All issues
Tech & Security Intelligence Issue 011 · 3 Aug 2026

The Weekly
Brief

The phishing page is now Microsoft's own login page. Passkeys become the Microsoft 365 default on 1 September, New Zealand's scam numbers jump again, and Kiwi firms say they'd survive an outage — but haven't tested it.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 6 min read

In this issue

01 Threat Alert

The phishing page is real — attackers are stealing accounts through Microsoft's own login screen

Researchers at Check Point have documented a phishing campaign that does away with the fake login page altogether. The bait is an email dressed up as a Microsoft Planner task notification, claiming HR has shared payroll and benefits updates and listing several "overdue" tasks to create urgency. Click the link and you land on the genuine Microsoft sign-in page at login.microsoftonline.com — the real thing, with the real certificate.

You sign in as normal, complete MFA as normal, and are then shown a permission request. Approve it, and Microsoft itself redirects you to an attacker-controlled endpoint hosted on AWS API Gateway, which captures the authorisation token — handing the attacker access to the account without ever learning the password. Between 25 June and mid-July, Check Point counted over 200 phishing emails aimed at around 120 organisations across a spread of industries and countries.

02 Microsoft 365

Passkeys become the Microsoft 365 default on 1 September — and text-message codes are on the clock

Microsoft has published the timetable for the biggest change to Microsoft 365 sign-in in years. From 1 September 2026, passkeys become the default authentication experience in Microsoft Entra ID. Any user currently set up for SMS or voice-call MFA will be automatically enabled for passkeys and, the next time they sign in and complete MFA, nudged to register one. By default that nudge can be snoozed indefinitely — but it will keep appearing.

The hard deadline comes later. On 1 February 2027, Microsoft-provided SMS and voice delivery is retired entirely. After that date, any user whose only MFA method is a text or a phone call gets a blocking prompt: they must register a passkey before they can sign in at all. Microsoft is explicit that there is no opt-out from the February behaviour — it applies to every tenant. Organisations with a genuine regulatory need for SMS can contract a telecom provider through the Microsoft Security Store; details land 18 September 2026 and configuration opens 30 October 2026. Anyone already on passkeys, Windows Hello or a FIDO2 key is unaffected.

03 Scams

NZ scam numbers jump again — fake shops up 87%, remote-access attacks up 73%

Security vendor Gen released its half-year threat report in July, and the New Zealand figures for the first half of 2026 all point the same way. E-shop scams rose 87% — counterfeit online retailers that take a card payment and deliver nothing. Malicious remote-access incidents rose 73%. Tech-support scams climbed 27%, and "Scam-Yourself" attacks — where the victim is talked into installing the malware themselves — rose 45%.

The report's argument is that the tell-tale signs people were taught to look for have largely gone. Rather than obviously dodgy websites and broken English, fraud is now embedded inside services people already trust: hotel and travel booking systems, messaging apps, software update channels and online advertising. Globally the same report tracked government-impersonation scams up 387% and over 304 million fraudulent ad impressions across the EU and UK in a single month.

04 New Zealand

85% of NZ firms think they'd survive an outage. Only 39% have tested it

Datacom released its Annual Data Sovereignty Report today, based on a survey of 155 senior New Zealand business and technology leaders, and the gap between confidence and evidence is the standout finding. 85% said they were confident of maintaining critical services through a disruption. Only 39% had actually tested their recovery capability in the past six months — and 13% have never tested it at all.

The same pattern runs through the rest of the data. 79% described their backup strategy as mature, but only 35% had a formal written policy on where critical data is stored, and just 41% had a documented exit or migration plan for getting data back out of a provider. 83% said they worried about offshore data storage, though 64% keep sensitive data solely in New Zealand. 45% reported that AI adoption is now shaping their infrastructure decisions.

Tip of the week

Stop staff approving apps into your Microsoft 365 — and start on passkeys

Stories 01 and 02 share a single afternoon's work. First, turn off user consent for applications in your Microsoft 365 tenant. By default, an ordinary staff member can grant an outside app permission to read their mail and files — that one prompt is the entire payload of the phishing campaign in story 01, and switching it to "admin approval required" removes the risk for everyone at once. While you're in there, review the apps that already have access; most tenants have two or three nobody recognises, and they should go. Second, get ahead of the passkey change: find out who is still on text-message MFA, and register passkeys for them now rather than in a queue of support calls on 1 September. Start with the accounts that would hurt most — anyone in finance, anyone with admin rights, and the shared or service accounts that no single person owns and everyone forgets. Both jobs are free, take well under an hour, and each removes a whole category of incident rather than reducing it. If you'd rather we did it, ask and we'll pull the report and make the changes with you.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup