Manchester SMB Threat Brief — September 2026: the quarter Microsoft 365 stopped being the safe option
Q3's UK threat picture is straightforward. Ransomware volume climbed 20% in July. Microsoft 365 identity attacks scaled to industrial levels. And the NCSC issued three joint edge-kit advisories in six weeks. Here's what actually happened between June and August 2026, and what a Manchester SMB should be doing about it in the next ninety days.

This is the second in our quarterly Threat Brief series. The June brief argued that "patch your edge kit" had overtaken "change your password" as the single most important thing a UK SMB could do. Q3 hasn't overturned that argument — if anything, it's reinforced it — but it has added a second, equally uncomfortable one: your Microsoft 365 tenant is now under attack at industrial scale, and basic MFA on its own is no longer sufficient to keep the attackers out. Every figure below is cited, so you can check it yourself.
What this brief is
An honest quarterly read on what actually threatened Greater Manchester SMBs in Q3 2026, drawn from NCSC advisories issued in June, July and August 2026, the 2025/2026 UK Cyber Security Breaches Survey, and July's global ransomware telemetry. It is written for the owner of a fifteen-to-fifty-person business in Manchester who wants to know what to do next — not for a security team of ten with a SIEM budget.
We keep it short, we cite everything, and we tell you the one thing to do this quarter. We do not sell anxiety.
The number that moved
The headline: ransomware jumped nearly 20% in July 2026 — 799 tracked incidents, up from 668 in June — with attacks on finance up 71%, tech up 62% and education up 44% (The Register, 7 August 2026, citing Comparitech data). Two groups — Qilin and The Gentlemen — together claimed nearly a third of July's attacks.
That's the headline. But it isn't the number that most alarmed us. That one is quieter and comes from Microsoft themselves — "hundreds of organisations daily" are being compromised by device-code phishing campaigns against Microsoft 365, with 10 to 15 distinct campaigns launching every 24 hours since 15 March 2026 (Cisco Talos and Microsoft VP Tanmay Ganacharya, via The Register, 1 July 2026). If your business runs on Microsoft 365 — and almost every Manchester SMB we work with does — you are, statistically, inside the target set of an automated criminal industry that runs day and night.
What's actually happening right now
Three trends dominate the Q3 picture, and each of them shifts one of the assumptions a typical SMB has been quietly relying on.
1. Ransomware is back on the rise, and the sector mix is shifting
After a comparatively quieter June, July became the second-busiest ransomware month of 2026 so far — only March was busier (The Register, 7 August 2026). The important detail for a Manchester SMB is not the raw count but the sector shuffle. Attacks on finance rose 71% month-on-month. Attacks on tech firms rose 62%. Attacks on pharmaceuticals and medical billers rose 46%. Manufacturing continued at its already-high baseline: an ESET-commissioned survey published in April 2026 found 78% of UK manufacturers had suffered at least one cyber incident in the previous twelve months, and in more than half of the worst cases the losses exceeded £250,000.
The reason this matters is the composition of Inology's client book — and, by extension, of the wider Manchester SMB economy. Accountancy firms, financial planners, manufacturers, and engineering distributors are all sitting inside the sectors that saw the sharpest Q3 lift. The mid-year lull is over. The 2025/2026 Cyber Security Breaches Survey, published by the Home Office and DSIT in April 2026, put the baseline at 43% of UK businesses reporting a breach or attack in the last twelve months — 46% of small businesses, 65% of medium businesses. Q3's data suggests those numbers will be higher when the 2026/27 survey is published next spring.
2. Microsoft 365 identity attacks have gone industrial
This is the story of the quarter. Three separate but related threads point at the same target: your M365 tenant.
The first is criminal phishing-as-a-service kits, specifically EvilTokens (first identified by French firm Sekoia in March 2026, documented in detail by Cisco Talos in July) and its companion ARToken panel. These are packaged tools that let a low-skill attacker run a Microsoft device-code phishing flow against a target, silently authenticate as the user, obtain persistent Outlook inbox access, and pivot from there — completely bypassing standard MFA in most tenants (The Register, 1 July 2026). The user thinks they've clicked a normal Microsoft login prompt. They haven't.
The second is state-aligned OAuth-app abuse. Google's Threat Intelligence Group reported on 21 August 2026 that three Russian-linked groups — UNC6293, UNC7005 and UNC5976 — added OAuth-application abuse to their targeted M365 and Google Workspace phishing, starting in June 2026 and expanding through August (The Register, 21 August 2026). The mechanic here is different from criminal kits but the outcome is the same: an OAuth-connected malicious app receives ongoing permission to read the mailbox, and that permission survives password resets.
The third is on the mail-server side. NCSC and 15 partner countries jointly warned on 23 July 2026 that a Russian state-supported group tracked as LAUNDRY BEAR is running a zero-click "beehive" (or "Ulej") exploit against the Zimbra Collaboration Suite webmail platform — victims only have to view a malicious email in a vulnerable Zimbra instance to be compromised (NCSC, 23 July 2026). Zimbra is less common in the Manchester SMB book than Microsoft 365, but the underlying pattern — a webmail platform compromised silently on view — is the direction of travel that criminal groups tend to follow within twelve months.
