Filed under: Cybersecurity — Data Protection — August 2026
What happened
RingCentral, the phone and messaging platform used by more than 600,000 businesses, has confirmed that an extortion group called ShinyHunters broke in through a social-engineering attack in July and stole account data. This week that breach was confirmed to affect 1.6 million accounts, with names, email addresses, phone numbers, and physical addresses exposed. RingCentral refused to pay, and the group leaked a large batch of the stolen files publicly. Core calling and messaging service was not disrupted.
Why it matters to your business
If your business uses RingCentral for phones or voicemail, your account details may be in this leak — and we already flagged a phishing kit last week that impersonates RingCentral voicemail notifications to steal Microsoft 365 logins. That campaign just got more convincing: scammers now have real names, numbers, and addresses to make follow-up phishing calls or emails feel legitimate. Anyone whose contact info was exposed is a more attractive target for impersonation scams built around this breach.
What to do this week
Check whether your business email shows up at haveibeenpwned.com, change your RingCentral account password, and turn on multi-factor authentication under the RingCentral admin portal (Settings > Security > Multi-Factor Authentication) if it isn’t already required. Tell staff that any unexpected “RingCentral security alert” email, text, or phone call this month deserves extra scrutiny — verify through the official app or website rather than clicking a link or calling a number provided in the message. Watch for spear-phishing that references your real name, phone number, or address to seem trustworthy.
The bigger picture
A breach at a vendor you trust doesn’t stay contained to that vendor — stolen contact details become raw material for the next phishing campaign aimed at you and your customers. — RingCentral data breach exposed info of 1.6 million accounts
Want help checking if your team’s accounts show up in a breach like this? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Phishing — August 2026
What happened
Security researchers presenting at Black Hat USA showed a new attack technique that hides malicious HTML and CSS inside an email so it breaks out of its normal boundaries and messes with the mail program’s own interface. In one demonstrated chain against Outlook, the trick pops up a fake Microsoft sign-in box that looks like it belongs to the app itself and captures whatever password the reader types. A similar trick against Gmail was used to quietly send data out to an attacker’s server. This is proof-of-concept research only — the researchers found no evidence it has been used in real attacks yet, but the underlying flaws in Outlook and Gmail were still unpatched as of the August 6, 2026 publication date.
Why it matters to your business
Almost every Phoenix small business runs on Outlook, Gmail, or both, and this attack needs nothing more than the victim opening an email — no attachment, no link click required to start. Because the fake login box appears to come from inside a program employees already trust, it’s harder to spot than a typical phishing email, and it specifically targets the Microsoft 365 and Google Workspace credentials that unlock everything else in your business.
What to do this week
Make sure Outlook (desktop and web) and Chrome/Edge are set to auto-update, since fixes from Microsoft and Google will roll out as patches rather than a single big announcement. Remind staff that Microsoft 365 and Google will never ask for a password inside a pop-up that appears while simply reading an email — if a sign-in prompt shows up unexpectedly while previewing a message, close it and log in directly at office.com or google.com instead. If you haven’t already, turn on multi-factor authentication for every Microsoft 365 and Google Workspace account; it won’t stop every version of this attack, but it blocks the plain password theft variant cold.
The bigger picture
This is a reminder that browser-based email interfaces are their own attack surface, not just the messages inside them — the same category of trick showed up in this year’s Ubiquiti and hotel Wi-Fi login-hijack stories. — New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Not sure if your team would spot a fake login prompt? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Phishing — August 2026
What happened
Researchers caught a commercial phishing kit called “Greatness” — sold for $289 a month on Telegram — running a campaign that spoofs RingCentral voicemail and performance-review notification emails. The messages fail standard email authentication checks but still land in inboxes because RingCentral is on many companies’ trusted-sender allow lists, and the email itself falsely claims to be “verified” by that same list. Clicking the button routes victims through a fake Microsoft sign-in that either captures an already-approved login session or talks them into approving a “device code” sign-in — either way, the attacker ends up with a working session that never had to beat a password or MFA prompt. Researchers found stolen sessions still logging in successfully more than two weeks later.
