What to look out for today
Three themes SMEs should watch for today:
- “Fix this now” web pages and messages that talk a user into carrying out steps on their own device (a common, repeatable social-engineering pattern often described as ClickFix).
- Payment and banking manipulation where criminals aim to change payment details or trigger fraudulent transfers by abusing trusted access and business processes.
- SaaS/AI dependency risk: service disruption (e.g., ChatGPT availability issues) and API key misuse leading to unexpected bills/consumption of paid credits.
Why this matters to smaller businesses
- Finance and admin teams are prime targets because a single approved payment or updated bank detail can cause immediate loss.
- Non-technical staff can be manipulated into doing the attacker’s work if the instructions look like routine troubleshooting or “security verification”.
- Cloud and AI tools are now business-critical for marketing, customer service, HR and ops. Outages and account misuse can disrupt work or create surprise costs.
Warning signs
- A web page, email or chat message claims you must “prove you’re not a robot” or “fix an issue” and then asks you to follow steps on your computer rather than simply logging in normally.
- Any instruction that involves copying/pasting text, running a “quick command”, installing a “support tool”, or changing security settings to continue.
- Unexpected payment change requests (especially urgent, confidential, or “I’m in a meeting” style messages), or suppliers requesting new bank details without a known process.
- Sudden spikes in AI usage/credits, new API tokens created, or alerts about usage you don’t recognise.
- Staff reporting that an AI/SaaS tool is down and trying to “find an alternative login link” via search results or unofficial pages.
How attackers may exploit the situation
- Step-by-step deception: criminals use convincing pages or prompts to guide a user into taking actions that effectively hand over access (without needing advanced hacking).
- Process abuse: they aim for finance workflows—changing payee details, intercepting invoices, or pushing through transfers by impersonating managers or suppliers.
- Trusted tokens and keys: attackers target API keys and service credentials because they can be used quietly to consume paid resources or access systems.
- Outage opportunism: when popular tools are disrupted, scammers often piggyback with fake “status updates”, “support calls”, or “recovery steps”.
What to do today
- Send a 2-minute staff warning: “No copy/paste ‘fix’ steps. No installing tools. If a page tells you to run steps to ‘verify’ or ‘repair’, stop and ask IT.”
- Reconfirm payment-change controls: bank detail changes must be verified using a known phone number (not the one in the email) and ideally require a second approver.
- Lock down AI/SaaS access: enable MFA where available, restrict who can create API keys, and set spending/usage alerts on AI platforms.
- Prepare for SaaS disruption: agree a simple fallback plan for teams (what to do if a key tool is unavailable) so staff don’t search for unofficial “workarounds”.
Ask your IT provider
- Do we have controls to stop users running unapproved software or remote-access tools (and do we alert on it)?
- How are we protecting email accounts from takeover (MFA, risky sign-in alerts, mailbox forwarding rules monitoring)?
- Can we detect and block known “tech support / fix-it” style social-engineering patterns in web/email filtering?
- Which SaaS/AI systems do we rely on, and do we have MFA, role-based access, and usage/spend alerts enabled?
- Do we have a written process for supplier bank-detail changes and invoice verification, and can you help us test it?
Patch watch - only one short paragraph, and only if relevant
Some reports today highlight active exploitation of high-impact software flaws in widely used platforms. For SMEs, the practical step is to ask your IT provider to confirm whether any internet-facing business systems or hosted apps you rely on use affected components, and to prioritise updates where the vendor or managed service flags urgent risk.
One action today
Send a same-day staff note: “If any webpage/email tells you to copy/paste steps to ‘fix’ or ‘verify’ something on your computer, stop and report it—do not follow the instructions.”
Related Actions On Cyber resource
Actions On Cyber checklist: Prevent invoice fraud and verify supplier bank detail changes
Sources
- Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones (The Hacker News)
- Financially Motivated Threat Actor BREEZE COMET Targets Brazil (Google Threat Intelligence)
- OpenAI confirms ChatGPT outage as users report errors (BleepingComputer)
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 (The Hacker News)
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.