Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB cyber lookout: trusted-link phishing and “Apple Support” voice AI scams

What small and medium-sized businesses should look out for today.

High Wednesday 26 August 2026, 08:58 UK time
Today’s look-out: Phishing themes: trusted hosting links + AI voice calls requesting codes

What to look out for today

Two phishing themes are getting attention and are very relevant to smaller organisations:

  • “Trusted link” phishing where malicious pages are hosted on legitimate platforms (reported as abuse of npm mirrors) and used to show convincing “Cloudflare CAPTCHA” style pages that push people on to attacker-controlled sites.
  • AI voice calls pretending to be Apple Support, pressuring people to share device passcodes and 2FA codes (linked to stolen-device scenarios, but the same approach can be adapted to business accounts and helpdesks).

Why this matters to smaller businesses

SMEs, schools and charities often rely on quick judgement calls by non-technical staff. When phishing pages are hosted on a well-known domain (or a “normal looking” package/mirror link), and when calls sound professional and urgent, it becomes harder to spot scams. A single code or login can lead to email takeover, invoice fraud, payroll changes, or wider account compromise.

Warning signs

  • Links that look “reputable” but lead to an unexpected login step, CAPTCHA page, or a sudden redirect to another site.
  • Any call claiming to be Apple/IT/support that asks for a passcode, verification code, or to “approve” a sign-in you didn’t start.
  • Unexpected security prompts right after clicking a link in an email, chat message, or social post.
  • Pressure tactics: “You must act now or your device/account will be locked / your data will be deleted.”
  • Staff reporting a “CAPTCHA” that appears out of context (e.g., after clicking an invoice, shared document, or HR-related link).

How attackers may exploit the situation

  • Hosting abuse for credibility: attackers place malicious redirect pages on legitimate hosting/mirrors so the link appears safer and is more likely to pass basic scrutiny.
  • Credential and session capture: the “CAPTCHA” or follow-on site is used to push users to a fake login, capture credentials, or harvest one-time codes.
  • Voice social engineering: AI voice agents can scale phone-based phishing, targeting staff who handle devices, email access, payments, or admin tasks.

What to do today

  • Tell staff one simple rule: never share one-time codes or passcodes with anyone on a call. If in doubt, hang up and call back using a known, official number.
  • Reinforce safe link handling: if a link leads to an unexpected CAPTCHA/login, stop and verify via a separate route (e.g., go to the supplier site directly, or check with the sender through a known channel).
  • Update your internal “phone request” process: any request to change access, reset MFA, or approve sign-ins should require a second check (another person or a known internal callback).
  • Make reporting easy: remind staff how to report suspicious emails, links and calls quickly (even if they’re not sure).

Ask your IT provider

  • Do we have controls to reduce account takeover impact (e.g., strong MFA policies, conditional access, alerts for unusual logins)?
  • Can we block or warn on known phishing redirect patterns, and do we have link-scanning / safe browsing protections in place?
  • What’s our process when a user says they entered credentials or a code—what gets reset first (passwords, sessions, MFA tokens), and how fast?
  • Do we have a clear procedure for payment/bank detail change verification in case email accounts are compromised?

Patch watch - only one short paragraph, and only if relevant

No major patch-driven SME action is the lead story today. However, keep an eye on router/edge device safety in general—reports of unpatched router issues are a reminder to ensure business internet equipment is managed, updated where possible, and not exposing internal services unexpectedly.

One action today

Send a same-day staff note: “Never share passcodes or one-time verification codes on calls; if a link opens an unexpected CAPTCHA/login, stop and verify via a known route.”

Related Actions On Cyber resource

CTA: Use the Actions On Cyber ‘Phishing & Suspicious Call Handling’ mini-checklist (reporting steps + verification script).

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.