{
  "id": 12826406,
  "title": "Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later",
  "url": "https://urgent.news/2026/10/08/cheapskates-wouldnt-pay-for-security-help-got-hit-by-ransomware-and-12826406",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T08:15:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/08/cheapskates-wouldnt-pay-for-security-help-got-hit-by-ransomware-and-went-bust-months-later/5301757"
  },
  "original_language": "en",
  "account": "Two cautionary tales of security negligence and the devastating consequences that followed emerged from the pen of cybersecurity consultant Dave Hatter. The first story featured a construction business that foolishly refused to hire Hatter's firm due to budget constraints. Three weeks later, the same company fell victim to a ransomware attack that wiped out its most vital data. Despite having a backup drive, it was connected to the encrypted server, rendering it useless. The small business couldn't afford to pay the ransom and subsequently closed its doors within months. This tragedy underscores the critical need for off-site or cloud-based backups, along with timely server patching. Refusing to believe they were potential targets, small companies often underestimate the threat of ransomware gangs, but these malicious actors are just as eager to prey on businesses of any size, making them just as vulnerable. The second incident involved a phishing campaign orchestrated by criminals who first gained access to an executive's email account through a carefully crafted request for proposal message. By setting up email filtering rules, the attackers ensured their malicious emails would bypass the victim's security measures, appearing as routine business correspondence. Upon clicking a malicious download button, users were redirected to a fraudulent Microsoft 365 login page, designed to mimic the real one, complete with a fake 2FA code request. By capturing the victim's login and 2FA code through this man-in-the-middle attack, the hackers gained full control over the compromised Microsoft 365 account. With this access, the criminals could have caused havoc, initiating fraudulent money transfers, stealing sensitive data, or even impersonating the victim to launch further phishing attacks. Fortunately, the victim's company employed a software solution called TarBot that detected and revoked suspicious logins, thwarting the attack. However, experts emphasize that phishing-resistant MFA methods, such as hardware keys or passkeys, offer a more effective defense against these increasingly sophisticated attacks, as AI-assisted phishing techniques make it harder to spot red flags like poor grammar or obvious fake login pages.",
  "summary": "The owner knew a guy...",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later",
        "url": "https://urgent.news/2026/10/08/cheapskates-wouldnt-pay-for-security-help-got-hit-by-ransomware-and",
        "published": "2026-10-08T08:15:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}