• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
Shoal IT Solutions

Shoal IT Solutions

Managed IT Services London

  • Home
  • Cyber Essentials
  • Blog
  • Support
  • Contact

GOOD THINKING 99!

1 September 2026 by Mike Fish

We are into Q4 of 2026 and I think everyone is hoping for some cooler, wetter weather after this summer’s incredible heatwaves and drought. This month we focus on how AI is transforming email scams and a quick reminder to check the security of your company website.    

Scam emails have evolved

In the past we could easily spot scam emails with bad spelling and grammar an obvious tell, however with these bad actors now using AI to help them, the result is often very convincing. Messages now arrive reading as well as something from a genuine company. With attackers able to feed public details about your company into an AI tool, messages are being produced with the right names, the right job titles and a perfectly believable reason to be in touch such as one of your suppliers asking you to update bank details for an invoice. So how can you protect yourself and your team?

  • Judge an email by what it is asking for rather than how well it is written – money, logins and bank-detail changes are all red flags
  • However urgent, make sure any change to a supplier’s bank details is confirmed by phone, on a number you already have – better to be right than pressurised into making a mistake
  • Update your staff training to focus on slowing down when a message involves money or log ins… bad spelling is no longer the main focus
  • Make sure you have phishing-resistant MFA or passkeys turned on to make it harder for attackers to use a stolen password
  • Make it really easy to report a suspicious email and make reporting part of your office culture so everyone is comfortable to do so
  • Remember that AI hasn’t changed everything so still watch out for:
    • Requests for money, gift cards or payment to a new account
    • Asking for a login, verification code or personal details
    • Threats, deadlines and pushing you to “do something now”
    • Display names and email addresses not matching

Security and your business website 

Most small businesses set up their websites once and then stop thinking about it – it’s doing its job and you have plenty else on your plate. However, neglecting your website is an opportunity for the hackers to break in. Many small business sites run on WordPress and in itself that isn’t the problem, rather the risk is usually the plugins and themes added to it that often don’t get updated for years. Often your business isn’t targeted by your name but identified by automated tools that scan websites looking for known weak spots such as a plugin with a security hole that hasn’t been fixed. This underlines the importance of patching for known holes as soon as updates are released by the plugin maker – if you don’t it stays open and vulnerable.

If you are hacked, attackers often stay under the radar keeping the site running and using it for their own purposes such as:

  • Serving malware to your visitors or pushing them to a page that tries to install something
  • Hidden spam and scam pages that ride on your site’s standing with search engines
  • Copying what people type into your contact or checkout forms, including payment details

The consequences of hacked website include search engines dropping hacked sites down the rankings and browsers blocking them so your clients see a “this site may be dangerous” warning instead of your homepage. If you use a hosted builder most of the security and updates should be handled for you reducing risk, however, if you have a self-hosted WordPress site, make sure that updates are a designated responsibility and that this is regularly monitored. Make sure:

  • WordPress, plugins and themes are updated with automatic updates turned on wherever possible
  • Unused plugins are deleted and replace any that the developer has abandoned
  • A strong, unique password on the admin login is used with MFA if your setup supports it
  • Back up regularly so that even if a site is hacked it can be restored instead of rebuilt
  • Responsibilities for website maintenance are clearly allocated and reviews incorporated into your policy
Category: tech tipsTag: #AI, #hackers, #scam email, #website, #wordpress, cyber security

About Mike Fish

Previous Post:NO FATE

Shoal Computer Solutions Ltd Copyright © 2020–2026
All rights reserved · Company No 4349065
Terms & Conditions · Return to top

21 Ellis Street, London, SW1X 9AL
Contact Us