Webwire Pty Ltd - The Week in Tech: Passkeys, Microsoft 365 Disruption and New Phishing Tactics Put SMEs on Notice
The latest technology and cybersecurity news for SMEs, including Microsoft passkeys, a Microsoft 365 outage, Teams impersonation and new phishing tactics.
The Week in Tech: Passkeys, Microsoft 365 Disruption and New Phishing Tactics Put SMEs on Notice
The past seven days have delivered a clear message for Australian businesses: cloud convenience is valuable, but identity, resilience and human judgement remain central to keeping operations running.
From Microsoft making passkeys the default authentication path to a major Microsoft 365 outage and new phishing techniques designed to bypass automated filters, the latest developments are highly relevant to small and mid-sized organisations.
1. Microsoft begins its shift from SMS codes to passkeys
Microsoft has started rolling out passkeys as the default authentication experience for users of Microsoft Entra ID who still rely on SMS or voice-based multifactor authentication. The change began on 1 September 2026 and will prompt affected users to register a passkey when they next complete multifactor authentication.
Microsoft has also confirmed that its own SMS and voice authentication service will end on 1 February 2027. Businesses that still need those methods will be able to select a supported third-party telecom provider, with provider information and commercial details expected from 18 September 2026.
The change applies to Microsoft Entra ID in the public cloud. Other cloud environments may follow a different timeline.
According to a recent Microsoft identity advisory, passkeys use public-key cryptography and are designed to resist phishing more effectively than SMS and voice codes. That makes the transition more than a product change. It is part of a wider move away from authentication methods that can be intercepted, socially engineered or redirected through SIM swapping.
Why it matters for businesses
Many SMEs still use SMS authentication because it is familiar, easy to deploy and available on almost every phone. However, a code delivered by text does not protect an employee if an attacker has already persuaded them to enter it into a fake login page or has taken control of their phone number.
For business leaders, the Microsoft change creates both a deadline and an opportunity. A planned move to passkeys can reduce account takeover risk, simplify the sign-in experience and demonstrate stronger security controls to customers, insurers and larger supply-chain partners.
It also creates a communications challenge. Employees need to know what a genuine registration prompt looks like, especially because attackers may try to imitate the change with fake passkey setup pages.
Practical steps to take now
- Review which users, administrators, contractors and service accounts still rely on SMS or voice authentication.
- Start a small pilot of passkeys with IT administrators and a group of technically confident staff.
- Choose an approved recovery process that does not depend solely on a phone number or email account.
- Communicate the change through established internal channels and remind staff that IT will never ask for a one-time code over an unsolicited call or chat.
- Record the transition in your security and compliance documentation, including exceptions for users who cannot immediately use a passkey.
Background: Microsoft guidance on passkey deployment provides the technical context, while Microsoft has published the relevant public-cloud timeline in its identity security announcement.
2. A Microsoft 365 outage shows the business risk of cloud concentration
A Microsoft 365 outage that began on 31 August continued into 1 September and affected users across several services. Reports and Microsoft service updates identified problems involving Exchange Online, Outlook, Teams, SharePoint Online, OneDrive for Business, Copilot, Purview and Defender XDR.
Microsoft attributed the incident to a core authentication configuration used by multiple Microsoft 365 services. Recovery began after a fix was applied, but the event demonstrated how a problem in a shared identity layer can spread across email, collaboration, documents and security tools at the same time.
According to industry coverage of the incident, some users could not load or refresh files, search content, synchronise OneDrive or access parts of Teams and Exchange Online. For a small organisation that depends on Microsoft 365 as its central workplace, even a temporary disruption can affect sales, payroll, customer support and internal decision making.
Why it matters for businesses
Cloud services remove the cost and complexity of running many systems in-house, but they do not remove the need for continuity planning. A subscription is not the same as a business continuity strategy.
The outage also highlights the danger of assuming that one vendor can provide every essential capability without a fallback. If email, documents, identity, meetings and endpoint security all depend on the same service ecosystem, one incident can create a broad operational impact.
This does not mean SMEs should abandon cloud services. It means they need to understand their critical dependencies and decide what staff should do when a major platform is unavailable for several hours.
Practical steps to take now
- List the business processes that depend on Microsoft 365 or another single cloud provider, including invoicing, customer support and approvals.
- Define a simple fallback for urgent communication, such as an alternative phone tree, secondary messaging channel or emergency contact list.
- Keep an offline or independently accessible copy of critical contacts, supplier details, recovery procedures and key documents.
- Check how your organisation will access service health information if administrators cannot sign in normally.
- Test a short outage scenario with managers and team leaders, focusing on who makes decisions and how customers are informed.
A useful starting point is Microsoft’s service health guidance, but the bigger task is internal. Your business continuity plan should explain what people do, not just identify which vendor is responsible.
3. Attackers are impersonating IT support through Teams and remote access tools
Microsoft Threat Intelligence has reported a human-operated intrusion campaign that uses Microsoft Teams external collaboration to impersonate IT support staff. The attackers contact employees, build credibility and then attempt to gain remote access or persuade the victim to install software.
The campaign is especially relevant to SMEs because many organisations use outsourced IT providers, casual support arrangements and external contractors. Employees may be accustomed to receiving messages from people outside the business, particularly when a managed service provider or software supplier is involved.
According to a recent Microsoft threat intelligence report, the attackers can use a convincing support pretext to obtain remote access and deploy malware. Microsoft has also previously described hybrid attacks that begin with spam or email bombing, followed by a Teams contact offering to fix the problem.
Why it matters for businesses
This is not simply a phishing problem. It is a trust problem that combines identity impersonation, collaboration platforms and remote administration tools.
