What to look out for today
- Supplier breach ripple-effects: a major professional services firm breach is being claimed as supply-chain related. Expect follow-on emails pretending to be “security updates”, “portal resets”, or “new login links”.
- Ransomware data-theft fallout: a large consumer brand has confirmed data theft at a subsidiary following a ransomware incident. These events often lead to impersonation, invoice fraud and “we need updated bank details” scams aimed at partners and smaller suppliers.
- Finance-team credential theft: reporting highlights phishing lures aimed at tax/finance workflows. Even if the campaign is described in another region, the technique (finance-themed lures to steal logins and deliver malware) is highly portable.
- App store trust isn’t perfect: a case involving a fraudulent crypto wallet app underscores that “it was in the official store” is not a guarantee—use extra checks for finance/crypto apps on work devices.
Why this matters to smaller businesses
SMEs are often targeted after big-name incidents because criminals know staff recognise the brand and are more likely to click. If you use large consultancies, household-name suppliers, or popular SaaS tools, attackers will try to:
- Harvest passwords via convincing “account reset” pages.
- Redirect payments by impersonating supplier finance teams.
- Use stolen data (names, email formats, invoice references) to make scams more believable.
Warning signs
- Emails referencing a supplier breach and urging you to reset passwords immediately via a link.
- Unexpected invoice re-issues, “bank detail changes”, or requests to pay a different account.
- Messages claiming you must re-authenticate to keep access to a client portal.
- Attachments described as tax documents, “payment advice”, “statement”, or “remittance” you weren’t expecting.
- Colleagues receiving calls that follow an email (“I’ve just sent you the new payment details—can you action today?”).
How attackers may exploit the situation
- Brand impersonation: spoofing well-known firms and subsidiaries to push fake logins or malware-laced attachments.
- Thread hijacking: replying inside existing email chains using compromised mailboxes so the request looks “normal”.
- Payment diversion: using breach publicity as an excuse for “new banking arrangements” or “temporary accounts”.
- Credential stuffing: if passwords are reused, attackers try the same login across email, Microsoft 365/Google Workspace, payroll and accounting tools.
What to do today
- Warn staff (especially finance and reception): no payment detail changes via email alone; verify using a known phone number from your records.
- Check your supplier communications process: ensure purchase ledger staff know the approval steps for new bank details and urgent payments.
- Harden email logins: confirm MFA is enabled for email and any finance/admin SaaS; remove legacy/basic authentication where possible.
- Quick review of inbox rules: look for new mail-forwarding, “hide this sender”, or rules moving finance emails to RSS/Archive.
- Mobile/app hygiene: only install finance/crypto apps that your business has approved; double-check publisher name and reviews, and avoid using personal wallet apps on work devices.
Ask your IT provider
- Do we have phishing-resistant MFA (or strong MFA) on email and admin accounts, and do we alert on impossible travel/sign-in anomalies?
- Are we monitoring for new inbox rules, auto-forwarding and suspicious OAuth/app consents in Microsoft 365/Google Workspace?
- Can we add/strengthen anti-impersonation controls (domain lookalike detection, DMARC alignment reporting, external sender banners) without disrupting business emails?
- What’s our process to quickly contain an account takeover (disable sign-in, revoke sessions/tokens, reset MFA, check sent items and rules)?
Patch watch - only one short paragraph, and only if relevant
If your organisation still hosts an old web forum or community site, note the reporting about public exploit details for a patched vBulletin issue. This is mainly a risk for businesses running their own forum infrastructure—check whether you have any internet-facing forum software at all, and if so ensure the maintainer confirms it’s up to date.
One action today
Send a 3-line notice to finance staff today: no supplier bank-detail changes by email; verify using a known number; escalate any “breach-related reset/payment change” message to IT immediately.
Related Actions On Cyber resource
Actions On Cyber checklist CTA: Supplier payment change verification (anti-invoice fraud) mini-checklist
Sources
- Ernst & Young data breach claimed by ShinyHunters extortion gang (BleepingComputer)
- Coca-Cola confirms data theft in Fairlife ransomware attack (BleepingComputer)
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware (The Hacker News)
- Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin (BleepingComputer)
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.