Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Saturday brief: Sextortion emails, malicious “trading/crypto” ads, and breach-driven phishing

What small and medium-sized businesses should look out for today.

High Saturday 25 July 2026, 18:14 UK time
Today’s look-out: Breach-driven scams and malvertising leading to credential theft and malware

What to look out for today

Three themes worth flagging to staff and suppliers today:

  • Sextortion emails demanding $2,000 in Bitcoin sent to people whose email addresses were exposed in past breaches and then reused by scammers.
  • Malicious adverts and lookalike websites pretending to be crypto/trading brands (e.g. wallets and charting tools) to infect devices via the browser.
  • Breach notifications in logistics and utilities that can trigger follow-on scams (fake delivery messages, “account verification” emails, fake support calls) aimed at customers and businesses.

Why this matters to smaller businesses

SMEs are targeted because they’re busy, often have shared inboxes, and rely on email, browsers, and delivery providers every day. Even when a breach happens to a supplier, criminals commonly use the news (or stolen details) to make phishing more believable. A single click can lead to mailbox compromise, invoice fraud, or downtime from malware/ransomware.

Warning signs

  • Sextortion language: claims they recorded you via webcam, includes an old password, demands crypto payment, and sets a short deadline.
  • Unexpected “delivery problem” or “customs fee” messages, especially if they push you to click quickly or log in.
  • Search/ad results that lead to slightly off domains, unusual spelling, or pages asking you to download “updates”, “security tools”, or “wallet/trading” software.
  • Browser oddities: sudden prompts, new extensions, antivirus pop-ups from a website, or repeated login prompts for Microsoft 365/Google.
  • After a supplier breach is in the news: an increase in calls/emails claiming to be that supplier’s support team.

How attackers may exploit the situation

  • Sextortion campaigns use breach-exposed email lists to scale intimidation. The goal is payment, but the same inbox may also be tried for password reuse or further phishing.
  • Malvertising/lookalike sites lure staff who search for tools, dashboards, or downloads. If a machine is compromised, attackers may steal saved browser passwords and session cookies and then access email, finance, or cloud services.
  • Supplier breach “piggybacking”: criminals reference real incidents (or copy real emails) to trick victims into clicking, handing over codes, or changing bank details.

What to do today

  • Send a short staff warning about sextortion emails: do not reply, do not pay, report to IT, and treat it as spam.
  • Remind teams to avoid clicking ads for software/tools; use bookmarks or known-good links for commonly used services.
  • Reinforce payment-change controls: any bank detail change must be verified using a trusted phone number (not one in the email).
  • Check shared mailboxes (finance@, info@, accounts@) for suspicious rules/forwarding and unusual logins if you have access.
  • Prepare for supplier-themed scams: if you use delivery partners, brief front-desk and customer-facing staff to be cautious with “delivery issue” links and calls.

Ask your IT provider

  • Can you block common sextortion indicators (crypto payment phrases, known templates) without trapping legitimate mail?
  • Do we have DNS/web filtering that reduces risk from malvertising and lookalike domains?
  • What’s our process to detect and respond to mailbox compromise (new inbox rules, unusual forwarding, suspicious sign-ins)?
  • Are MFA and conditional access enforced for email and key SaaS (and do we have alerts for MFA fatigue/push abuse)?
  • If a laptop is suspected infected via the browser, what is the isolation and recovery playbook (who to call, how fast, what gets reset)?

Patch watch - only one short paragraph, and only if relevant

No specific patch item is driving today’s brief. The practical focus is reducing exposure to phishing and malvertising through email protections, web filtering, and strong account controls (especially for shared mailboxes and finance workflows).

One action today

Send a same-day staff note: “Ignore sextortion emails, don’t click sponsored/download links for tools—use bookmarks—and verify any bank detail change by phone using a known number.”

Related Actions On Cyber resource

Actions On Cyber checklist: Payment change & invoice fraud call-back verification (finance team quick steps)

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.