The 2025/2026 Breaches Survey already had phishing as the most disruptive attack type for 69% of businesses reporting a breach, and phishing itself at 38% of all UK businesses in the past twelve months. Those numbers pre-date the industrialisation. The mailboxes now getting compromised are protected by MFA. What changed is how the phish itself works.
3. State-aligned edge-kit exploitation widened, with three NCSC advisories in six weeks
The June brief's edge-device theme is not going away. In fact it's amplified. Three separate NCSC-led joint advisories landed in Q3, all pointing at network edge kit and mail servers.
- 13 July 2026 — Russian FSB Cisco advisory. NCSC and 18 agencies across 12 countries called out Russian FSB Centre 16 actors — tracked under names including Berserk Bear, Energetic Bear, Static Tundra and Ghost Blizzard — for globally exploiting poorly configured Cisco devices, particularly via the Smart Install feature and legacy SNMP, to gain persistent access to critical infrastructure (NCSC, 13 July 2026). The UK sanctioned 24 individuals and entities the same day and formally attributed the December 2025 Poland energy grid attack.
- 23 July 2026 — Zimbra "LAUNDRY BEAR" advisory. Covered above.
- August 2026 — Iran IRGC advisory (re-published). NCSC re-published (in its August 2026 file drop) the joint UK/US/Australia/Canada advisory that Iranian IRGC-affiliated actors are exploiting known unpatched Fortinet, Microsoft Exchange and Log4j vulnerabilities to run ransomware, including data extortion and disk encryption (NCSC advisory PDF, August 2026 folder). This particular advisory's underlying text was originally issued in September 2022; NCSC's decision to re-drop it in the August 2026 folder is the signal — the same vulnerabilities are still being exploited.
The wider context: the NCSC's most recent Annual Review put the UK at an average of four "nationally significant" cyber attacks every week, more than double the year before (NCSC, 14 October 2025). The Cyber Security and Resilience Bill's official summary factsheet, updated 30 June 2026, confirms 204 nationally significant incidents out of 429 total managed by NCSC in the year to September 2025 (gov.uk, 30 June 2026). This is not a receding threat picture.
The wider picture: three regulatory items you should have on your Q4 board pack
Three regulatory changes touch UK SMBs during Q4 2026 and into next year. None of them are optional to be aware of.
First, Cyber Essentials v3.3 — MFA auto-fail is here. IASME confirmed that the updated Cyber Essentials Requirements for IT Infrastructure v3.3 apply to all assessment accounts created after 26 April 2026. The most important change: any organisation that fails to implement MFA on all cloud services (where MFA is available — whether free, paid or included) automatically fails the assessment. Organisations with older accounts have six months to certify against the previous version — meaning if you started your assessment before 26 April 2026 and haven't finished it, you have until 26 October 2026 or you'll be rolled onto v3.3. The v3.3 rules also formalise the 14-day critical-patch window we've been urging clients to adopt for two years. If your business needs Cyber Essentials for tender, insurance or supply-chain reasons, this quarter is when to make sure you're on the right side of that deadline. We wrote a longer piece on what CE+ audit day actually looks like separately.
Second, the Cyber Security and Resilience Bill — still moving through Parliament. The Bill was introduced on 12 November 2025 and continues its Parliamentary stages. The most consequential proposal for our client base is around incident reporting — regulated entities will need to notify within 24 hours of an incident and provide a fuller report within 72 hours (gov.uk Summary of the Bill, 30 June 2026). SMBs are largely out of direct scope, but the supply-chain provisions will pull many into scope indirectly. If you supply IT services, professional services, logistics or components to a regulated operator, expect the assurance questionnaires to get harder. DSIT has said it will consult on implementation in 2026.
Third, the SRA warning notice on AI misuse — 17 August 2026. The Solicitors Regulation Authority issued a formal warning notice on the misuse of AI, applicable to all firms and individuals it regulates (SRA, 17 August 2026). The regulator received 42 reports of potential AI misuse between July 2025 and July 2026, and has ongoing investigations that include confidential client information being entered into public AI tools without safeguards. For legal-sector clients this makes shadow AI — staff using ChatGPT-style tools on client matters without governance — an explicit regulatory concern. If you're a Manchester law firm reading this, a written AI acceptable-use policy is now the minimum.
Watch list — October
Three things we'll be watching next month, so you don't have to.
First, 26 October 2026 — Cyber Essentials v3.3 grace period ends. Any older CE assessment account that hasn't certified against the previous version by that date rolls automatically onto v3.3 rules.
Second, continued Zimbra exploitation. NCSC's LAUNDRY BEAR advisory named a specific mail platform, but the zero-click on-view mechanic is generalisable. If any part of your business runs on-premises webmail (Exchange or otherwise) rather than Microsoft 365 or Google Workspace, the next twelve months are worth planning a migration in.
