Phishing attacks response requires immediate action as AI-powered campaigns now generate personalized fraud emails at scale, specifically targeting your accounts payable and email systems. The FBI warns that OAuth consent phishing and passkey-themed attacks can grant attackers permanent access to corporate data without stealing passwords.
Cybercriminals are using artificial intelligence to launch unprecedented phishing campaigns against small businesses. Researchers discovered threat actors generating one million personalized fraud emails in just three days, specifically targeting accounts payable departments with AI-crafted invoices and payment requests that bypass traditional email security (Dark Reading).
The FBI has issued an alert about OAuth consent phishing attacks targeting users of messaging applications like Microsoft Teams and Slack. These attacks trick employees into granting attackers permanent access to corporate email accounts and sensitive data without stealing passwords. Once permission is granted, attackers can read emails, send messages on behalf of the user, and access company files (KnowBe4).
Microsoft warns that cybercriminal groups including ShinyHunters and Helix are conducting passkey-themed phishing campaigns against Microsoft 365 corporate accounts. The attacks impersonate legitimate security notifications about passkey setup or single sign-on verification, leading victims to credential-harvesting pages (Bleeping Computer).
A massive data breach at identity verification provider IDScan has exposed over 150 million driver's licenses and identity documents. The compromised data includes full names, addresses, dates of birth, license numbers, and document photos. This breach affects businesses that rely on ID verification for customer onboarding, age verification, and employee screening (New York Post).
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed its DAVID driver database was breached through stolen credentials belonging to a police department employee. The credentials were compromised from a personal device where work passwords had been saved, allowing unauthorized access to millions of Florida driver records. The incident underscores the importance of multi-factor authentication and proper credential hygiene (Bleeping Computer).
Small business owners should train employees to recognize AI-generated phishing attempts, implement multi-factor authentication across all business systems, avoid saving work credentials on personal devices, and verify any unexpected permission requests through separate communication channels.
How should small businesses handle phishing attacks response right now?
AI-powered phishing attacks are now generating one million personalized emails in three days, targeting accounts payable departments with fake invoices. The FBI and CISA have alerted businesses to OAuth consent attacks on Microsoft Teams and Slack, where employees unknowingly grant attackers read-and-send access to email. Passkey-themed campaigns impersonate Microsoft 365 security notifications to harvest credentials. For SMBs, the single most important action is enabling multi-factor authentication across all email and collaboration tools immediately. Train your team to verify unusual permission requests through a separate channel before accepting them. Avoid saving work passwords on personal devices, as the Florida DMV breach shows how compromised credentials expose millions of records.
Key takeaways
- Enable MFA on all email and collaboration platforms (Teams, Slack, Microsoft 365) within 48 hours.
- Train employees to verify unexpected permission requests by contacting the sender through a known phone number or chat.
- Never save work passwords on personal devices or browsers; use a business password manager instead.
- Review recent email permission grants in Microsoft 365 account activity and revoke any unfamiliar OAuth applications.
Frequently asked questions
What happens if an employee clicks a phishing link and grants permission to an attacker?
The attacker gains permanent access to your email, can read all past messages, send emails on your behalf, and access files stored in your account. They do not need your password. Check your email permission settings immediately in Account Settings > Security > App Password or OAuth permissions, and revoke anything unfamiliar.
How do we know if our company was targeted by the IDScan or Florida DMV breaches?
If your company uses ID verification for customer onboarding or employee screening, contact your vendor to confirm whether they rely on IDScan data. For the DMV breach, only Florida driver records were exposed. Monitor credit reports and watch for suspicious activity if your data was included.
What is OAuth consent phishing and why does it bypass password protection?
OAuth consent phishing tricks employees into granting third-party apps access to their corporate accounts. Since the attacker uses the legitimate OAuth flow, they bypass password requirements entirely. Always verify the app requesting access and check that the permission scope matches the actual service you use.
Should we use passkeys instead of passwords to prevent these attacks?
Passkeys are more secure than passwords, but attackers now impersonate passkey setup notifications to harvest credentials. Passkeys alone are not a complete solution. Combine passkeys with MFA and employee training to recognize fake security notifications.
Sources
- https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days
- https://blog.knowbe4.com/fbi-alert-oauth-consent-phishing-is-targeting-users-of-messaging-apps
- https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/
- https://nypost.com/2026/09/11/personal-finance/idscan-data-breach-exposes-153-million-drivers-licenses
- https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/