A breach at the Adaptavist Group led to impersonation emails aimed at its customers. It’s a pattern we see again and again: attackers use the trust and context stolen in one breach to launch convincing phishing against everyone in that orbit.

What it means for you

Impersonation works because it borrows legitimacy — a real supplier name, a real project, a plausible request. Generic “spot the dodgy email” advice struggles against messages that look genuinely like a company you already work with.

The defences are layered: strong email security and authentication (SPF, DKIM, DMARC), phishing-resistant MFA, and staff who are trained to verify unusual requests through a second channel. We set all of this up for clients and run regular awareness training to keep it sharp.

Source: The Register, 21 April 2026.