August 2026 Newsletter
Posted By: Mark Monday 21st September 2026 Tags: AI, Apple, Artificial Intelligence, Big Tech, cyber crime, Cyber Security, Data Breach, Data Protection, Data Theft, ISO Certification, Meta, Newsletter, phishing, ransomware, Social Engineering, Social Media, technology, vishing, VPNThis month: Social engineering business risks, big tech’s open letter to businesses, Meta’s lawsuit settlement, August IT news review – plus the latest LaneSystems news.

Social Engineering: The Human Risk Every Business Must Address
What Social Engineering Means — And Why It Targets People, Not Systems
Social engineering is one of the most common and effective techniques used by cyber criminals today. Instead of breaking into networks through technical weaknesses, attackers focus on manipulating people. They use trust, urgency, authority, fear, or simple distraction to persuade someone to hand over information, approve access, or click something they shouldn’t.
For businesses, this makes social engineering particularly dangerous. Even organisations with strong firewalls, secure passwords, and modern security tools can be compromised if just one employee is tricked at the wrong moment. Social engineering takes many forms — phishing emails, vishing phone calls, smishing text messages, fake websites, impersonation attempts, and even fraudulent invoices that look completely legitimate. The goal is always the same: convince someone to act quickly without stopping to question what they’re seeing.
How Social Engineering Attacks Target Businesses
Cyber criminals tailor social engineering attacks to fit real business processes. Common examples include:
-
Phishing emails that appear to come from Microsoft, HMRC, suppliers, or senior staff, asking the recipient to log in, update details, or open an attachment.
-
Vishing calls where attackers impersonate IT support, finance teams, or management to pressure employees into sharing access codes or approving payments.
-
Smishing messages sent to mobile phones, often pretending to be delivery updates, bank alerts, or MFA prompts.
-
Business email compromise (BEC) where attackers gain access to a real mailbox and use it to redirect payments or request sensitive information.
-
Fake supplier invoices inserted into genuine email chains after a mailbox has been compromised.
These attacks work because they blend seamlessly into everyday business activity. Staff are busy, messages look familiar, and attackers know how to mimic the tone and timing of legitimate communication.
Real-World Social Engineering Incidents — And Their Impact
In the last month, Apollo Global Management suffered a four-day breach after attackers talked their way into its cloud systems, gaining access to personal data including names, addresses and Social Security numbers . The social engineers posed as colleagues or IT staff to harvest login and MFA credentials.
Some of the world’s largest organisations have fallen victim to social engineering over the years, proving that no business is immune:
-
Twitter: In 2020, Attackers used phone-based social engineering to convince employees to hand over internal access credentials. This led to the compromise of high-profile accounts including Apple, Barack Obama, and Elon Musk, resulting in global disruption and reputational damage.
-
Uber: In 2022, a hacker gained access to internal systems by tricking an employee into approving a fraudulent MFA request. Once inside, the attacker accessed internal dashboards, Slack channels, and administrative tools.
-
Sony Pictures: As far back as 2014, Social engineering was used to gain initial access leading to a major breach that leaked confidential data, disrupted operations, and caused long-term financial and reputational harm.
These incidents highlight a simple truth: even organisations with world-class security can be breached if attackers successfully manipulate a single individual.
The Cost of Social Engineering and Data Breaches for SMEs
While large companies make headlines, small and medium-sized businesses often suffer the most severe consequences. According to UK government data, the average cost of the most disruptive cyber breach for SMEs is £3,550, though industry research places the typical SME impact closer to £6,400. More serious incidents can cost UK businesses £195,000 on average, and an IBM report on fully confirmed data breaches shows costs exceeding £3 million.
For smaller organisations, even a short period of disruption can have long-lasting effects. Invoice fraud, payroll redirection, or compromised email accounts can create financial strain, damage client trust, and require extensive remediation.
Mitigating Social Engineering Risks — Practical Steps for Businesses
The good news is that social engineering risks can be significantly reduced with the right approach:
-
Regular awareness training so staff understand how attackers operate.
-
Clear reporting processes for suspicious emails, calls, or messages.
-
Multi-factor authentication (MFA) to protect accounts even if passwords are compromised.
-
Controlled phishing simulations to identify vulnerabilities and improve response behaviour.
-
Strong supplier verification processes to prevent invoice fraud.
-
Up-to-date security policies that guide staff on safe communication and data handling.
Technology plays a role, but people remain the first line of defence — and the most effective when properly equipped.
LaneSystems provides structured phishing and vishing awareness training designed to help employees recognise real-world social engineering attempts and respond confidently. For businesses across the North-East, this training is a practical way to strengthen cyber resilience and reduce the likelihood of costly incidents. Get in touch for more details.

