If you run a small or mid-sized business around Manchester and your cybersecurity plan is “we’ve got MFA turned on, so we’re covered” — it’s worth pausing on that. Right now, criminal groups are running phishing campaigns that get past standard multi-factor authentication on Microsoft 365 accounts, and almost every business in the region runs on Microsoft 365. This isn’t a distant, abstract threat. It’s happening at volume, this month, to businesses exactly like yours.
What’s actually happening right now
The attack getting the most attention is called device-code phishing, and it’s being run at industrial scale — new campaigns launching every day, hitting hundreds of organisations. Two criminal toolkits are behind a lot of it: one lets low-skill attackers impersonate a real user and get lasting access to their mailbox while sailing straight past standard MFA; the other is a companion tool that makes running the attack even easier. Some of the more sophisticated groups involved are going a step further, tricking a user into granting a malicious app permission to their mailbox — permission that survives even if the password is changed afterwards.
The uncomfortable detail here is that MFA being switched on is no longer the reassurance it used to be. These attacks are specifically built to work around it.
And ransomware is climbing sharply too
Separately, ransomware attacks jumped by around a fifth in a single month this summer, with some sectors — finance, technology, education — seeing much sharper rises than that. Modern ransomware isn’t really after your data anymore; it’s after your uptime. That matters because it means “we don’t hold anything sensitive” stopped being a reason to feel safe. If shutting your systems down for a few days would cost you money, you’re a viable target regardless of what’s actually stored on them.
“We’re too small to be a target” is exactly the assumption they rely on
Lancashire Police have been direct about this recently: most cyber attacks aren’t sophisticated, targeted operations against big-name corporations — they’re basic, opportunistic attempts exploiting simple, common vulnerabilities, and small businesses are hit constantly. Their figures put the average cost of a serious attack at around £195,000 to the business involved. For a small or mid-sized company, that’s not a bad quarter — it’s existential.
What actually helps
None of this requires an enterprise security budget. A few things make a genuine difference:
- Move to phishing-resistant MFA for your important accounts. Standard app-based MFA can be bypassed by these attacks; hardware security keys, passkeys, or Windows Hello are built specifically to resist them. Prioritise finance and management accounts first.
- Review what third-party apps have access to your mailboxes. A malicious OAuth app granted access once can keep that access indefinitely, even through a password reset, unless it’s specifically revoked.
- Get Cyber Essentials certified if you haven’t already. It’s a government-backed, proportionate standard built for exactly this size of business, not an enterprise framework you have to scale down.
- Use what’s already available locally. The Northwest Cyber Resilience Centre is a police-led, Home Office–funded service offering practical, affordable support — including staff training and vulnerability assessments — specifically for SMEs in this region.
Not sure whether your current setup would actually stand up to this? Get in touch with Valetech Solutions for a clear-eyed look at your Microsoft 365 security, your MFA setup, and what a proportionate next step looks like for a business your size.