What to look out for today
Two practical risks are front-and-centre today:
- Cloud/service disruption knock-on: after widely reported Microsoft 365/Azure disruption, expect confusion, delays and “urgent support” messages targeting staff.
- Teams/Zoom impersonation phishing: realistic emails and web pages pretending to be Zoom or Microsoft Teams, used to steal sign-ins or push malware.
Why this matters to smaller businesses
- Dependency risk: if you rely on Microsoft 365 for email, files, meetings, finance approvals or customer comms, even a short outage can pause operations.
- Scam follow-on: attackers routinely exploit high-profile outages by sending fake “Microsoft support” calls/emails and bogus “re-login” links.
- Credential theft = business compromise: a single staff login can lead to mailbox takeover, invoice fraud, data theft and ransomware.
Warning signs
- Emails/messages claiming your Microsoft 365 account will be suspended or you must “re-verify” after an outage.
- Meeting invites or “missed chat/voicemail” notifications that push you to sign in to Zoom/Teams via a link.
- Unusual requests to install a “Zoom/Teams update”, browser add-on, or remote support tool to “fix access”.
- Staff reporting they can’t access Microsoft 365 and then receiving external helpdesk numbers via email/text.
- New inbox rules, unexpected MFA prompts, or colleagues receiving odd replies “from you”.
How attackers may exploit the situation
- Outage-themed impersonation: “Microsoft incident ticket”, “route issue fix”, “reset your session” messages to harvest credentials.
- Typosquatted lookalike domains: fake Zoom/Teams pages that appear legitimate to rushed users.
- Malware delivery via ‘fix’ steps: once trust is gained, victims are nudged into opening a file or running an ‘update’.
- Target selection and follow-up: modern malware campaigns increasingly profile victims to prioritise higher-value targets (e.g. finance/admin users).
What to do today
- Send a 2-line internal note to staff: “Outage scams are common. Don’t click ‘re-login’ links or install ‘fix’ tools. Use our normal support route.”
- Reinforce the rule: access Microsoft 365, Teams and Zoom via bookmarks or known apps, not links in emails.
- Protect finance workflows: pause/confirm any supplier bank detail changes or urgent payment requests with a call-back to a known number.
- Check for account takeover signals in Microsoft 365: suspicious sign-ins, new forwarding rules, or unexpected MFA re-registrations.
- Make sure you have an outage workaround: a plan for customer comms and document access if Microsoft 365 is degraded.
Ask your IT provider
- What’s our standard process for verifying Microsoft support messages and service advisories?
- Do we have conditional access / risky sign-in alerts enabled, and who monitors them?
- Can you quickly check for new inbox forwarding rules and suspicious sign-ins for finance/admin accounts?
- What’s our business continuity plan for Microsoft 365 outages (email, files, telephony, customer comms)?
Patch watch - only one short paragraph, and only if relevant
If you run on-premise Windows/Active Directory, speak to your IT provider about your certificate services and domain controller protections. Today’s reporting includes a new Active Directory-related attack path that appears to reduce the effort needed for an internal user account to impersonate higher-privilege systems. For many SMEs this is an IT-provider hygiene check rather than an immediate staff action.
One action today
Email staff today: “Outage scams are common—don’t click ‘re-login’ links or install ‘fix’ tools for Microsoft/Teams/Zoom; use bookmarks/apps and report anything suspicious to IT.”
Related Actions On Cyber resource
Actions On Cyber: Supplier-impersonation & invoice fraud call-back checklist
Sources
- Microsoft blames massive Microsoft 365 outage on maintenance bug (BleepingComputer)
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery (The Hacker News)
- New Dolphin X malware uses AI to rank high-value targets (BleepingComputer)
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.