Reformed IT
01158 244 824Request a callback
Cyber security · 4 min read

A few things worth flagging this month.

Fake invoices, a record Microsoft update and a one-in-three attack rate. The detail behind this month's security alerts, with sources.

By Felicity Price · Oct 2026
A few things worth flagging this month. — Reformed ITReformed IT · Nottingham office

Our October client newsletter flagged three things worth knowing: fake invoice scams, a Microsoft security update that’s worth finishing, and how common attacks now are. The newsletter keeps things short on purpose. This is the longer version, with a link to where each figure comes from so you can check our working.

Fake invoices and “our bank details have changed.”

In an invoice or mandate scam, you try to pay a genuine supplier, but a criminal convinces you to send the money to an account they control instead. According to UK Finance’s Annual Fraud Report 2026, these scams cost UK victims £41.3 million across 2,305 cases in 2025. That’s slightly down on the year before, but 68% of the losses (£28 million) came from business accounts. UK Finance’s explanation is a useful one: businesses make genuine, higher-value payments regularly, so a fraudulent one is harder to spot and stop.

The same report describes how it usually works. The criminal poses as a supplier and says the bank details have changed, often after intercepting emails or getting into someone’s email account. And once the money has gone it’s hard to get back: only 48% of the money lost to this type of scam was returned to victims in 2025.

Law firms get impersonated too, which matters if you pay or receive money through solicitors. In March 2026, Linklaters warned of scam emails sent from a lookalike domain (@us-linklaters.com) and purporting to come from one of its lawyers. Norton Rose Fulbright publishes its own fraud alerts about fake invoices that use its name and letterhead. Linklaters’ advice is to phone your usual contact to confirm before you engage with a suspicious message, and Norton Rose Fulbright asks people to contact its fraud alert team first.

What to do about it:

  • If a bank detail changes, or an invoice arrives that you weren’t expecting, ring the supplier on a number you already have. Don’t use the number in the email.
  • Check the sender’s address letter by letter. Lookalike domains swap or add a single character.
  • Have a second person approve any change to who gets paid.
  • Switch on multi-factor authentication for everyone’s email. A lot of these scams start with a compromised mailbox, and we explain how to roll it out without the helpdesk pain in MFA without the friction.

The Microsoft update that’s worth finishing.

Microsoft’s September 2026 Patch Tuesday fixed 972 security flaws, a new monthly record by CrowdStrike’s count (other trackers, such as Malwarebytes, count a handful fewer). 113 were rated critical, and two were already being used by attackers before the fix arrived. That’s what’s known as a zero-day.

Both of those flaws are in Windows itself: CVE-2026-81963 in the Windows Update stack and CVE-2026-85880 in Windows’ internal messaging system (ALPC). In each case the attacker needs to already be on the machine, for example through a malicious download or a phishing email. From there, the flaw lets them take full control of it. So the update doesn’t stop the first foot in the door, but it stops what comes next.

What to do about it: if your laptop has been nagging you to restart and install an update, do it. Updates usually download in the background but only finish installing when the device restarts, so a machine that hasn’t been restarted in weeks can still be running the vulnerable version.

How common are attacks?

Hiscox’s Cyber Readiness Report 2026, based on 6,800 cyber security decision-makers across the UK, Europe and the US, found that nearly one in three organisations were hit by a cyber attack in the last year.

That isn’t a reason to panic. It’s a reason to check that the basics are actually in place, rather than assumed: updates installed, multi-factor authentication switched on everywhere, and a habit of double-checking when money is about to move.

Every figure above links to where it came from.

Felicity Price
Written by
Felicity Price
Marketing Coordinator, Reformed IT
See the team
Keep reading

Related from the team.

Related questions

Have a question this didn't answer?