Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB cyber brief: Microsoft 365 email disruption + fake CAPTCHA ‘ClickFix’ scams

What small and medium-sized businesses should look out for today.

High Monday 31 August 2026, 22:28 UK time
Today’s look-out: Cloud disruption scams and fake ‘CAPTCHA’ command-run phishing

What to look out for today

  • Exchange Online disruption: authentication issues and email delays/failures can affect normal operations and also create cover for scams (“we couldn’t email you, so use this new process”).
  • Fake CAPTCHA / “ClickFix” style prompts: staff are being tricked by realistic web prompts into running actions on their computer (e.g. in Windows Terminal) that give attackers a foothold.
  • Hiring/contractor fraud beyond IT: suspected North Korean-linked job fraud is being reported expanding into healthcare, sales and marketing roles—raising insider and payroll risk for any organisation recruiting remotely.

Why this matters to smaller businesses

SMEs rely heavily on Microsoft 365 and a small number of key SaaS tools. When a major service is unstable, staff improvise (personal email, WhatsApp, new file shares) and fraudsters exploit confusion with “urgent” messages. At the same time, social engineering that persuades someone to run a “fix” can bypass many technical controls. Finally, remote hiring scams can create long-lasting risk (access to customer data, finance systems, and internal comms) even when the role isn’t “technical”.

Warning signs

  • Emails failing or delayed; repeated sign-in prompts; staff reporting they “can’t get into Outlook/Teams” (and then receiving alternative instructions via personal channels).
  • A website suddenly asks users to prove they’re human by opening Terminal/Command Prompt, pasting something, or “running a quick check”.
  • Support-themed messages referencing Cloudflare/CAPTCHA, “security verification”, “quick fix”, or “copy/paste this to continue”.
  • Recruitment red flags: reluctance to do live video, inconsistent identity documents, pressure to start quickly, unusual requests about equipment shipping/addresses, or evasiveness about location.

How attackers may exploit the situation

  • Outage-driven invoicing and payment diversion: criminals claim email is down and push payment changes via phone, SMS, or “new” email addresses.
  • Command-run social engineering: fake CAPTCHA prompts on compromised sites can trick users into performing steps that hand control or access to attackers.
  • Insider access through hiring: fraudulent workers may seek legitimate access to systems, then use it to move data, enable further compromise, or create persistence.

What to do today

  • Reinforce the rule: nobody should ever paste/run commands from a website, email, or chat message to “fix” access.
  • Outage procedure: remind teams which channels are approved when email is unstable (e.g. Teams, phone tree) and what is not allowed (personal email for customer data).
  • Payment change controls: require a call-back to a known number (not one in the email) for bank detail changes or urgent invoice re-issues—especially during service incidents.
  • Hiring checks: for remote hires/contractors (including sales/marketing/admin), use stronger identity verification and a documented onboarding checklist; restrict access until verification is complete.

Ask your IT provider

  • Do we have an agreed process for Microsoft 365 incidents (who checks status, who communicates internally, and which fallback tools are permitted)?
  • Do we have controls to reduce damage from “run this command” scams (e.g. least privilege on endpoints, application controls, logging/alerting for unusual remote tunnels/command activity)?
  • Can you provide a quick report of recent sign-in anomalies and any spikes in failed logins during the Exchange Online issue?
  • What’s our standard for onboarding/offboarding accounts for new starters/contractors, and how quickly can access be revoked if a hire is suspected fraudulent?

Patch watch - only one short paragraph, and only if relevant

No specific patch action is the main issue today. The bigger risk is social engineering (fake CAPTCHA/“ClickFix”) and operational disruption from cloud service instability—focus on user guidance, access controls, and incident-ready processes.

One action today

Send a one-paragraph staff alert: “Never paste or run commands from a website/CAPTCHA or ‘support’ prompt—report it immediately,” and remind everyone that bank detail changes must be verified by call-back to a known number.

Related Actions On Cyber resource

Actions On Cyber: Payment Change & Invoice Fraud Call-Back Checklist

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.