Why it matters to your business
If your business uses RingCentral for phones or voicemail — common among Phoenix small businesses — or has simply allow-listed it in your email filters, this campaign is built to slip past your spam protection entirely. Once an attacker has a live session in someone’s mailbox, they can read invoices and client files, redirect payments, and send convincing messages to your customers and vendors as if they came from your own staff. Because the kit is sold to anyone with $289, expect copies of this trick wearing other trusted brand names next.
What to do this week
In the Microsoft 365 Defender portal (security.microsoft.com), go to Email & collaboration > Policies & rules > Threat policies > Anti-spam policies and check for any “allowed sender/domain” entries for RingCentral or other vendors that skip standard filtering — tighten or remove blanket allow rules like that. In the Microsoft Entra admin center (entra.microsoft.com), go to Protection > Conditional Access and, if you haven’t already, restrict the “device code” authentication flow to only the accounts that genuinely need it. Tell staff plainly: a “verified sender” banner inside an email proves nothing, and no one should approve a device sign-in code they didn’t personally request. Spot-check Entra sign-in logs for sessions from unfamiliar locations that have stayed active for days.
The bigger picture
Phishing kits keep getting better at hiding behind trusted brand names to slip past technical filters, which makes a skeptical, trained employee your last and most reliable line of defense. — Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back
Not sure your email filters would catch a trick like this? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Phishing — July 2026
What happened
Security researchers at MailGuard caught a new phishing campaign impersonating Intuit QuickBooks, spotted July 29, 2026. The email looks like a routine payment confirmation — subject line “Payment Received — Invoice #INV-xxxx Has Been Paid” — complete with a fake transaction ID, payment date, and a “View Receipt” button. Clicking it leads to a convincing fake QuickBooks login page that harvests your email and password, then shows a fake “Please wait…” screen so you don’t immediately realize anything went wrong.
Why it matters to your business
QuickBooks (or similar accounting software) sits at the center of most small businesses’ financial life, so an email that looks like a payment notification is exactly the kind of thing a busy owner or bookkeeper clicks without a second thought. Once attackers have those login credentials, they can see real invoices and client billing details, redirect future payments, or use the account to send convincing follow-up scams to your customers or vendors. The senders behind this campaign are using rotating, randomized email addresses, so blocking one sender won’t stop the next wave.
What to do this week
Tell anyone who handles invoicing or bookkeeping: never click a “View Receipt” or “View Invoice” button in an email — instead, log into QuickBooks directly (typing the address yourself or using your saved bookmark) and check payment status there. Hover over any “payment received” link before clicking to see the real destination domain — legitimate QuickBooks emails link to intuit.com or quickbooks.com, not a random business or personal domain. If your accounting staff use QuickBooks Online, turn on multi-factor authentication for it now if it isn’t already on (Settings gear icon > Account and Settings > Security).
The bigger picture
Fake payment and invoice emails targeting small business finance staff are a recurring, evergreen scam because they work — the fix isn’t new software, it’s making “log in directly, don’t click the link” a habit for anyone touching money in your business. — QuickBooks Payment Confirmation Phishing Campaign Targets Business Users
Want your bookkeeping team trained to spot these before they click? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity — Phishing — July 2026
What happened
Researchers at ReliaQuest found attackers breaking into the Wi-Fi gateway devices at hotels and conference centers — across multiple U.S. cities plus India and Saudi Arabia — and quietly changing their DNS settings. Guests trying to sign into Microsoft 365 get silently redirected to convincing fake login pages (domains like m365-owa[.]com and ms365-live[.]com). In some cases the attackers go a step further and abuse a legitimate Microsoft sign-in feature called “device code” authentication, tricking the victim into approving what looks like a normal sign-in — which hands the attacker a live, already-approved session. No password is stolen and MFA is never actually challenged, because the attacker’s session was authorized by the victim directly.
Why it matters to your business
Any employee who checks email or OneDrive on hotel or conference Wi-Fi during a business trip is a potential target — the campaign has been hitting financial, legal, professional-services, healthcare, and retail firms without much pattern to who gets picked. A compromised mailbox means an attacker can read invoices, client files, and banking details, and send messages that look like they came from your own staff. This is squarely a summer-travel-season risk for any Phoenix business with people out at conferences, client visits, or trade shows.
