Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

SMB Cyber Intelligence Brief: ransomware extortion + router compromise risk + “disable security to fix it” tricks

What small and medium-sized businesses should look out for today.

High Monday 31 August 2026, 16:04 UK time
Today’s look-out: Ransomware disruption and supplier/network edge compromise, plus scams that push staff to bypass security

What to look out for today

Three themes to brief staff and IT on today:

  • Ransomware groups publicly claiming data theft and using leak sites to pressure victims into paying.
  • Network edge / router compromise being used for spying and credential theft (especially where routers are managed by an MSP/telecoms provider).
  • Malware disguised as legitimate tools that relies on users being convinced to add it to antivirus exclusions or “allow lists”.

Why this matters to smaller businesses

  • Ransomware is rarely just encryption now—data theft and extortion can create legal, reputational and customer-notification issues even if operations keep running.
  • Routers and network access systems are a single point of failure. If compromised, attackers may intercept traffic, steal credentials, and undermine security monitoring—often without obvious signs to end users.
  • “Just add an exception” is a common turning point in real incidents. Once a user weakens security controls, attackers gain persistence and can move toward email compromise, invoice fraud, or ransomware.

Warning signs

  • Unexpected or urgent requests to disable antivirus, add exclusions, or run “signed/legitimate” software to fix a problem.
  • Unplanned network changes: new remote access paths, unexplained configuration updates, or connectivity behaving oddly (intermittent access, sudden routing/VPN changes).
  • Extortion indicators: unusual emails claiming stolen data, threats to publish files, or references to a “leak site”.
  • Security tooling seems “quiet”: fewer alerts than normal, missing logs, or monitoring gaps reported by your IT provider.

How attackers may exploit the situation

  • Ransomware operators may break in, steal data, then apply pressure via public claims and direct extortion messages—aiming to force rapid payment decisions.
  • Router and authentication infrastructure compromise can be used to capture admin credentials, watch traffic, and reduce your ability to detect what’s happening.
  • Signed or “trust-looking” apps (e.g., utilities/adware bundled as helpful tools) are used to persuade staff to override controls—making endpoint protection less effective.

What to do today

  • Reinforce a simple rule: staff must not add antivirus exclusions, disable protection, or install “fix tools” based on an email/call/chat message—route all such requests through IT.
  • Confirm your backups and recovery plan (what you can restore, how quickly, and who approves a restore). Ensure at least one backup copy is protected from tampering.
  • Check who manages your router/firewall (in-house, MSP, telecoms). Make sure device admin accounts are controlled, monitored and not shared broadly.
  • Prepare for extortion messaging: decide who triages suspicious claims (IT + leadership + legal/insurer as appropriate) so staff don’t engage ad hoc.

Ask your IT provider

  • Which routers/firewalls do you manage for us, and how do you monitor for unusual tunnels/remote access and configuration changes?
  • Do we have central logging for network devices and admin activity, and how quickly would we notice if logging went missing?
  • What controls stop users (or attackers) from adding antivirus exclusions or disabling protections without approval?
  • If we received an extortion email today, what is our first-hour response (isolation steps, evidence preservation, and who contacts the insurer)?

Patch watch - only one short paragraph, and only if relevant

Separately, Microsoft has acknowledged a Windows 11 update issue that can reset mouse settings. It’s not a security alert, but if your IT team uses the August preview updates, be prepared for user support tickets and consider whether preview updates are appropriate on business devices.

One action today

Send a same-day staff note: “Do not disable antivirus or add exclusions/install ‘fix tools’ from emails or calls—forward to IT/helpdesk immediately.”

Related Actions On Cyber resource

Actions On Cyber checklist: Ransomware readiness (backups, first-hour response, and extortion triage)

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.