Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

SMB Cyber Intelligence Brief — Identity & comms platforms in the spotlight

What small and medium-sized businesses should look out for today.

High Friday 21 August 2026, 14:09 UK time
Today’s look-out: Cloud identity takeover and comms-platform targeting (with follow-on phishing)

What to look out for today

Today’s main SME lookout is identity and communications platforms being actively targeted, plus the usual follow-on: phishing, account takeovers, and supplier-style scam messages that exploit uncertainty after security news.

  • Microsoft Entra ID: Microsoft has warned of a maximum-severity issue that has been exploited in attacks.
  • Self-hosted comms: TrueConf Server flaws are being treated as actively exploited (US agencies told to prioritise fixes).
  • Third-party software ripple effects: A breach at a large organisation (SickKids) exposed employee/applicant data via third-party software, highlighting how HR-style data can leak even when “core systems” are unaffected.
  • Malware delivery tricks: New reporting shows attackers abusing FTP server “banners” to deliver Windows malware (a reminder that older admin services and tooling can be a weak link).

Why this matters to smaller businesses

  • Identity is the front door: If an attacker can compromise sign-in/identity controls, they often don’t need to “hack” anything else to get into email, files, finance approvals, and customer data.
  • Comms platforms are high-impact: A compromise of conferencing/chat can quickly lead to internal impersonation, stolen meeting links, or surveillance of sensitive conversations.
  • Third-party incidents create believable scams: When a well-known organisation reports a breach, criminals commonly send “update your details / re-verify payroll / download a form” messages to staff and applicants.

Warning signs

  • Unexpected sign-in prompts, MFA fatigue requests, or “urgent” verification messages for Microsoft 365/Entra-linked accounts.
  • New or unknown admin accounts, new MFA methods added, or changes to conditional access/security settings you didn’t request.
  • Unusual meeting invites, chat messages, or “support” outreach referencing conferencing tools or comms upgrades.
  • Emails/SMS claiming to be from HR/recruitment asking you to re-enter personal details or download “updated application documents”.
  • Unexpected outbound traffic from servers that host legacy services (e.g., FTP) or odd behaviour on a server that “never changes”.

How attackers may exploit the situation

  • Account takeover to access email, then invoice fraud, payroll diversion, or supplier payment-change scams.
  • Abuse of comms platforms to impersonate colleagues/IT support and push links or “security tools”.
  • Targeting externally reachable servers (especially self-hosted communications or older admin services) to gain a foothold and deploy remote access tooling.
  • Data-breach themed phishing using real brand names and plausible context (“you were affected”, “download your report”, “confirm your details”).

What to do today

  • Tell staff what’s happening: a short internal note: “expect fake Microsoft/security and HR-style messages; do not approve unexpected MFA prompts; report anything urgent/odd.”
  • Check admin access: confirm who has Entra/M365 admin roles, review recent changes to roles/MFA methods, and remove stale accounts.
  • Review sign-in alerts: look for unfamiliar locations/devices, repeated failed logins, and sign-ins outside working patterns—especially for finance and administrators.
  • Verify internet-facing services: if you run self-hosted comms (e.g., TrueConf) or legacy services like FTP, confirm they are still required and monitored.
  • Reinforce payment controls: insist on call-back verification for any change of bank details, even if it appears to come from a known email thread.

Ask your IT provider

  • Are we affected by the reported Entra ID exploited issue, and what mitigations/updates have been applied or verified?
  • Do we have any internet-exposed communications servers (including self-hosted conferencing), and are they monitored with alerting?
  • What is our process to detect and respond to new admin accounts, new MFA methods, and suspicious mailbox rules?
  • Can you provide a weekly report of high-risk sign-ins and privileged role changes?
  • Do we still need services like FTP; if yes, how are they logged and protected?

Patch watch - only one short paragraph, and only if relevant

Some of today’s reporting references actively exploited issues in widely used platforms (notably Microsoft Entra ID and a self-hosted communications product). If you rely on these, treat this as an urgent prompt to confirm your provider has applied vendor fixes/mitigations and validated sign-in and admin-change monitoring.

One action today

Send a same-day staff warning: “Do not approve unexpected MFA prompts or ‘account re-verify’ requests; report suspicious Microsoft/HR/security messages immediately.”

Related Actions On Cyber resource

CTA: Use the Actions On Cyber ‘Payment change / invoice fraud call-back checklist’ for finance teams

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.