
Weekly Briefing • September 18, 2026
Nothing this week came through the firewall. The most expensive item was an email with no attachment, no link, and a clean authentication record. The one with the most medical records attached happened on a network in San Francisco that belongs to a software company most patients have never heard of. The third moved client files out of a practice through a consent screen, in about the time it takes to click Allow.
Your security controls sit around your network. All three of these happened outside it — in your payment approval process, in a vendor's building, and in a browser tab. Here's what happened, and what it means for how your firm operates.
The Invoice Passed Every Security Check, Because There Was Nothing to Check
Between August 3 and 5, Microsoft tracked a single campaign of more than a million emails, 87.7 percent of them landing in US inboxes. Each one impersonated an executive at the company receiving it and asked accounts payable to process an ACH payment of just under $50,000. Underneath the executive's signature sat a ServiceNow subscription invoice: branding, invoice number, issue and due dates, itemized lines, and bank details pointing at accounts the attacker controlled. Microsoft found no evidence that ServiceNow, or any other company named in those emails, was compromised. The whole operation ran on a lookalike domain registered on July 31, days before the first message went out.
Here is why filtering did not stop it. There was no attachment to scan and no link to check, because the invoice was drawn directly into the body of the email as HTML. The executive's name appeared only in the display name, the signature, and the reply-to label, while the message itself was sent through a real, working third-party email service. SPF, DKIM, and DMARC all check the sending service, and the sending service was legitimate, so the mail passed every authentication test and arrived with no warning banner attached to it. The fraud lived entirely in the parts a person reads and a filter does not.
Key Insight
Every signal that made that invoice look approved — the name in the From field, the signature block, the invoice layout, the forwarded thread underneath it — was typed by the person asking for the money. None of it required access to anything you own.
Microsoft also found the fingerprints of generative AI in how the templates were assembled: heavy HTML commenting, near-identical structure across samples, the same invoice details reused while the company and executive names changed for each target. That is mass production, and it means the version aimed at a twelve-person practice costs the sender no more than the one aimed at a hospital system. Microsoft listed IT services, business advisory, and consumer goods among the industries hit, and nothing in the method is specific to any of them. The tells that survived are human ones: the quoted "forwarded" conversation carries no date headers, which genuine forwarded mail always has; the subject lines use phrases like "due bill" and a misspelled "ACH Parment"; and in one thread the CEO asks not to be copied, then announces in the next message that he is sending it himself. Tell whoever opens your mail to read the thread, not the signature. Full analysis here: AI-Assisted Executive Impersonation Fuels Invoice Fraud at Organizations.
Your Patients' Records Were Taken From a Building You Do Not Own
zHealth, a San Francisco company selling cloud practice management and electronic health records software, has reported that 118,563 people had information exposed: names, medical information, and health insurance information, varying by person. The dates are the part to sit with. Someone was inside zHealth's network between January 20 and January 21 of this year, roughly one day. The company did not learn that information may have been copied until around June 15. The review establishing whose data was actually involved finished on September 3. Intrusion to finished answer: about eight months. Affected people are being offered twelve months of single-bureau credit monitoring. zHealth has not said how the attacker got in.
If your practice runs on a hosted EHR or practice management platform, that timeline is part of what you bought. Your patients' records sat in a building you do not own, the window opened and closed before anyone noticed, and your first notice arrives in a letter you had no hand in writing. The shape repeats across the same set of disclosures: a benefits administrator traced its breach to a single employee email account and still reported Social Security numbers exposed, and one intrusion at a credentialing vendor reached about 75 of its customers at once. One break-in at a vendor becomes a notification obligation at every practice on the platform.
Two things follow from that. The call worth making this month is to your EHR or practice management vendor, asking in writing which of your patient records sit in their environment and how quickly they commit to telling you when something happens — your business associate agreement entitles you to that answer, and the regulatory clock starts running on you whether or not the vendor is prompt. The second is what you tell patients who ask. Credit monitoring watches for new credit accounts being opened. It does not watch claims submitted to a health plan or prescriptions filled in someone else's name, which is what medical identity theft actually looks like. The check that finds that is reading the explanation of benefits statement line by line. Full analysis here: Health Records Vendor Discloses Data Breach Affecting 118,000 Individuals.
Your Staff Signed Into an AI Tool. Nothing on Your Network Noticed.
