Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB cyber lookout: stolen sessions, RMM phishing, and SaaS disruption

What small and medium-sized businesses should look out for today.

High Thursday 03 September 2026, 17:24 UK time
Today’s look-out: Account takeover from infostealers + RMM phishing + SaaS disruption

What to look out for today

  • Compromised logins showing up in “infostealer logs” (not just passwords, but sometimes active sign-in sessions).
  • Phishing that tries to get you to install or sign into Remote Monitoring & Management (RMM) tools (often framed as IT support, compliance, or urgent admin work).
  • Operational disruption from SaaS outages (AI assistants and related workflows may be unreliable today).
  • Small-business websites at risk where WordPress sites use popular plugins and attackers are actively trying to take over vulnerable sites.

Why this matters to smaller businesses

SMEs are frequently hit through stolen credentials and trusted tools, not “Hollywood hacking”. A single compromised mailbox or cloud account can quickly lead to invoice fraud, payroll diversion attempts, data exposure, and customer-impacting disruption. If an attacker gets an authenticated session (not just a password), they may be able to access services without triggering MFA in the way you’d expect.

Separately, if your staff rely on AI tools for drafting, customer responses, or coding, an outage can create rushed workarounds (copy/pasting sensitive data into alternate tools, using personal accounts, or bypassing normal checks).

Warning signs

  • Unexpected sign-in prompts, password reset emails, or MFA notifications that no one initiated.
  • New “authorised app” or “connected app” approvals in Microsoft 365/Google/other SaaS you don’t recognise.
  • Mailbox rules you didn’t create (e.g., auto-forwarding, moving invoices to RSS/Archive, deleting sent items).
  • Emails/Teams messages urging you to install an “IT tool”, “remote support”, “monitoring agent”, or to sign into an admin portal quickly.
  • Website admin accounts you don’t recognise, or unexpected plugin/theme changes on your WordPress site.
  • Sudden pressure to use alternative AI tools due to outages, especially using personal accounts or unknown platforms.

How attackers may exploit the situation

  • Infostealers: attackers use stolen passwords and/or stolen session tokens to log into email, file storage, CRM, accounting, and payment platforms. From there they may attempt invoice redirection, internal phishing, or data theft.
  • RMM phishing: trick staff into installing or authenticating an RMM tool, giving attackers persistent remote access that can lead to ransomware or business email compromise.
  • Website takeover: automated attacks target widely used WordPress components to gain control of sites (defacement, malicious redirects, or planting malware).
  • SaaS outages: attackers may take advantage of confusion and urgency (e.g., “use this new tool instead”) to push phishing links or data-harvesting forms.

What to do today

  • Tell staff: do not install “support/monitoring” tools from email links. All IT tool installs must come via your normal IT channel/ticket.
  • Prioritise accounts: check admin accounts, finance mailboxes, payroll/HR, and any shared inboxes first for unusual sign-ins and mailbox rules.
  • Reset and revoke: where you suspect compromise, reset passwords and revoke active sessions (log out everywhere) for the affected accounts.
  • Review app access: remove unknown OAuth/connected apps and re-check MFA settings and recovery methods.
  • Website owners: confirm who manages WordPress updates; ensure you have a recent clean backup and that admin access is restricted and monitored.
  • Outage plan: if AI tools are down, use an agreed fallback process. Avoid pasting sensitive client or HR/finance data into random alternative services.

Ask your IT provider

  • Do we have alerts for impossible travel, repeated failed logins, and suspicious sign-ins to Microsoft 365/Google?
  • Can you quickly revoke sessions and investigate mailbox rule changes if an infostealer compromise is suspected?
  • Do we have controls to prevent staff installing unauthorised RMM/remote access tools?
  • What’s our rapid-response process for suspected account takeover in finance (including supplier payment change verification)?
  • For our website: who patches plugins, how quickly, and how do we detect unauthorised admin creation or file changes?

Patch watch - only one short paragraph, and only if relevant

If your business runs a WordPress site (especially using Elementor Pro) or you self-manage software/services like Plex, treat vendor “update now” notices seriously. Active exploitation of common components can turn into website takeover or malware distribution quickly, so confirm ownership of updates (internal, agency, or MSP) and when it will be done.

One action today

Today, have IT review sign-in logs and revoke sessions for any high-risk accounts (admins, finance, payroll) and remind staff that any request to install remote-support/RMM tools must go through your normal IT process.

Related Actions On Cyber resource

CTA: Actions On Cyber checklist — “Account takeover quick response (email & cloud): revoke sessions, remove rogue rules, and lock down finance workflows.”

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.