Posts

9 Out of 10 Small Businesses Have a Compromised User Right Now. Most Don't Know I

Image
Threat Intelligence Identity Risk June 2026  ·  8 min read The Guardz 2026 State of MSP Threat Report analyzed six months of real telemetry from SMB environments worldwide. The headline finding is the most alarming number in small business cybersecurity this year — and almost nobody is talking about it yet. Every post in this series has described the risk of credential compromise — what it costs, how it happens, how attackers use it, and what to do about it. This post contains the research that puts a number on exactly how widespread that compromise actually is inside real small businesses right now. In April 2026, Guardz published its 2026 State of MSP Threat Report — six months of telemetry data from September 2025 through February 2026, drawn from SMB environments managed by IT providers across North America, EMEA, and APAC, covering billions of audit events across Microsoft 365, Google Workspace, endpoint, and ...

The FBI Just Warned 6.5 Million World Cup Fans. Your Business Has a Problem Too.

Image
Breaking News Cyber Awareness June 2026  ·  7 min read The 2026 FIFA World Cup kicks off June 11. The FBI has issued a formal warning about fake event-related websites designed to capture personal information, payment information, and login credentials from fans searching for tickets. What the warning does not say is what those stolen credentials can mean for the businesses those fans work for. Editorial note: This article is for defensive cybersecurity awareness only. It does not link to, reproduce, or enable access to fraudulent sites. The examples below have been kept generic so employees can recognize risky patterns without creating a directory of scam infrastructure. On May 27, 2026, the FBI's Internet Crime Complaint Center published a formal public service announcement warning that criminals are imitating FIFA's official online presence ahead of the 2026 FIFA World Cup. These sites can closely co...

A Major UK Retailer Had 70 Days to Stop the Attack. They Didn't Know It Was Happening.

Image
Case Study Ransomware June 2026  ·  8 min read In February 2025, attackers walked into a major UK retailer's network using social engineering against a service desk. For 70 days they moved through the system, stole the password database for every domain user, and exfiltrated customer data — before deploying ransomware that shut down online shopping for nearly seven weeks and cost the company $409 million. Here are the five things every business with a payment system needs to know. A major UK retailer is one of Britain's most recognizable brands — 64,000 employees, 1,049 stores, a household name for 141 years. In the spring of 2025 it became the most expensive ransomware victim in British retail history. The attack didn't start in April when the ransomware deployed. It started in February — two months earlier — when attackers called the retailer's IT service desk, posed as an employee, and used social engineering to get their...

A Major U.S. Life Insurance Company Was Hacked. 1.4 Million Customers' SSNs Were Exposed. It's Own Systems Were Never Touched.

Image
Case Study Third-Party Risk May 2026  ·  8 min read On July 16, 2025, attackers used a phone call to social engineer access to a third-party CRM system used by a major life insurer. They never touched the insurer's internal networks. They didn't need to. The vendor had the data. The vendor had the access. And the vendor was the open door. A major U.S. life insurance company has 1.4 million customers. On July 16, 2025, threat actors accessed the personal data of the majority of those customers — names, addresses, Social Security numbers, dates of birth, policy numbers, and financial information. The insurer's internal systems were never breached. Its policy administration platform remained secure throughout the entire incident. No attacker ever penetrated the insurer's own network infrastructure. They didn't need to. The insurer used a third-party cloud-based CRM system to manage customer relationsh...