Posts

Showing posts from August, 2026

The US Department of Homeland Security Was Warned About a Breach — Twice — Before It Happened. Both Times, Someone Decided It Was Nothing

Image
Case Study Alert Fatigue August 2026  ·  7 min read The US Department of Homeland Security Was Warned About a Breach — Twice — Before It Happened. Both Times, Someone Decided It Was Nothing. In May 2026, security systems flagged intruders inside a major federal information-sharing network. An analyst looked, and decided it was nothing. Roughly a week later, the same intruders returned, and got flagged again. An analyst looked, and decided it was nothing a second time. Three weeks after the first alert, the breach was finally confirmed — backdoors installed, credentials stolen. This isn't a story about a missing alarm. The alarm went off twice. It's a story about what happens after it does. Most breach stories in this series describe a gap in defenses — a password nobody changed, a device left exposed, a warning that never arrived. This one is different, and in some ways more unsettling, because nothing was missing. ...

69% of Ransomware Victims Refused to Pay Last Year — the Highest Rate Ever Recorded. Here's What Changed.

Image
Good News What's Working August 2026  ·  7 min read Most of what this series covers is a warning. This one isn't. New research shows that more businesses said no to ransomware demands last year than at any point on record — and the reason isn't luck. It's preparation, catching up. Here's the record-breaking number, and a look back at every quiet win this series has documented this year that never made a scary headline. Ransomware coverage tends to follow one shape: the number of attacks goes up, the story gets written, everyone feels a little worse about the internet. That shape is accurate as far as it goes — attacks are up. But it leaves out the half of the story where businesses are winning, quietly, in ways that don't make headlines because nothing dramatic happened. This post is about that half. Verizon's newest global breach research, drawing on real incident data from the past year, found ...

One in Four Breaches Is Now AI-Enabled. Here's Every Way That's Shown Up in This Series.

Image
New Research Synthesis August 2026  ·  8 min read For most of this year, the AI-powered attacks we've covered read like isolated, almost freakish stories — a subscription phishing kit, a ransomware attack that fixed its own error in 31 seconds, an email assistant that helped rob its own employer. IBM's newest global breach research shows they were never isolated. One in four malicious breaches now involve AI, up 56% in a single year, and they cost businesses a million dollars more than an ordinary breach. Here's the number, and every place it's already shown up in stories we've told this year. Every time this series has covered an AI-related attack, there's been an implicit question sitting underneath it: is this a genuine trend, or a handful of striking anecdotes that make for a good headline? A subscription phishing kit is alarming. So is a ransomware attack that fixes its own mistakes. But two or three ...

Six Government Agencies on Two Continents Just Warned About a Ransomware Franchise. It Even Rewrote Its Own Victim's MFA to Let Itself In.

Image
Government Advisory Ransomware August 2026  ·  8 min read On August 10, the FBI, CISA, the NSA, the US Secret Service, the Department of Defense Cyber Crime Center, and South Korea's National Police jointly warned about a ransomware operation that doesn't run like a gang anymore — it runs like a franchise. The people breaking in and the people who wrote the software are no longer the same people. One documented intrusion is the kind of detail that changes how you think about multi-factor authentication. Here's how the operation is structured, what actually happened, and what stops it. Most of the ransomware coverage in this series has described a single group doing everything: breaking in, moving around, encrypting, extorting. The operation described in this joint advisory works differently, and the difference matters, because it's where a lot of modern ransomware is heading. Rather than one team running sta...

Twelve Questions to Ask Your IT Provider — and What a Good Answer Sounds Like.

Image
Practical Guide Keep This One August 2026  ·  9 min read Across this series we've told you a dozen times to "ask your IT provider." We've never given you the questions. So here they are — the twelve that matter most, why each one matters, and how to tell a reassuring answer from one worth following up on. None of them require any technical knowledge to ask, and a good provider will be pleased you did. Most small business owners have the same relationship with their IT provider: things work, occasionally something breaks and gets fixed, an invoice arrives monthly, and security is assumed to be handled somewhere in there. It usually is, at least partly. But "assumed" is doing a lot of work in that sentence, and the gap between what an owner thinks is covered and what's actually covered is where most unpleasant surprises live. The awkwardness is that the conversation feels hard to start. Nobo...