisories?
  • Do we have conditional access / risky sign-in alerts enabled, and who monitors them?
  • Can you quickly check for new inbox forwarding rules and suspicious sign-ins for finance/admin accounts?
  • What’s our business continuity plan for Microsoft 365 outages (email, files, telephony, customer comms)?

Patch watch - only one short paragraph, and only if relevant

If you run on-premise Windows/Active Directory, speak to your IT provider about your certificate services and domain controller protections. Today’s reporting includes a new Active Directory-related attack path that appears to reduce the effort needed for an internal user account to impersonate higher-privilege systems. For many SMEs this is an IT-provider hygiene check rather than an immediate staff action.

One action today

Email staff today: “Outage scams are common—don’t click ‘re-login’ links or install ‘fix’ tools for Microsoft/Teams/Zoom; use bookmarks/apps and report anything suspicious to IT.”

Related Actions On Cyber resource

Actions On Cyber: Supplier-impersonation & invoice fraud call-back checklist

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.