
Monday 7 September 2026 · 6-minute read
Every story this week turns on the same quiet question: who is actually asking? An IT support chat that isn't IT, a text from a toll operator that was never a toll operator, a message from the Student Loans Company that would love your bank details, and AI agents inside the business acting under identities nobody thought to check. Impersonation is having a moment, and the defence in every case is the same unglamorous habit: pause, and verify through a channel you chose yourself. Four items this week, all published in the first days of September.
On 2 September, Microsoft Threat Intelligence published a detailed teardown of a live campaign in which attackers use Teams' external collaboration features to pose as IT or helpdesk staff. The approach is patient and human-operated: the attacker builds rapport in chat, persuades the employee to grant remote access through Quick Assist or similar tools, then quietly installs a Node.js-based implant and pivots across the network, capturing screenshots and working towards domain controllers along the way. One convincing conversation converts into enterprise-wide access.
What lifts this above routine threat reporting is where Microsoft puts the fix. Alongside the expected technical controls, its top recommendations are behavioural: establish internal helpdesk authentication phrases, teach people to spot external-tenant indicators in Teams, and normalise verifying unsolicited support contact through a known internal channel before granting anything.
What does this mean for me? The helpdesk relationship is built on compliance: IT asks, users do, and years of awareness messaging ("just call the helpdesk!") have reinforced that trust. This campaign expands the attack surface. Two concrete moves. Agree on a lightweight authentication ritual for genuine IT contact: a shared phrase, a ticket number quoted back, a callback via the published number, and communicate it as protecting staff, not doubting them. Then check whether your own people can even tell an external Teams tenant from an internal colleague; in most default configurations the visual difference is easy to miss, and that is worth showing, not describing, in your next comms.
Source: Microsoft Security Blog, 2 September 2026 (vendor threat intelligence, based on observed intrusions).
In June, Google filed a civil lawsuit, and the FBI ran Operation Ghost Hook against the "Outsider" phishing kit, one of the larger phishing-as-a-service operations behind the toll-fine, delivery and banking texts that plague everyone's phones. On 3 September, Group-IB published research on what happened next: within a month of the lawsuit, affiliates had stood up more than 700 new phishing pages. The kit offers over 267 ready-made templates impersonating banks, telecoms firms, logistics companies, toll systems, and government fine services, has targeted people in more than 54 countries, and bypasses one-time-code MFA by sitting as an adversary-in-the-middle during login.
The honest caveat: Group-IB sells the monitoring services this research showcases. But the core observation, that supply-side disruption slowed nothing for long, is well evidenced and matters.
What does this mean for me? Resist the temptation to celebrate takedowns in your awareness comms as if the problem shrank; the infrastructure regrows in weeks. The durable lesson for your people is that scam texts are an industrial product, personalised at scale, not a sign they were individually targeted or careless. That framing reduces shame, and shame is the enemy of reporting. It is also a timely prompt to check that your guidance covers texts and phone as thoroughly as email, and that colleagues know one-time codes are phishable, which makes "never enter codes on a page you reached from a link" the behaviour to drill.
Source: Group-IB research, 3 September 2026 (vendor threat research).
A survey of 202 enterprise technology and security leaders, run by analyst firm Enterprise Management Associates for Cequence Security and reported on 1 September, puts numbers on something many of us have suspected: 65% of organisations have seen AI agents act outside their intended scope, and 29% say an incident had measurable impact. Detection is slow (only a third could contain an out-of-scope action within minutes) and nearly half could not produce a complete 30-day audit trail of agent activity.
The finding that belongs on a slide, though, is the confidence gap: 94% of leaders were confident their agents had appropriate access, while only 33% had actually provisioned them with least privilege. It is a modest, vendor-commissioned sample, so treat the precise percentages lightly. The gap between felt assurance and verified control, however, is the oldest pattern in our field, now wearing a new outfit.
What does this mean for me? Human risk teams should claim a seat in AI agent governance, because the failure modes are behavioural: overconfidence, unclear ownership, delegation without verification. The practical framing that lands with leadership is that an agent is a new joiner who works at machine speed and never asks clarifying questions. Would we give that person shared credentials and no manager? Push for three things you can actually influence: a named human owner for every agent, unique identities rather than shared credentials, and the same joiner-mover-leaver discipline you would demand for staff.
Source: Infosecurity Magazine, 1 September 2026, reporting an EMA survey commissioned by Cequence Security.
On 1 September, the Student Loans Company and the UK Fraud Minister issued a warning timed to the autumn payment run: roughly £2.6 billion is about to land with 1.1 million students, and fraudsters know the schedule as well as the SLC does. Impersonation scams spike in September, January and April, the three payment months, using the classic pressure lines: a payment is blocked, bank details need updating, act now. The SLC says its fraud prevention work saved £56.2 million last year, and its advice is pleasingly behavioural: stop and think before you click, go to your account directly via GOV.UK rather than through any link; forward scam texts to 7726.
What does this mean for me? Attackers plan campaigns around predictable financial moments; most awareness calendars ignore them. Map your year's "money moments" (payroll changes, bonus season, tax deadlines, benefits enrolment) and time your comms to land just before each one, when the lure is about to arrive, and relevance is highest. This story also travels well beyond work: plenty of your colleagues are parents of students or have new starters fresh from university, and security messages about protecting family money are read with an attention that corporate policy reminders never get. It is a ready-made, zero-effort piece for your champions network this week.
Source: GOV.UK news release, 1 September 2026 (official government guidance).
Four stories, one habit: when something asks, check who's asking, through a route you picked yourself. If you do one thing this week, make it the helpdesk verification ritual, because the fake IT call is the impersonation your organisation is least prepared to doubt. Back next Monday.
The CyBehave Weekly Briefing is researched and written for human risk, security awareness and behaviour change professionals. Forward it to a colleague who would enjoy it.
Until next Monday,
The CyBehave Team
Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.