An employee may correctly understand that they should not open a suspicious email, yet still accept help from someone who appears to be an IT technician. Once remote access is granted, the attacker may be able to inspect files, steal browser sessions, access password stores or move further into the environment.
The risk is higher when support providers are not clearly identified, when external chat is open to all users, or when remote-control software can be installed without approval.
Practical steps to take now
- Publish a clear rule that IT support will never request access through an unsolicited Teams message or unexpected phone call.
- Require employees to verify support requests through a known phone number or an existing service desk ticket.
- Restrict external Teams communication where practical and review guest and external access settings.
- Block or require approval for remote-control software that is not part of your standard IT toolkit.
- Train staff to report suspicious support contacts immediately, even if they already clicked a link or granted access.
Service providers should also have named contacts, documented escalation procedures and a consistent method for confirming urgent access requests. A short verification process can prevent a long recovery effort.
For additional context, Microsoft provides user-facing advice on recognising phishing through Teams and external chats.
4. Invisible Unicode characters are being used to hide phishing content
A new Microsoft security research report describes a phishing campaign that used invisible Unicode tag characters to split financial terms inside messages. To a person, a word such as funding could still appear normal. To some filters or automated processing systems, however, the hidden characters may interrupt the text and make keyword detection less reliable.
The technique is known as ASCII smuggling. It became widely discussed in the AI security community because invisible characters can hide instructions from a person while still being processed by an AI model. Microsoft researchers now report that a similar technique has been repurposed for traditional phishing and spam campaigns.
The research found that the activity involved finance-themed messages and large-scale distribution. Microsoft said layered protections detected most of the messages through other signals, including sender reputation, URL analysis, authentication checks and machine learning. The lesson is not that email filters have stopped working. The lesson is that no single detection method should be treated as sufficient.
According to Microsoft security research, defenders should normalise or strip invisible Unicode characters before applying content signatures and should treat unusual character patterns as an anomaly signal.
Why it matters for businesses
SMEs often rely on managed email security, which is sensible, but configuration and user behaviour still matter. Attackers continually adapt their messages to exploit gaps between what a person sees and what software processes.
The issue is also relevant to businesses introducing AI assistants. If an AI tool can read email, documents or web content and take actions on behalf of a user, hidden text may become more than a filtering concern. It could influence a summary, recommendation or automated workflow.
This is a strong reminder to treat AI adoption and email security as connected areas rather than separate projects.
Practical steps to take now
- Keep email security controls, anti-phishing policies and threat intelligence feeds enabled and regularly reviewed.
- Ask your provider how it handles invisible Unicode, look-alike domains, QR code phishing and image-based lures.
- Make sure staff know that a familiar-looking message can still be malicious if the sender, link or request is unexpected.
- Apply extra verification to payment changes, supplier bank details and requests for confidential information.
- Review which AI tools can ingest email or documents and restrict their ability to make external changes without human approval.
For most organisations, the practical answer is not to teach employees about every Unicode character. It is to combine layered technical controls with a strong verification culture.
5. The cloud and SaaS estate needs a clearer owner
The week’s stories share a common theme: technology decisions that once looked like routine administration now have direct implications for risk, cost and continuity.
Authentication settings affect account takeover. A cloud outage affects operations. Collaboration tools can become attack channels. AI-enabled workflows can process content that employees cannot easily inspect. These issues are connected by the growing complexity of the modern SaaS estate.
Many SMEs have accumulated cloud services gradually. A team starts with Microsoft 365, then adds accounting software, customer relationship management, payroll, marketing automation, online storage and AI tools. Over time, responsibility becomes unclear. Licences continue renewing, access remains active after staff leave and nobody has a complete view of which provider holds which data.
Why it matters for businesses
Unmanaged SaaS creates financial waste as well as security exposure. Unused licences cost money. Excessive administrator permissions increase the impact of a compromised account. Unknown integrations can expose customer or supplier data. A service may also be essential to operations without appearing in the formal IT register.
This is particularly important for Australian businesses that need to understand privacy, contractual and data-handling obligations. The exact requirements vary by sector and organisation size, but the underlying management principle is universal: know what you use, who can access it and what happens if it fails.
Practical steps to take now
- Maintain a current register of cloud and SaaS services, including the business owner, technical owner and renewal date.
- Review administrator accounts, third-party integrations and dormant user access at least quarterly.
- Confirm how each critical provider handles backups, data export, incident notification and service outages.
- Consolidate overlapping tools where possible and remove services that no longer have a clear business purpose.
- Give every new AI or SaaS purchase a short security and privacy review before staff begin using it.
A lightweight register can be managed in a spreadsheet at first. The important point is to assign ownership and make the review part of normal business operations.
What This Means For Your Business
The most important technology news this week is not one isolated product announcement. It is the growing expectation that businesses must actively manage identity, cloud dependency and AI-related risk. The old approach of setting up a service and leaving it alone is no longer enough.
Start with the basics. Identify where SMS authentication is still in use, prepare users for passkeys and verify that administrators have secure recovery options. Review your Microsoft 365 continuity plan and make sure managers know how the business will communicate during an outage.
Then test the human layer. Ask employees how they would verify an unexpected Teams support request, a payment change or a message from a supplier. Review which AI tools can access company information and ensure automated actions have sensible limits and human approval.
These actions do not require a large security department or an unlimited budget. They require clear ownership, regular reviews and a willingness to test assumptions before an incident exposes them. For Australian SMEs, practical preparation is still one of the most cost-effective ways to reduce cyber risk and protect business continuity.
Call Webwire on 08 9386 0053 or contact us at enquiries@webwire.com.au.