This website uses cookies

Read our Privacy policy and Terms of use for more information.

PHISH & TELL™ –
The Cyber & AI Risk Triage Desk

So your business doesn’t break while you’re busy running it.
A 5-minute weekly brief that tells you what to ignore, what to fix, and what can wait.

This week is about choosing your helpers before the stressful moment arrives.

Several of the useful stories this week had similarities: a payment page that looked official, an AI assistant that already had access, a support call that sounded helpful, a recovery firm that showed up at exactly the wrong time. The fix is not to distrust everyone. The fix is to decide, while things are calm, who gets trusted and how that trust is checked.

THIS WEEK’S 10-MINUTE WIN
Make a one-page "who we call first" card for cyber emergencies.

GuidePoint Security's GRIT team investigated a group calling itself "Ransom Busters" that emailed ransomware victims before the attacks were public, offering decryption keys and deletion of stolen data for $20,000 to $60,000. Researchers assessed with moderate confidence that the group was likely a ransomware affiliate posing as a recovery firm, not an independent helper (BleepingComputer).

Should you care?

YES – urgently – If your emergency plan today is "we would figure it out." That is normal for a small business, but it creates a real problem under pressure. If a stranger already knows about your incident and offers to fix it quickly, your team needs a rule before anyone replies, pays, uploads files, installs a tool, or negotiates.

🤷‍♀ MAYBE – worth checking – It’s been a while since you’ve written or reviewed your plan.

NO – low priority (for now) – You regularly review and test your plan.

What’s happening (plain English)?

After a cyber incident, there can be a second scam layered on top of the first one. Someone may claim they can recover files, delete stolen data, or talk to the criminals for less money. They may sound informed because they are connected to the attack or have access to leaked information.

What to do now

Create a one-page card called "Who we call first." Put it somewhere the owner, office manager, finance lead, and IT contact can find it without logging into a locked computer.

If this happens

First move

What waits

Files are locked or a ransom note appears

Call the named IT provider or incident contact

Paying, replying to criminals, reinstalling tools

A "recovery firm" emails or calls

Save the message and call your known contact

Clicking links, uploading sample files, signing anything

Payroll, banking, or vendor payment may be affected

Call the bank using your saved number

Sending new payments, changing bank details

Customer or employee data may be involved

Call counsel, insurer, or your designated advisor

Public statements, customer emails, blame

Keep the card simple. Include names, phone numbers, backup numbers, and one rule: nobody hires a recovery company, pays money, installs remote access, or sends files during a cyber incident without two named approvers.

AI REALITY CHECK
AI assistants are useful, but connected apps turn them into a data doorway

Varonis disclosed a Microsoft Copilot Personal vulnerability chain called CoSnitch, tracked as CVE-2026-24301, where a crafted link could make Copilot automatically run attacker instructions and pull data from connected apps such as Gmail, Outlook, Google Drive, Calendar, and OneDrive. Varonis said Microsoft shipped patches on August 18, 2026 and that it had seen no evidence of exploitation in the wild (Varonis Threat Labs).

The practical lesson is not "never use AI." The lesson is that an AI tool with inbox, calendar, and drive access should be treated like a staff member with keys. It should only have the access it needs, and someone should review that access on purpose.

This week, do three things:

  • Open the connected-apps or integrations page for the AI tools your team uses.

  • Disconnect inboxes, drives, calendars, and cloud accounts that are not actively needed.

  • Check whether the tool has saved memory or long-term instructions, and delete anything that should not be part of future work.

If you are testing a new AI helper, start with read-only access or sample files. Do not give a brand-new agent access to your live customer folders, finance inbox, HR files, or password-reset emails on day one.

READER QUESTION OF THE WEEK
If someone calls and says they are from a vendor or recovery company, how do we verify them without being rude?

Short answer: thank them, end the call, and call back through a number you already trust.

You do not need to accuse anyone. You can say: "Thanks for flagging it. For security, we call vendors back through our saved contact list. I will route this to the right person." Then hang up and use your own records, the vendor portal, a signed contract, or a known account manager's number.

This matters because a RingCentral incident reported this week involved a sophisticated social-engineering campaign, and a ShinyHunters spokesperson told The Register the group voice-phished an employee into handing over a password. The data later posted online included 1.6 million unique email addresses plus names, physical addresses, and phone numbers tied to RingCentral accounts (The Register).

What to do first:

  • Write one callback rule: passwords, codes, access changes, payment changes, and remote-support sessions are never handled from an inbound call.

