New phishing scam is smarter than ever… here’s how to protect your business

Microsoft is warning business owners about a new type of phishing scam (where cyber criminals pose as a trusted source to trick you into giving away login info), which uses popular cloud services like SharePoint and OneDrive.

Although these platforms are usually safe, scammers have figured out how to trick privacy settings to get past security checks.

The scammers hack your cloud storage by stealing your login details or buying them on the black market.

Once they get inside, they upload a file that is designed to look authentic – like a fake Microsoft 365 login page. They set the file to “view-only” or limit access to specific people, such as you and your team.

Opening these files or following any links inside the emails could cause serious damage to your business. Scammers can use your information to access your systems, or they can install malware (malicious software) that lets them cause disruption and steal information.

Recovering from these kinds of attacks can be expensive and time-consuming – not to mention the damage it could do to your business’s reputation.

Make sure your employees are aware of this new threat and know to be cautious when opening emails, even if they appear to come from a trusted service.

Before opening any shared files, double-check the sender’s identity. If something feels off, contact the sender directly to verify it.

Make sure you use multi-factor authentication (MFA) across all your team’s devices. This adds an extra layer of security by requiring a second piece of information (like a code sent to your phone) along with your password.

Also, keep your security software up to date so that it’s always ready to block the latest types of attack.

Would you like our help protecting your business with added security, training, and monitoring? Get in touch.

Recent posts

Don’t trust AI with this security essential

Don’t trust AI with this security essential

Let me start with a question: If you needed a strong password, would you ask AI to generate one for you? It sounds reasonable enough.  Tools like ChatGPT and Copilot can write reports, draft emails and even create bits of code. Asking them for a 16-character...

read more
Relying on Windows 10 extended support? Time to upgrade

Relying on Windows 10 extended support? Time to upgrade

Are you still running Windows 10 because “it’s fine for now”? I hear that a lot.  And to be fair, if you signed up for Extended Security Updates (ESU) programme, Windows 10 probably does still feel fine. It turns on. It works. It gets security updates. No drama....

read more
How to stop AI projects stalling

How to stop AI projects stalling

Have you noticed how many AI projects start with excitement… and then quietly go nowhere? I’m seeing it a lot.  A demo here, a pilot there, plenty of internal chatter, but very little that makes it into day-to-day use.  And it’s not because AI doesn’t work...

read more