LaneSystems News
Charity News
We continue our Hospice partner support by donating 6 monitors — including 3 donated by our partner Origin Storage — worth £900, for use by the nurses to help with the vital work that they do.
Phishing & Vishing Training: Strengthening Your First Line of Defence
Phishing and vishing attacks remain one of the most effective ways criminals breach organisations — not by breaking systems, but by manipulating people. Even well-trained, experienced staff can be caught off guard by messages or calls that appear completely legitimate. Attackers use urgency, authority, and familiarity to create pressure, and as highlighted in last month’s article, a single successful attempt can lead to credential theft, financial loss, or unauthorised access deep inside a business’s systems .
That’s why structured phishing and vishing training is no longer a “nice to have” — it’s a critical layer of cyber protection. Real-world simulations and guided awareness sessions help employees recognise the subtle cues that attackers rely on, giving them the confidence to pause, question, and report suspicious activity before damage occurs. Organisations that take this proactive approach significantly reduce the likelihood of successful attacks and strengthen their overall resilience .
LaneSystems provides tailored phishing and vishing training designed specifically for busy teams who need practical, actionable skills. Our sessions help staff understand how modern social-engineering attacks work, what red flags to look for, and how to respond safely under pressure. If your business wants to reduce risk, protect sensitive information, and build a more cyber-aware workforce, now is the ideal time to invest in this training.
Get in touch today to for more information about our phishing and vishing awareness training.
ISO Certifications
When many businesses hear the word ISO, they immediately think of policies, audits and certificates on the wall. And that is often where the misunderstanding begins.
Most SMEs are already carrying out much of what ISO requires. They are onboarding staff, managing suppliers, resolving issues and continuously improving services. The challenge is often not doing the work itself. It is connecting the work together in a structured way.
At LaneSystems, we believe management systems should become part of the normal rhythm of the business rather than a collection of documents sitting in folders and only being opened during audit season.
Because the strongest ISO implementations do not simply help businesses achieve certification. They help businesses run better.
If you’re a business in the north-east of England, contact us today to find out more about our help with gaining ISO certification and how it can help your business work more effectively.

Tech Giants Warn of Rising AI-Driven Cyber Threats
More than 100 major technology and financial firms — including Google, Microsoft, OpenAI, Anthropic, Adobe, Oracle, Visa and MasterCard — have signed an open letter urging governments and businesses worldwide to strengthen their cyber-defences before AI-powered attacks become significantly more advanced. The letter warns that AI-enabled cyber-attacks will grow “more widespread and more sophisticated” within months as the technology rapidly improves .
The signatories argue that current “status quo” security measures are no longer sufficient and highlight years of under-investment in critical infrastructure protection . They call for governments to provide defensive AI tools to essential services such as hospitals and water utilities, and for tech companies to offer responsible access, funding and hands-on support to under-resourced defenders.
The letter follows a series of high-profile breaches, including AI agents organising themselves to bypass security and successfully attack Hugging Face — described as the world’s first AI-enabled cyber-attack . Recent intrusions into US government systems have further heightened concern .
While the letter is global in scope, its message is directly relevant to UK organisations: cyber-attacks are increasing, AI tools are evolving rapidly, and both public and private sectors are being urged to raise their defensive standards before the threat escalates further.

