Updated October 2026 to our current guidance. The original reporting date is unchanged.
A texted code proves someone typed it. It does not prove where they typed it. Here is how a rented kit uses that gap, three things you can do today, and the other way in that needs no click at all.
Count What’s on Your Computers →See how many programs each Windows PC has, how many are current, and how many need updating. No credit card needed.
In this article
Hey folks! Most offices I talk to have two things in place for email. A spam filter catches the junk, and a second sign-in step, usually a six-digit code texted to a phone, stands behind the password. Both do real work, and you should keep both.
There is one thing the code was never built to do, and a rented kit is designed around it.
Here is the way it goes. Your accounts-payable person, a careful one who has never fallen for anything, opens an email that looks like it came from a vendor you really use. It mentions a real invoice number and is signed by a name they recognize. It says a payment detail changed and asks them to sign in to confirm.
The link opens a Microsoft sign-in page that looks exactly like the real one. They type their email, their password, and the six-digit code off their phone. The page says thank you. Nothing looks wrong, and they go back to their afternoon.
The person on the other end now reads that mailbox for a while, learns who pays whom, and waits for a real invoice so they can change the bank details on it. They did not need to be skilled to set any of this up. They rented it.
Kits like this are rented by the month, like any other software subscription. Microsoft described one in September 2026 that sold for $1,500 up front and $500 a month, used AI to tailor its emails to each target’s job, and had reached more than 12,000 inboxes before it was taken down (Microsoft, September 22, 2026). The renter supplies a list of targets and the kit does the rest.
An AI model reads what is public about each person, the company website, a LinkedIn page, an old press mention, and writes each one a different email that sounds like it came from their own bank, a coworker, or a vendor they pay. The kit builds the fake sign-in page and sends the batch. A spam filter blocks what it has seen before, and it has not seen any of these.
A good-looking scam used to take effort. Now it takes a monthly fee.
Most owners have never had this explained, so here it is in plain English.
Think of the fake page as a puppet standing between your employee and the real Microsoft. When your employee types a password into the puppet, the puppet types the same password into Microsoft at the same moment. Microsoft texts the code. Your employee reads it off the phone and types it into the puppet, and the puppet passes it along. The code worked exactly as designed. It proved the right person typed it. It could not tell that they typed it into the wrong page.
One more step. Once you are signed in, Microsoft gives your browser a kind of day pass, a small file that says “this one is already logged in,” so it does not ask for the password all day. The puppet keeps that pass, and from then on it needs neither the password nor the code.
So the second sign-in step is still worth having. It stops a lot of lazy attacks. It just has a limit, and knowing the limit tells you what to change.
None of these costs anything to start.
The typos are gone, so stop grading the writing and grade the ask. Anything that pushes you to hurry, keep it quiet, make a payment, or sign in from a link is the signal, however clean it looks. Give your team the rule out loud: a real vendor never minds if you call a number you already have on file to confirm a change before you act.
Ask whoever runs your email to switch your second sign-in step from a texted code to a phishing-resistant one: a passkey, or an app prompt where you tap a matching number on the screen. There is no code to read out and type into a fake page, so the puppet has nothing to pass along. Your IT person may call it “phishing-resistant MFA.”
A stolen sign-in is one way into a business. A program that has not been updated is another, and it needs nobody to click anything. That one is covered in the next section.
These messages are written to get past a busy person on a Tuesday afternoon. Expecting everyone to catch every one is a hope, and a plan needs more than hope: a couple of habits and fewer ways in.
My own father let one of these people onto his computer, and I do this for a living. I stopped them remotely before they reached the spreadsheet with his bank passwords.
I have spent 35+ years in cybersecurity. FBI InfraGard trainer. Dozens of managed clients since 1991. None has had ransomware.
Most setups keep Windows current, and that part usually runs fine. Here is the boundary few people mention. Windows Update never touches third-party software. The PDF reader, the accounting add-on, the old tool on a back-office machine each update on their own, or not at all. Nobody did anything wrong. That is where Windows Update’s job ends.
So who has been checking the rest?
Here is a quick way to find out. Before you run anything, guess how many programs are on one of your computers and write the number down. Then run the Reveal Scan on that Windows PC. It counts what is installed and tells you how many programs are current and how many need updating.
If the second number is bigger than you expected, that is common. You don’t have to be able to do this. We’ll do it with you.
Mostly, and keep both. The kit is built around their two limits: a filter has nothing to match against a brand-new message, and a texted code can be passed along by a fake page. Swapping the texted code for a phishing-resistant one closes the second limit.
The programs that need updating are a separate question, and counting them takes a few minutes.
The Reveal Scan counts what is installed on each Windows PC: how many programs are current and how many need updating. Read-only, no credit card needed.
Count What’s on Your Computers →The scan is on us. If you want step-by-step instructions afterward, that’s a paid report, and you’ll see the price before you decide.
If you run it and never speak to us again, that’s a fine outcome.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
Join the owners who get Craig's Insider Notes every week.