Threat Analysis: NCSC Edge Device Alert, Manchester Airports Breach, and Microsoft Teams Vishing, What UK SMBs Need to Know

Threats & Attacks

Threat Analysis: NCSC Edge Device Alert, Manchester Airports Breach, and Microsoft Teams Vishing, What UK SMBs Need to Know

Hello, Mauven here.

This is your Daily Threat Analysis for 27th August 2026.

Three items today. One from the NCSC, one from Manchester, and one that tells you something important about how ransomware operations have industrialised their initial access. All three have direct implications for UK SMBs. Let us get into it.


1. NCSC Alert: Internet-Exposed Systems and Edge Devices

The NCSC published an alert today titled Disruptive cyber activity highlights risk from internet-exposed systems and edge devices. The language is calm and measured, as it always is. What it is describing is not calm.

The advisory highlights a pattern of disruptive cyber incidents linked to internet-facing systems, VPNs, firewalls, remote access gateways, and network edge devices, that have either unpatched vulnerabilities or default and weak credentials. Attackers are finding these devices, exploiting known flaws, and using them as the doorway into networks.

The NCSC has published guidance on securing internet-exposed systems repeatedly over the past three years. The fact we are still having this conversation tells you everything about how seriously organisations are taking it.

Here is what the advisory does not spell out: the organisations being disrupted are not, for the most part, ignorant of this risk. They know their Fortinet or Cisco or Palo Alto device is internet-facing. They know patches exist. The failure is operational, patch management processes that prioritise uptime over security, managed service providers who are not contractually required to apply security updates within any defined timeframe, and no one internally with both the authority and the knowledge to push the issue.

For UK SMBs, the practical translation is this:

  • VPN appliances: If your remote access solution is a dedicated VPN appliance, ask your IT provider when it was last patched. Get a specific date. If they cannot tell you, that is your answer.
  • Firewalls with remote management enabled: Internet-facing management interfaces on firewalls are a known target class. If yours is exposed to the public internet, it should not be.
  • Default credentials: eSentire documented a live exploitation of CVE-2026-35616 in Fortinet EMS this year, where attackers deployed a credential-stealing payload disguised as a legitimate patch file. Fortinet EMS versions 7.4.5 through 7.4.6 were affected. If you are running Fortinet products, verify your version and your patch status today.

The NCSC advisory links to their existing guidance on network device security. Read it. Then ask your IT provider to demonstrate they have implemented it.


2. Manchester Airports Group: 8.7 Million Customers Affected

The UK’s largest airport operator, Manchester Airports Group, which runs Manchester, East Midlands, and London Stansted, has confirmed a data breach affecting 8.7 million customers.

The data involved includes names, contact details, and booking information. That is the full package for a convincing follow-on phishing campaign. An attacker who knows you flew through Manchester in March and can reference your booking reference has a significant advantage over someone firing generic emails into the void.

I will say what the breach notification will not say directly: 8.7 million UK customers is not a niche exposure. A meaningful percentage of UK business travellers and their families are in this dataset. If your staff travel for business through any of the three affected airports, or if your customers do, treat their inboxes as an elevated-risk environment for the next six to twelve months.

The practical concern for SMBs is not the breach itself, you cannot un-expose the data. The concern is what comes next. Spear-phishing using travel context is highly effective precisely because it does not look like generic spam. An email referencing a specific flight, from an address that looks like airport customer services, asking you to verify a refund or update your account, is going to get clicks.

What to do:

  • Remind staff now that any airport or travel-related email asking them to click a link or log in should be verified by navigating directly to the official site, not by clicking the email.
  • If you have customers who travel through these airports, consider proactively alerting them that travel-themed phishing may increase.
  • Check whether your organisation’s travel booking data is held by a third party. If so, ask them what data was involved and whether your organisation is in the exposed set.

The ICO will be taking a close interest in this one. For the airports group, the question of whether notification timelines were met will matter. For everyone else, the question is whether your own incident response plan includes a clear process for handling downstream exposure from third-party breaches, not just direct incidents to your own systems.


