What to look out for today
Today’s theme is attackers going after identity checks and account recovery (not just passwords), plus the knock-on effect of public breach reports: they can be used to make very believable impersonation emails and calls.
- Account recovery / verification fraud: criminals try to beat or bypass the checks used to reset access to email, payroll, banking, Microsoft/Google accounts and SaaS tools.
- “Fake worker” and onboarding abuse: attempts to get a real account created by passing HR or contractor checks, then using that access for fraud or data theft.
- Breach-driven impersonation: public news of a breach can trigger follow-on scams pretending to be the affected company, their IT helpdesk, or partners.
- Stronger WhatsApp account security is rolling out: multiple passkeys and stronger two-step verification options are becoming available — worth enabling for staff who use WhatsApp for work.
Why this matters to smaller businesses
SMEs often rely on a small number of people and a few key SaaS accounts (email, payroll, banking, booking systems, CRM). If an attacker can convince someone to reset access or can get an account created during onboarding, they can move quickly into payment diversion, invoice fraud, payroll manipulation or data theft — often without “hacking” in the traditional sense.
Separately, when any organisation reports stolen data, criminals commonly use the news to run impersonation campaigns (e.g. “we’re investigating the incident”, “download this report”, “reset your password here”), targeting customers, suppliers and staff.
Warning signs
- Unexpected “reset your password” / “account recovery” emails or MFA prompts (especially outside working hours).
- A caller claiming to be IT/support who pressures for one-time codes, approval prompts, or a quick “verification” step.
- HR or finance receiving unusually polished applications, urgent onboarding requests, or reluctance to join video calls / provide normal verification.
- Requests to change bank details or payment routes that lean on identity proof (“we’ve re-verified our account”) rather than normal supplier controls.
- Staff using WhatsApp for work without two-step verification/passkeys enabled.
How attackers may exploit the situation
- Social engineering the recovery process: attackers exploit weak helpdesk or self-service recovery steps to take over email/SaaS accounts.
- Creating “legit” access: rather than breaking in, they try to pass as a contractor/employee so the business creates the account for them.
- Impersonation off the back of breach headlines: using the breach as a pretext to trick people into clicking links, sharing data, or paying fake invoices.
- Messaging app takeovers: if WhatsApp accounts are taken over, attackers can impersonate staff, request urgent payments, or harvest contacts.
What to do today
- Lock down account recovery: review who can reset email/Microsoft 365/Google/admin accounts, and require a second approver for admin resets.
- Re-brief staff (15 minutes): no one-time codes, no approving unexpected login prompts, and always verify payment changes out-of-band.
- Strengthen WhatsApp for work users: enable stronger two-step verification and passkeys where available, especially for directors, finance and customer-facing teams.
- Review onboarding controls: ensure HR/line managers have a clear checklist for identity verification and that access is least-privilege on day one.
- Test incident response basics: confirm you can quickly disable accounts, reset sessions, and isolate devices if a takeover is suspected.
Ask your IT provider
- How do we protect and monitor account recovery for Microsoft 365/Google and key SaaS tools (who can reset what, and is it logged and alerted)?
- Do we have alerts for “suspicious” events like mass mailbox rule changes, new forwarding rules, or unusual admin activity?
- What’s our process to rapidly revoke access if a staff WhatsApp/email account is compromised (including VIP accounts)?
- Can we run a quick tabletop exercise based on CISA’s red-team lessons: detection, containment, and how fast we can isolate affected systems?
Patch watch - only one short paragraph, and only if relevant
No broad patch action is the main story today. However, if your business uses ISP-supplied or third-party routers (including for small sites or temporary offices), ask your IT support to confirm they can be centrally managed/updated and that remote exposure risks are being tracked and reduced.
One action today
Send a same-day reminder: staff must not share one-time codes or approve unexpected login prompts, and any payment/bank-detail change must be verified via a known phone number (not the one in the email/message).
Related Actions On Cyber resource
Actions On Cyber checklist: Payment change & invoice fraud verification (call-back and dual-approval)
Sources
- Hospital operator Nutex Health says data stolen in cyberattack (BleepingComputer)
- From Fake Workers to Account Recovery: The Growing Identity Verification Risk (BleepingComputer)
- A Tale of Two SOCs: Insights From Two Red Team Assessments (CISA Cybersecurity Advisories)
- WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android (The Hacker News)
- WhatsApp adds stronger two-step verification, multiple passkeys (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.