What to look out for today
Any situation where staff use the same email address, phone number, or other identifiers across lots of websites and services. When one of those services leaks data or gets abused, it becomes easier for criminals to:
- Target your staff with more convincing phishing and invoice/payment scams
- Attempt account takeovers on business email and SaaS tools ("password spraying" and reset attempts)
- Link personal and work identities, increasing doxxing, harassment, and social engineering risk
Why this matters to smaller businesses
SMEs typically rely on a small set of people (owners, office managers, finance staff) who have access to email, banking, payroll, and cloud services. If those individuals become easier to profile and target, fraud attempts become more believable and harder to spot.
Warning signs
- A sudden spike in “password reset” emails or SMS messages you didn’t request
- More spam that uses correct details (your role, supplier names, recent purchases, or a real phone number)
- New sign-ins or sign-in alerts from unfamiliar locations/devices
- Calls/messages that reference personal details to pressure quick action ("I know you handle payments")
How attackers may exploit the situation
- Credential and reset abuse: using leaked or guessed details to trigger password resets, then tricking staff into sharing codes or approving prompts.
- Correlation attacks: matching the same email/phone across multiple services to build a profile and craft tailored phishing.
- Supplier-style fraud: using learned details to impersonate a supplier or colleague and request urgent payment or bank detail changes.
What to do today
- Identify which roles are “high-risk targets” (owner, finance, HR, IT admin) and ensure they use separate addresses/aliases for low-trust sign-ups (marketing, webinars, downloads, SaaS trials).
- Turn on (or verify) multi-factor authentication for email and key SaaS platforms, and ensure sign-in alerts go to more than one person where possible.
- Remind staff: never share one-time codes, and treat unexpected reset prompts as suspicious.
- Check that your payment process includes an out-of-band callback to a known number before changing bank details.
Ask your IT provider
- Can we set up and manage email aliases or separate mailboxes for risky sign-ups and public-facing contact forms?
- Do we have sign-in alerting and central logging for Microsoft 365/Google Workspace and critical SaaS?
- Which accounts are our most targeted, and do they have stronger controls (MFA method choice, conditional access, admin separation)?
- What’s our process for responding to account takeover attempts (lockout, credential reset, session revocation)?
Patch watch - only one short paragraph, and only if relevant
No specific patch-driven SME action from today’s items. Keep routine updates running, but today’s main focus is reducing how easily attackers can correlate and target staff identities across services.
One action today
Create a separate “sign-up” email alias (or mailbox) for each high-risk staff role (owner/finance/HR) and stop using their primary work address for low-trust registrations and downloads.
Related Actions On Cyber resource
Actions On Cyber checklist: “Payment change and invoice fraud controls (call-back and verification steps)”
Sources
- Is Online Privacy Possible? How Digital Identities Can Help (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.