Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB Cyber Brief: payment fraud, ‘recruiter’ phishing, and cloud/API key theft

What small and medium-sized businesses should look out for today.

High Tuesday 01 September 2026, 20:23 UK time
Today’s look-out: Payment diversion and credential/key theft via social engineering and exploited SaaS/dev tooling

What to look out for today

Three themes SMEs should actively watch for today:

  • Payment fraud targeting banking/payment workflows (especially where online banking tools, payment files, or finance PCs are involved).
  • Recruiter-themed lures (fake job approaches and “coding tests”) used to get staff to run malware on Windows, macOS, or Linux.
  • Cloud/API key theft via exploited AI tooling — attackers are reported exploiting a flaw in an AI app framework to steal credentials, tokens and keys (including OpenAI and AWS keys).

Why this matters to smaller businesses

  • Payment fraud can cause immediate financial loss and operational disruption (supplier payments, payroll runs, customer refunds).
  • Recruiter scams don’t only affect job-seekers: they can target developers, IT admins, engineers, and contractors—anyone likely to open a “test” or project file.
  • Stolen API keys/tokens can lead to cloud bills spiking, data access, service outages, or attackers using your accounts to attack others—creating reputational and compliance problems.

Warning signs

  • Finance team reports: new payees, unusual refunds/chargebacks, repeated “failed” payments that need re-trying, or unexpected prompts to install/update banking software.
  • Staff receive unsolicited approaches offering work, asking to complete a “coding test”, or requesting you run a tool/script locally “to prove skills”.
  • Unusual logins or new API keys created in cloud/AI platforms; alerts about tokens generated, permissions changed, or sudden usage spikes.
  • Unexpected MFA prompts or password reset emails for cloud accounts.

How attackers may exploit the situation

  • Payment manipulation: compromise a finance workstation or intercept payment processes to trigger fraudulent transfers.
  • Social engineering: impersonate recruiters to persuade targets to run “tests” that install remote access malware.
  • Key harvesting: exploit weaknesses in AI/dev tooling or exposed services to steal credentials, tokens and cloud keys—then pivot into your SaaS and cloud environments.

What to do today

  • Finance controls: enforce a callback/verification step for any new beneficiary or bank detail change (use known numbers, not email reply details).
  • Staff comms: send a short alert: “Do not run coding tests/tools from unsolicited recruiters; report to IT.”
  • Key hygiene: review who can create/rotate API keys; rotate any keys that are old, shared, or stored in documents/chats; ensure MFA is on for cloud and AI platforms.
  • Monitoring: check for unusual cloud usage/cost spikes and new token/key creation events.

Ask your IT provider

  • Do we have a clear process to detect and respond to suspected payment fraud (including isolating a finance PC quickly)?
  • What controls stop staff from running untrusted code on company devices (especially developers/admins)?
  • How are cloud/API keys managed (inventory, rotation, least privilege, alerts for new key creation)?
  • Do we have alerts for unusual SaaS logins, MFA fatigue attempts, and abnormal usage/cost patterns?

Patch watch - only one short paragraph, and only if relevant

Attackers are reported exploiting a flaw in the Langflow AI application framework to steal cloud and AI service keys. If your business (or an IT supplier) uses Langflow or similar self-hosted AI tooling, treat it as urgent to confirm exposure, apply vendor fixes/mitigations, and rotate any potentially exposed keys and tokens.

One action today

Send a same-day internal note to finance and technical staff: verify any payment changes via callback, and do not run recruiter “coding tests” or tools—report them to IT; then review and rotate any shared/old cloud/API keys.

Related Actions On Cyber resource

Actions On Cyber checklist: Payment change verification (anti-invoice fraud) + Cloud account and API key hygiene quick-check

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.