Intezer reviewed roughly 16.9 million enterprise security alerts and found about 73,000 tied to AI tools and agents, a volume that grew 685 percent between February and June this year. Sorted by outcome, 94.1 percent were noise, 5.8 percent were genuine exposure, and 0.02 percent were real attacks. That headline is about alert fatigue inside large security teams, which is not your problem if you have eleven people and no security team. The second finding is.
A large share of AI use never produces a security alert at all, because nothing runs on the machine. Somebody grants a third-party AI application consent to their Microsoft 365 account, or pastes a document into a chat window. Both move your information to an outside company, and neither one looks like an event to any tool watching the endpoint. That is exactly what the researchers found across customer tenants: OAuth consent granted to AI applications, first sign-in events for new AI services, and clusters of data-protection alerts for uploads into generative AI tools. They put the consequence for firms like yours in the right register — client files and contract terms sent to a processor nobody approved is a disclosure question, not a tidiness question.
Three questions you can answer this month without buying anything: which AI applications currently hold standing access to your Microsoft 365 tenant, and who approved them; whether the free tier your staff signed into permits prompts to be retained for training; and whether your engagement letters or patient consents actually cover sending that material to a third party. In the environments we manage, a consent grant handing an outside application standing access to mail or files shows up as an identity finding rather than disappearing into tenant logs, which is the only place that activity leaves a trace. The same research also found AI brand names being used as bait: an invoice fraud lure citing a supposed Anthropic approval to justify a large payment, a fake Gemini Ads invitation, and an "OpenAI Partner Summit 2026" invite delivered through genuine Zoom infrastructure. Those land in your finance inbox, not with your IT provider, which is where this briefing started. Full analysis here: Enterprise AI Adoption Reshapes SOC Detection for Claude, Codex and Cursor.
Also on Our Radar This Week
China-Linked Actors Exploit Chrome and Windows Zero-Day Chain to Deploy GRIMWEDGE — Last week's briefing noted that two of September's patched flaws were already being exploited. Volexity has now shown what one of them, CVE-2026-85880, was being used for: a chain of three bugs, two in Chrome and that one in Windows, that turns a single click into code running on the machine. The targets were non-governmental organizations, so this is not aimed at your practice. Two details are, though. The lure linked to a genuine US university website and abused a flaw on that site to bounce visitors onward, so hovering over the link showed a real .edu domain and told the reader nothing. And Chrome downloads its update in the background but does not run the new version until the browser is restarted, which means an inventory report saying every machine is on the current version is not the same as every machine running it. Anyone who has kept forty tabs open for three weeks is still on the old one. Closing the browser is the whole fix.
Fake AI Trading Agent Steals Crypto Wallet Passwords and Deploys XWorm — HP spent April to June tracking a website advertising an autonomous AI trading agent, and what it installed is the useful part. The download contained a genuine Microsoft-signed Windows utility, renamed "Trading Agent.exe," whose only job was to satisfy the reputation check so Windows raised no warning, plus an attacker library beside it that the signed program obligingly loaded. The same research followed invoice-themed campaigns from the same toolkit to XWorm, a remote access tool that gives an operator hands-on control of the machine, and to stealers that read saved browser passwords. Two of the signed installers HP examined change the browser's default search engine and keep the change after they are uninstalled. A signature tells you who built a file. It does not tell you what the file does.
One Thing to Do This Week
Write one sentence and hand it to whoever pays your invoices: "Any invoice over an amount we set, and any request to change where a payment goes, gets confirmed by phone on the number already in our records before it is paid — including when the request comes from me." Say that last part out loud to them. This fraud works because a clerk who follows the rule is, in that moment, questioning the owner, and the rule only holds if it came from the owner first. The number in the invoice, the number in the signature block, and the number in the email footer do not count; the point is to move the conversation onto a line the sender does not control. Microsoft's campaign asked for just under $50,000, and finance teams commonly set the threshold somewhere in the low five figures. This takes one conversation and a note above the desk.
Get the Monthly Briefing
Once a month I pull the threats that actually mattered into one short read — what happened, what it means for firms like yours, and the one thing worth doing about it. Subscribe using the form at the foot of this page.
Brian Sammons has managed IT environments for Ohio professional service firms — medical, dental, legal, accounting, and financial — since 2004. He writes the Weekly Briefing for the owners, administrators, and IT managers responsible for keeping those firms running: what happened in security this week, and what it means for yours.
Questions about how this affects your environment? Schedule 15 minutes and I'll walk you through it.