Meta’s $18bn Child-Safety Settlement
Meta has agreed to pay up to $18bn (£13.3bn) to almost every US state after a major lawsuit accused Facebook and Instagram of harming children through addictive design and weak safety controls. As part of the settlement, Meta will introduce new measures for under-18s, including time limits, screen-time warnings, and enhanced parental controls . These changes apply only in the US for now, and Meta has not admitted wrongdoing.
The UK already has stricter rules. Under the Online Safety Act, young people face limits on harmful content, and from 2027, the UK will introduce a full social media ban for under‑16s . Unlike the US approach, the UK’s restrictions are legal requirements rather than voluntary platform changes.
However, experts say the Meta settlement could still influence UK policy. Now that Meta has accepted these safety features in the US, other countries — including the UK — may push for the same protections to be rolled out globally . Former Meta executives told the BBC they expect many of these measures to expand worldwide over time.
For UK businesses and parents, the settlement signals a broader shift: social platforms are being pressured internationally to redesign their services with child safety at the forefront.

August IT News Review
Here are some other notable infosec stories from the month.
Public Distrust Over Government Access to Encrypted Chats
Recent polling shows that around two-thirds of UK adults do not trust the current or any future government with access to their encrypted messages. Concerns centre on privacy, surveillance overreach, and fears that weakening encryption could expose users to cybercriminals. The debate has intensified following proposals to expand government powers over digital communications.
For businesses, the findings highlight a wider public expectation that private messaging — including internal corporate chats — should remain secure, strongly encrypted, and protected from unnecessary access.
Manchester Airports Group Customer Data Stolen
Manchester Airports Group (MAG) confirmed that cybercriminals accessed customer data after breaching a third-party supplier responsible for car park and booking services. While airport operations were unaffected, exposed information may include names, contact details, and booking references. MAG says it is working with the supplier to investigate and has notified regulators.
The incident underscores the growing risks posed by supply-chain vulnerabilities, where attackers target smaller partners to reach larger organisations. Businesses relying on external service providers should review vendor security controls and ensure robust contractual protections.
Carhartt Data Breach Impacts 12.9 Million Customers
US workwear brand Carhartt disclosed a data breach affecting 12.9 million customers, significantly lower than the 24 million claimed by the ShinyHunters cybercrime group – but still a significant size. Stolen data reportedly includes names, email addresses, and account details, though no payment information was taken. Carhartt has reset passwords and advised customers to remain alert for phishing attempts.
The incident highlights how criminal groups often exaggerate breach sizes to increase pressure or boost the value of stolen data. It also reinforces the importance of strong password hygiene and multi‑factor authentication.
Iran-Linked Cyberattack Shuts Down UK Power Plant
A UK power plant was temporarily taken offline following a cyberattack now attributed to an Iran-linked threat group. The incident disrupted operations but did not cause wider grid instability. Investigators say the attackers exploited vulnerabilities in industrial control systems, demonstrating the increasing sophistication of state-aligned cyber activity targeting critical infrastructure.
The event has renewed calls for stronger resilience measures across the UK’s energy sector, including improved segmentation, continuous monitoring, and rapid-response protocols. It also serves as a reminder that geopolitical tensions can spill over into domestic cyber risk.
Ransomware Criminal Poses as Recovery Firm to Steal Payments
Security researchers uncovered a case where a ransomware operator impersonated a legitimate data-recovery company to scam other cybercriminals. The attacker approached ransomware victims claiming to help negotiate or recover data, then diverted ransom payments for themselves.
The scheme highlights the chaotic and opportunistic nature of the cybercrime ecosystem, where criminals frequently target one another. For legitimate organisations, it reinforces the need to verify any third-party claiming to offer recovery or negotiation services. Businesses should rely only on trusted incident-response partners and avoid unsolicited offers of assistance.
Need Cyber Security?
If you’re a business in the North East of England and looking for professional and reliable cyber security services, IT consultation, and general IT services to keep your company cyber secure, get in touch. Cybersecurity is a continuous process, and staying proactive is key to safeguarding digital assets.