Third, sanctions and attribution activity. The UK's 13 July 2026 sanctions and formal attribution of the December 2025 Poland grid attack marks a shift in tempo. Expect more attribution activity through Q4, and — because attribution often precedes fresh advisories on TTPs — more product-specific patch guidance from NCSC.
The honest local view
We look after roughly forty-five Manchester SMBs across seven industries. What's changed on the ground for us this quarter?
Two things. First, we've moved every managed client onto phishing-resistant MFA (FIDO2 keys or Windows Hello for Business) for finance, legal and executive users specifically. Basic MFA — the six-digit code from the Microsoft Authenticator app — remains fine for lower-privilege staff, but any user who can move money or sign contracts is now protected against the EvilTokens class of attack. That single change is the largest security improvement most SMBs can make this quarter.
Second, we've formalised what we already did informally: a quarterly "edge audit" of every internet-facing device across every managed client. Firewall firmware version, admin-interface exposure, legacy protocol status, vendor support status. We do it whether or not a client asked for it. The reason is arithmetic: the joint advisories keep landing in the same places, and the effort of checking is small compared to the effort of recovering from the compromise you missed.
If you're not sure whether either of those two things is happening in your business right now, that's the conversation to have this quarter — before Q4 trading, and before the CE v3.3 deadline in October forces the question anyway. Our first assessment is ninety minutes, free, and produces a written two-page report with a costed remediation plan. Get in touch or call 0161 503 3535.
FAQ
If MFA isn't enough, what actually is?
The current answer is phishing-resistant MFA — meaning FIDO2 hardware keys, passkeys, or Windows Hello for Business. The device-code phishing kits described above bypass code-based MFA because they trick the user into completing a legitimate Microsoft login flow that the attacker piggybacks on. Phishing-resistant MFA is bound to the specific device and domain, so the attacker can't proxy it. Roll it out to finance, legal and executive users first. The kit is inexpensive — under £50 per user for a physical key, free if you use Windows Hello on modern hardware.
We're not "critical infrastructure" — do the NCSC edge-kit advisories actually apply to us?
Yes, in practice. NCSC advisories are written for critical infrastructure operators, but the underlying vulnerabilities and exploitation techniques apply to any organisation running the same product families. Cisco routers, Fortinet firewalls, SSL VPN appliances and Microsoft Exchange are the same products regardless of whose network they sit on. State-aligned actors tend to be the first to weaponise a technique; criminal groups then adopt the same technique within six to twelve months and turn it on the wider SMB estate. Reading the advisory now saves you reading the incident report later.
Should we be worrying about ransomware if we don't handle sensitive data?
Modern ransomware isn't primarily about the data — it's about the downtime. A financial-services firm loses trading days. A manufacturer loses production. An accountancy loses filing deadlines. The extortion demand is calibrated to the cost of being offline, not to the value of the data. That's why the sector shifts in July's data (The Register, 7 August 2026) matter more than the specific data types those sectors hold.
We're Cyber Essentials certified — does that cover this?
Cyber Essentials sets the floor, not the ceiling. The v3.3 update from April 2026 has raised that floor meaningfully — MFA everywhere, 14-day critical patching, and a hard fail if you don't hit them. But CE doesn't require phishing-resistant MFA. It doesn't require OAuth-app consent lockdown. It doesn't require SNMPv3-or-nothing on your switching kit. Those are all sensible next steps beyond the certificate. If you're already certified, ask your provider which of those three you have and which you don't.
What's the single highest-impact thing we can do this month?
Two candidates, and honestly it depends on which one you haven't done. If you're still running basic MFA for admin and finance accounts, roll phishing-resistant MFA to those users this month. If you've already done that, run an edge audit of every internet-facing device — firmware, admin interface exposure, legacy protocol status. Whichever of those is currently missing is the highest-impact single action.
How does this brief link to the June one?
The June brief flagged the shift from password-based to edge-device attacks. That trend has continued — three joint NCSC advisories on edge kit in Q3 is not a temporary spike. Q3's new material is that identity attacks against Microsoft 365 have industrialised alongside it, which changes the "we're safe because we have MFA" calculation. Read them together as a running series. We'll publish the next brief in December, covering Q4.
Where can I go if I need help right now?
If it's active — you suspect a compromise, you've had a phishing hit, a device is behaving oddly — call us on 0161 503 3535. If it's not active but you'd like an audit against the three trends in this brief, book a ninety-minute assessment on our contact page. If you're a very small business (under ten people) you can also access NCSC's Cyber Advisors programme for free hands-on consultancy — more than 760 small organisations have used it and over 150 have achieved Cyber Essentials via that route (NCSC blog, 15 July 2026). We recommend it without hesitation. If you're bigger than that and want the framework version, our Managed IT and cyber-resilience services build it in.
Ready to talk to a real Manchester MSP?
If any of this raised a question about your own setup, get in touch. We'll give you a straight answer — no sales pitch, no scaremongering.
Talk to a human