3. Microsoft Teams Vishing: This Is Now a Business

Zscaler published research today on a campaign they have been tracking since January 2026. The threat actor, assessed as likely functioning as an initial access broker for ransomware operations, has been targeting organisations through Microsoft Teams vishing attacks.

The playbook is straightforward and effective:

  1. Attackers contact the target via Microsoft Teams, impersonating IT helpdesk staff.
  2. They convince the target to open Quick Assist, Microsoft’s built-in remote assistance tool.
  3. Once inside, PowerShell scripts deploy a Go-based backdoor called GoGRPC.
  4. GoGRPC provides persistent access, which is then sold or used to deploy ransomware.

Zscaler identified four distinct variants of GoGRPC, which tells you this is not a proof-of-concept. This is an active, maintained toolset.

The advisory attributes this campaign broadly to an initial access broker operation. What it does not say is that this class of attack, impersonating IT helpdesk staff over a collaboration platform, has been documented in various forms since at least 2023. The techniques have matured considerably. The use of Teams specifically exploits the fact that many organisations trust inter-tenant Teams messages more than they should, particularly when the sender displays a corporate-looking display name.

For UK SMBs using Microsoft 365 and Teams:

  • Restrict Quick Assist: Microsoft Quick Assist can be blocked or restricted via Group Policy or Intune. If your helpdesk does not use it for legitimate remote support, disable it. If they do use it, ensure staff know that legitimate IT support will never initiate contact via Teams and then immediately request remote access.
  • External message warnings: Microsoft Teams can be configured to display warnings on messages from external tenants. Ensure this is enabled. It will not stop every attack, but it adds friction.
  • Train staff on the specific scenario: Generic phishing awareness training is not sufficient here. Staff need to know that Teams messages from apparent IT staff asking for remote access are a specific, documented attack pattern. The message will look convincing. The urgency will feel real.
  • Verify before you connect: Any unexpected request for remote access, regardless of the channel, should require a verification callback to a known number before the session is opened.

If your IT provider is telling you this does not affect you because your business is too small, ask them how many of the organisations targeted by access broker operations this year thought the same thing.


On the Supply Chain Front

A brief note on the TeamPCP arrests out of Australia today. Two individuals have been charged in connection with a series of developer supply chain attacks. The arrests are welcome. They also underscore something worth stating plainly: supply chain compromises affecting developer tooling and software build pipelines are not confined to large enterprises. Any UK SMB using third-party software, which is all of them, has downstream exposure to supply chain incidents they had no part in causing and may receive no direct notification about.

The TeamPCP case is not the first and will not be the last. If you have software suppliers whose security posture you have never reviewed, that is a gap worth addressing.


What to Do Today

If you have an hour:

  1. Ask your IT provider when your internet-facing VPN or firewall was last patched. Get a specific date in writing.
  2. Disable or restrict Microsoft Quick Assist via Group Policy if your helpdesk does not use it.
  3. Brief your staff on the Teams vishing scenario, not generically, but specifically: fake IT helpdesk, Quick Assist request, do not comply without a callback.

If you have ten minutes:

  1. Forward this briefing to whoever manages your IT.
  2. Check whether any of your staff have travel history with Manchester Airports Group that would make them a plausible spear-phishing target.

Before the next story: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and pass it to someone who needs the heads-up.


Sources

SourceTitleURL
NCSCDisruptive cyber activity highlights risk from internet-exposed systems and edge deviceshttps://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices
The RegisterCybercrooks jet off with Manchester Airports Group customer datahttps://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943
ZscalerHelpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoorhttps://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
BleepingComputerAustralia arrests alleged TeamPCP hackers behind supply-chain attackshttps://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/
eSentireFortinet Vulnerability CVE-2026-35616 and EKZ Stealerhttps://www.esentire.com/blog/fortinet-vulnerability-cve-2026-35616-and-ekz-stealer-attacking-obfuscating-compilers-with-binary-ninja-workflows

Filed under

  • smb-security
  • uk-business
  • social-engineering
  • incident-response
  • vendor-risk
  • supply-chain-risk
  • remote-access