What to do this week
Tell traveling staff to turn on a full-tunnel VPN before opening any browser or email app on hotel or conference Wi-Fi — never trust the network itself. In the Microsoft Entra admin center (entra.microsoft.com), go to Protection > Conditional Access > Policies > New policy, and under Conditions > Authentication flows, select “Device code flow” and set the grant to Block access unless a specific user genuinely needs it (e.g., certain IoT or CLI sign-ins). Also remind employees plainly: never approve a device sign-in code or MFA prompt unless you personally just typed it in on that exact device — if a prompt shows up out of nowhere, deny it and tell IT.
The bigger picture
This is another reminder that MFA alone isn’t the finish line — attackers are increasingly targeting the sign-in flow itself rather than the password. Locking down which authentication methods are even allowed matters as much as requiring MFA in the first place. — Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Got staff traveling for business this summer? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity · Social Engineering · July 2026
What happened
Security researchers at Palo Alto Networks’ Unit 42 uncovered an active campaign in which criminals pose as your own IT support over Microsoft Teams. It starts with a phishing email — often an “Employee Survey” with a PDF attached — followed minutes later by a Teams voice call from an outside account claiming to be a “System Administrator.” The caller talks the employee into installing a legitimate remote-control tool like AnyDesk or HopToDesk, then uses that access to plant malware called EtherRAT that hands the attacker full control of the computer. This is happening in the wild right now, and researchers found the crooks are already on their ninth version of the installer.
Why it matters to your business
For a Phoenix small business, Teams and Microsoft 365 are everyday tools, and a friendly “IT is calling to fix something” feels completely normal — especially when there’s no in-house IT desk to check against. One employee granting remote access gives a stranger the keys to that machine: saved passwords, email, QuickBooks, client files, and a foothold to spread across your network. Because AnyDesk and HopToDesk are legitimate, widely-used programs, your antivirus usually won’t flag the initial break-in. The endgame is data theft, wire-transfer fraud, or ransomware.
What to do this week
Set one firm rule with your team: real IT never cold-calls to install software or take remote control — if someone does, hang up and call back on a number you already trust. In Teams, limit who can reach your staff from outside: open the Teams admin center (admin.teams.microsoft.com) → Users → External access, and block or tightly restrict unknown external domains and unmanaged Teams accounts. Make sure remote-control apps like AnyDesk, HopToDesk, TeamViewer, and Windows Quick Assist are only installed and used by your actual IT provider, and remove any your team doesn’t recognize. Finally, treat unexpected “Employee Survey” emails with PDF attachments as suspicious and report them.
The bigger picture
Attackers have shifted from breaking in to being invited in — the fastest route onto your network is now a convincing phone call, not a software flaw. Teaching your team to pause and verify before granting access is the control that stops this cold. → Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back
Want help locking down Teams and remote-access tools before a fake “IT” call gets through? Book a free consult — https://micro1tech.com/contact/
Filed under: Cybersecurity • Phishing • July 2026
What happened
Since April 2026, a criminal crew that researchers track as “Pink” has been calling employees at small and mid-sized companies, posing as Microsoft or internal IT and claiming a “security upgrade” is required. On the phone, they walk the victim through a fake Microsoft 365 login and passkey-enrollment page in real time, capture the password and the MFA approval, sign in to the real account, then quietly register their own passkey so they keep access even after the victim changes their password. There is no software bug here — the attackers simply abuse the legitimate passkey feature Microsoft turned on in May. Security firm Okta detailed the campaign on July 8, 2026.
Why it matters to your business
Passkeys and multi-factor authentication are exactly what we tell every client to turn on — and this attack is built to defeat both by fooling a person on the phone instead of breaking any software. Once the crooks plant their own passkey, they own that mailbox and can silently read and download everything in SharePoint and OneDrive: your invoices, client records, tax documents, and banking details. For a Phoenix small business, one convincing call to a receptionist or bookkeeper can turn into wire fraud or a reportable data breach.
What to do this week
Tell every employee plainly: MicroOne (or your IT provider) will never phone you and walk you through adding a passkey or approving an MFA prompt — if you get that call, hang up and call us back on a number you already have. In the Entra admin center, review each user’s registered sign-in methods (Users > select the user > Authentication methods) and remove any passkey or authenticator you don’t recognize. Then tighten who can enroll: Entra ID > Security > Authentication methods > Passkey (FIDO2), and restrict registration to trusted devices. Finally, turn on a Conditional Access rule that blocks sign-ins from countries you don’t do business in.
