What to look out for today
Three themes SMEs should actively brief staff on and sanity-check with IT today:
- Microsoft 365 phishing designed to bypass two-factor authentication (2FA) by abusing legitimate-looking login flows.
- Fake “Cloudflare CAPTCHA” / “I’m not a robot” pages used as a step in phishing (“ClickFix”-style) and hosted via trusted-looking infrastructure.
- Ongoing attacks compromising Zimbra email servers (organisations running Zimbra themselves or via a hosting provider may be at heightened risk of mail disruption and mailbox compromise).
Why this matters to smaller businesses
- One mailbox or Microsoft 365 account takeover can lead to invoice fraud, payroll diversion, fake supplier bank changes, or the attacker using your account to target customers.
- Email is a dependency: if mailboxes are compromised or disrupted, it can stop approvals, orders, safeguarding comms (schools/charities), and time-critical client work.
- “Trusted” looking pages increase clicks: staff may be more likely to comply when they see familiar CAPTCHA branding or a convincing sign-in journey.
Warning signs
- Unexpected prompts to “complete a CAPTCHA to continue” before viewing a document, invoice, voicemail, or shared file.
- Emails pushing urgency: account locked, password expires today, new voicemail, shared document, missed payment.
- Staff report multiple repeated login prompts or being asked to approve sign-ins they didn’t initiate.
- New email auto-forwarding rules, unusual “sent items”, or replies you didn’t write.
- For Zimbra users/hosts: sudden mailbox errors, webmail behaving oddly, or unexplained admin changes.
How attackers may exploit the situation
- Microsoft 365 credential theft / session capture: attackers aim to defeat 2FA protections by steering users through legitimate-looking flows, then reusing access to log in as the user.
- CAPTCHA as a compliance step: the CAPTCHA page is used to make the victim feel they’re on a reputable site, then guide them into further steps (for example, handing over access or authorising something they shouldn’t).
- Email server compromise (e.g. Zimbra): attackers can read emails, intercept invoices, set forwarding, reset other passwords, and impersonate staff—often without immediate ransomware-style “noise”.
What to do today
- Brief staff in 5 minutes: “CAPTCHA prompts in emails are a red flag—stop and report.”
- Reinforce payment-change controls: any supplier bank detail change must be verified via a known phone number (not the email thread).
- Check Microsoft 365 basics: confirm MFA is enabled for all users, and ensure high-risk sign-in alerts are being monitored.
- Audit email rules: spot-check a few mailboxes (especially finance/admin) for unexpected forwarding rules or suspicious inbox rules.
- If you use Zimbra (directly or via a provider): ask for a status update today on whether your service is affected by the ongoing compromise wave and what monitoring is in place.
Ask your IT provider
- Are you seeing Mirage2FA-style Microsoft 365 phishing attempts against our tenant, and what alerts are you watching (sign-in anomalies, impossible travel, suspicious consent, new forwarding rules)?
- Do we block or warn on newly registered domains and suspicious link redirects in email?
- Can you provide a quick report of new mailbox forwarding rules created in the last 7–14 days (especially for finance, payroll, leadership)?
- If we use Zimbra: who is responsible for the platform (us/host/MSP) and what is the current security posture and monitoring for compromise indicators?
- What is our incident process if a mailbox is taken over (password reset, token revocation, rule cleanup, customer notification, finance checks)?
Patch watch - only one short paragraph, and only if relevant
If your organisation runs Zimbra (or you pay a provider that does), treat this as a live risk: attackers are actively compromising servers in ongoing attacks. Even if patching is “someone else’s job”, SMEs should request written confirmation of the provider’s remediation status and monitoring, because email compromise often leads directly to invoice fraud and data exposure.
One action today
Send a short internal alert today: “If an email link shows a CAPTCHA page or repeated Microsoft sign-in prompts, stop, don’t proceed, and forward it to IT/admin for checking.”
Related Actions On Cyber resource
Actions On Cyber checklist CTA: “Invoice fraud & supplier bank-change verification (call-back process) – print and use for finance/admin.”
Sources
- Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows (The Hacker News)
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages (The Hacker News)
- Hackers breached over 270 Zimbra servers in ongoing attacks (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.