  • Put the real vendor contact list somewhere your team can reach.

  • Teach staff that slowing down for verification is part of good customer service, not a sign of mistrust.

What can wait: a formal phone-security policy. Start with the callback rule first.

RISK RADAR
Also happening this week

Paid search ads can still lead you to the wrong bill-pay page

The FTC warned that paid search ads can impersonate bill-payment sites, using the Doxo case as an example of ads and pages that allegedly made consumers think they were paying official billers such as Labcorp, AT&T, and state toll authorities. The FTC said Doxo agreed to pay $2.1 million to settle allegations involving misleading bill-pay ads and added fees (FTC Consumer Advice, FTC Bureau of Consumer Protection).

Fix: Bookmark the real payment pages for taxes, utilities, insurance, banking, and key vendors from the invoice or portal. Do not start bill payments from a search ad.

One Windows flaw moved onto CISA's must-fix list

CISA added CVE-2026-33824, a Windows Internet Key Exchange Service Extensions remote-code-execution flaw, to its Known Exploited Vulnerabilities catalog after active exploitation was reported. BleepingComputer reported that the bug affects supported Windows 10, Windows 11, and Windows Server releases when IKEv2 is enabled, and NIST's NVD lists the vulnerability as CVE-2026-33824 (BleepingComputer, NIST NVD).

Fix: Confirm that August Windows updates are fully installed and that machines have rebooted. Downloaded but pending updates do not count.

"We have MFA" may still leave an old sign-in path open

Huntress research reported a 155x increase in password-spraying attacks in the first half of 2026, including more than 81 million login attempts and 78 account compromises in a two-week window. In 23 affected businesses Huntress analyzed, 8 had no multifactor authentication and 15 had MFA that did not apply to the sign-in path attackers used (BleepingComputer).

Fix: Ask your Microsoft 365 or Google Workspace admin one specific question: "Does MFA apply to every user, every app, and every sign-in method, with legacy sign-ins blocked?"

Ransomware keeps aiming at backups

An updated joint advisory summarized by Help Net Security says Medusa ransomware has impacted more than 500 organizations since June 2021, including education, insurance, law, healthcare, manufacturing, government, and financial-services victims. The report notes that Medusa's encryptor shuts down backup and security services before encrypting files (Help Net Security).

Fix: Restore one real file from your off-site backup this month. A backup you have not tested is still a question mark.

A third-party order plugin exposed customer details

SafePal disclosed that an authorization flaw in a third-party order-tracking plugin exposed names, email addresses, shipping addresses, phone numbers, and purchase details for about 39,798 customers. SafePal said wallet seed phrases, private keys, and payment card numbers were not involved, and it later tightened retention and took down more than 30 fraudulent sites and phishing links tied to follow-on scams (SafePal).

Fix: List the plugins, widgets, and apps on your website that touch customer data. Remove the ones you do not use and confirm the rest are still maintained.

Storefront cameras need maintenance too

Hunt.io reported that more than 14,530 Dahua IP cameras were compromised during a 35-day campaign using brute force, older authentication-bypass flaws, and cloud-relay abuse. The researchers said one backdoor account could survive password changes and, on most firmware, a factory reset (Hunt.io).

Fix: Ask whoever installed your cameras whether they are reachable from the internet, whether remote access uses MFA, and whether the firmware is current.

Before you go

This week's small move is not dramatic: write down who gets called first.

That one card can keep a hard day from becoming a confused one. Pick the trusted people now, save their contact details somewhere reachable, and make it normal for your team to verify before they hand over access, money, files, or passwords.

My weekly question to you: What security question or weird email caught your attention this week?

Reply and tell me. I read every response.

~Alexia

P.S. If one of these checks raises a question, bring it to office hours — free and private, Fridays at 1pm ET. Sometimes a quick 8-minute conversation is enough to figure out what matters and what can wait. Add office hours to your calendar and drop in when you have a question. (Some folks have asked whether ro.am drops you right in with me, face to face. No, don’t worry, you enter a lobby on a web site (or app) called Ro.am, and I let you in. No surprises for either of us. 🙂)

P.P.S. Remember, if you are a small supplier or vendor and you are looking to qualify for bigger contracts, check out our sister newsletter, Quote and Qualify™️, at newsletter.brightleafreadiness.com.

You’re subscribed to Phish & Tell™️ because your business is worth protecting.

🩷