What to look out for today
- Microsoft 365 login traps on hotel/conference Wi‑Fi: reports of attackers changing Wi‑Fi/DNS settings to redirect users to fake Microsoft 365 sign-in pages.
- Real-time “interactive” phishing: phishing that doesn’t just steal passwords for later, but hijacks accounts immediately while the victim is signing in (notably seen in insurance-themed lures, but the technique generalises).
- Ransomware/extortion groups going after exposed business platforms: activity linked to Cl0p affiliates targeting internet-exposed enterprise systems to steal data and extort.
- SaaS dependency disruption: a reported global ChatGPT outage is a reminder to plan for third-party service downtime.
Why this matters to smaller businesses
If an attacker captures a Microsoft 365 login, they can rapidly access email, SharePoint/OneDrive files, Teams chats, and then send convincing invoices or payment-change requests from a real account. Travelling staff and anyone working from public Wi‑Fi are at higher risk. Separately, extortion gangs often target “whoever is exposed”, including smaller firms running specialist platforms via an MSP or hosting provider.
Service outages (even from reputable providers) can also disrupt customer service, admin workflows, and marketing if your team relies on a single tool without a fallback.
Warning signs
- Staff report being asked to sign into Microsoft 365 again right after joining hotel/conference Wi‑Fi.
- Browser shows a sign-in page that looks right, but users notice odd URL/domain or repeated prompts.
- Unexpected MFA prompts (“Approve sign-in?”) when the user isn’t logging in.
- Sudden email rules created, new forwarding set up, or messages disappearing from inboxes.
- Partners/customers receive unusual “please pay this new bank account” messages from your genuine email address.
- Operational reliance issues: teams unable to work because a single SaaS tool is unavailable.
How attackers may exploit the situation
- Public Wi‑Fi redirection: manipulate DNS/Wi‑Fi equipment so “login.microsoftonline.com” lookalikes or fake sign-in pages harvest credentials.
- Real-time session hijacking: the attacker uses the captured sign-in details immediately to get into the account while the victim is still active, aiming to bypass or fatigue MFA.
- Inbox takeover for fraud: once inside Microsoft 365, attackers monitor invoices, then send payment diversion or urgent wire/transfer requests.
- Data theft and extortion: targeting internet-exposed business systems to steal data and pressure organisations to pay.
What to do today
- Send a travel/public Wi‑Fi reminder: advise staff to avoid signing into Microsoft 365 on public Wi‑Fi unless they use your company VPN (or their phone hotspot) and to report any repeated login prompts.
- Check Microsoft 365 sign-in activity: review recent sign-ins for impossible travel, unfamiliar locations, or suspicious user agents; investigate any spikes.
- Lock down email forwarding: ensure outbound auto-forwarding is restricted and alerting is enabled for new inbox rules/forwarders.
- Rehearse “payment change” controls: confirm your team always verifies bank detail changes out-of-band (phone call to a known number, not the email thread).
- Plan for SaaS downtime: note which workflows depend on ChatGPT (or any single tool) and define a manual fallback for today.
Ask your IT provider
- Do we have Conditional Access or equivalent controls to reduce risky sign-ins (e.g., require MFA, block legacy auth, flag risky locations)?
- What alerts do we receive for new inbox forwarding rules, suspicious OAuth app grants, or abnormal sign-in patterns?
- Can we enforce phishing-resistant MFA (e.g., passkeys/security keys) for finance/admin accounts?
- Which of our systems are internet-exposed via hosting/MSP arrangements, and how are they monitored for compromise and unusual data access?
- What is our SaaS resilience plan (backup access, offline copies of critical docs, alternative tools) for outages?
Patch watch - only one short paragraph, and only if relevant
If you run specialist enterprise platforms or file/PLM systems via an MSP or hosting provider, ask whether any internet-facing deployments have been reviewed for exposure and hardened, as extortion groups are actively hunting for externally accessible systems to break into.
One action today
Message staff today: “Don’t sign into Microsoft 365 over hotel/conference Wi‑Fi unless you’re on the company VPN or your phone hotspot; report unexpected sign-in/MFA prompts immediately.”
Related Actions On Cyber resource
CTA: Actions On Cyber checklist — “Invoice and bank detail change verification (anti-payment diversion) + Microsoft 365 account takeover quick response.”
Sources
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts (BleepingComputer)
- CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking (The Hacker News)
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE (The Hacker News)
- OpenAI confirms ChatGPT is down worldwide (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.