The bigger picture
The lock on your accounts is only as strong as the person who can be talked into opening it, and attackers have simply moved from email to the phone. Coaching your team to recognize the pitch is now as important as any software setting. → Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back
Not sure who could add a passkey to your Microsoft 365 accounts right now? Book a free consult → https://micro1tech.com/contact/
Filed under: Cybersecurity · Ransomware · July 2026
What happened
Security researchers are tracking an active phishing campaign in which criminals pose as Interpol’s cybercrime unit. The emails claim your company is under investigation and link to a password-protected Proton Drive archive that supposedly holds “video evidence.” The file inside is really a program disguised as a video — opening it installs custom-built ransomware that encrypts your files and demands payment. Businesses across the U.S., Europe, Asia, and the Middle East have already been hit, spanning legal, medical, finance, media, and other everyday industries.
Why it matters to your business
This campaign is aimed squarely at small businesses without a dedicated IT or security team — exactly the kind of Phoenix companies most at risk. A “law enforcement is investigating you” email is engineered to make a busy owner or bookkeeper panic and click before thinking. There is no fixed ransom: the attackers size up your business only after they have locked your files, so even a small firm can face a painful demand — on top of downtime that stops billing, payroll, and QuickBooks cold.
What to do this week
Treat any unsolicited “law enforcement” email as a scam — real agencies don’t email you a Proton Drive link and a password. Turn on file extensions in Windows (File Explorer → View → Show → File name extensions) so a file named “evidence.mp4.exe” gives itself away. Never open password-protected archives from outside your company, and never run a file that asks you to “enable” or “unzip and open” it. Confirm your backups are running and kept offline or in a separate cloud account, and that MFA is on for email and Microsoft 365 or Google Workspace. Finally, give the people who handle email and invoices a quick heads-up that this exact scam is circulating.
The bigger picture
Ransomware crews keep leaning on fear and urgency because it works far better than any technical exploit, and once files are encrypted, paying rarely gets everything back cleanly. The only dependable “recovery” is not getting hit in the first place — layered email filtering, tested backups, and trained staff. → Why the Only True Recovery from Ransomware Is Prevention
Would your backups actually survive a ransomware hit — or just look like they would? Book a free consult → https://micro1tech.com/contact/
Filed under: Cybersecurity · Phishing · July 2026
What happened
Attackers have refined a trick called “ConsentFix,” an evolution of the “ClickFix” scam, that steals Microsoft 365 accounts without ever grabbing a password. The victim gets a real-looking Microsoft sign-in screen and is coached to drag a small “localhost” link into their browser, which quietly hands the attacker a live session token. Because the token is already an approved, signed-in session, it sails right past the account password and multi-factor authentication (MFA). Step-by-step instructions, working code, and video tutorials for this attack were posted to Russian cybercrime forums back in March, so it is no longer limited to skilled hackers.
Why it matters to your business
For most Phoenix small businesses, the Microsoft 365 mailbox is the crown jewels — it holds invoices, banking details, client files, and the password-reset links for everything else. Attackers scout targets on LinkedIn first, then send a tailored lure through trusted services like Dropbox or DocSend, so the message looks routine. One employee dragging one link can give a stranger full access to email, and MFA won’t save you because it was never challenged. From there it’s a short step to fake invoices, wire-transfer fraud, and messages sent to your clients in your own name.
What to do this week
Lock down who can approve apps: in the Microsoft Entra admin center (entra.microsoft.com), go to Identity → Applications → Enterprise applications → Consent and permissions → User consent settings, and set it to “Do not allow user consent” (or allow only verified publishers with low-impact permissions). Turn on the admin consent workflow on that same screen so approval requests route to you instead. Then tell your team the plain rule: Microsoft never asks you to drag or paste a link into your browser bar to log in — if a sign-in prompt does, stop and report it. Finally, in the Entra sign-in logs, spot-check for logins from unexpected cities or countries over the past two weeks.
The bigger picture
MFA is essential, but it is no longer a finish line — today’s attacks skip the password fight entirely and go after the human and the session token. Training your team to recognize the lure is now just as important as the technical controls behind it. → Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back
Not sure whether your Microsoft 365 is set up to block this? Book a free consult — https://micro1tech.com/contact/