Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later
The owner knew a guy...
Two cases of security breaches highlight the importance of proper cybersecurity measures for small businesses. A construction firm initially refused security help due to budget constraints, only to suffer a ransomware attack and go out of business within months. The company had an unpatched Windows server with critical data on a shared backup drive, which became encrypted by the ransomware, leaving the business unable to pay employees or access vital information.
In a second case, a phishing attack was launched via a fake Microsoft 365 login page, tricking an executive's email account into revealing login credentials. This allowed the attackers to access the second company's Microsoft 365 account, potentially compromising sensitive customer data, bank accounts, and enabling further fraudulent activities.
The victim's company detected the suspicious login through TarBot, an app designed to identify anomalous logins, and successfully thwarted the attack. The incident underscores the effectiveness of phishing-resistant MFA methods, such as hardware keys or passkeys, in preventing sophisticated phishing attacks.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.