A breach at the Adaptavist Group led to impersonation emails aimed at its customers. It’s a pattern we see again and again: attackers use the trust and context stolen in one breach to launch convincing phishing against everyone in that orbit.
What it means for you
Impersonation works because it borrows legitimacy — a real supplier name, a real project, a plausible request. Generic “spot the dodgy email” advice struggles against messages that look genuinely like a company you already work with.
The defences are layered: strong email security and authentication (SPF, DKIM, DMARC), phishing-resistant MFA, and staff who are trained to verify unusual requests through a second channel. We set all of this up for clients and run regular awareness training to keep it sharp.
Source: The Register, 21 April 2026.