The break-in that doesn't need you
For years the advice was simple. Don't click the bad link. Train your staff. Check the sender before you open the attachment.
That advice is still good. It just isn't the main way businesses get hit right now.
Verizon's 2026 Data Breach Investigations Report examined more than 22,000 confirmed breaches. The most common way attackers got in was not a trick. It was a known software flaw that nobody had patched. Stolen passwords had held that top spot for years. This year it slipped to second.
Put plainly: nobody clicked anything. Nobody typed a password into a fake page. The attacker found a machine your business had left reachable from the internet, noted that the machine had a known hole in it, and used the fix that had already been published to walk in.
Your side of the wall
Almost every business has a few devices that can be reached from the internet. There is the router or firewall. There may be a VPN, the thing that lets you check the books from the cabin or lets your accountant in during tax season. Add a camera system, a phone system, a scheduling portal. Nobody opens these. Nobody thinks about them.
They were installed once, by somebody, and then the business moved on. Most owners could not tell you the model number or the version of software running on them. Fewer still could tell you who is responsible for updating them.
That is the gap. Not stupidity. Attention. You are already doing four other jobs.
What is happening right now
In August, the FBI, CISA, the NSA, and the Secret Service published a joint warning about a ransomware operation called Gunra. It is rented out to affiliates, which means the people breaking in are not the people who wrote the code. The advisory names the front door directly: unpatched VPN and firewall devices facing the internet.
Those flaws were not unknown. They had fixes available. The fixes were sitting uninstalled at the edge of the network.
In July, SonicWall disclosed two flaws in its SMA 1000 remote access appliances. One of them scored 10.0 out of 10 for severity, the highest rating possible. An attacker did not need a username or a password to begin. Both flaws went onto the government's list of vulnerabilities known to be exploited in the real world.
That list keeps growing. On September 27, CISA added two more Citrix NetScaler flaws to it, because attackers were already using them.
The part that surprises people
Getting inside one of these appliances is not always undone by patching later. In the SonicWall cases, attackers were observed taking the appliance's stored credentials, its live session data, and its multi-factor authentication seeds. A patch closes the door. It does not remove what was left in the room.
So if a remote access device of yours was reachable from the internet and out of date, the honest conclusion is not "we patched it." The honest conclusion is that somebody needs to check whether anything was taken.
What to do this week
Most of this does not require new software. It requires knowing where you stand.
1. Find your edge devices. Answer one plain question: what lets people connect to our network from outside, and what is it called?
2. Write the version numbers down. Ten minutes of work. If you cannot find a version number anywhere, that is your answer.
3. Update them, or replace them. If the maker still supports the device, install the update. If updates stopped years ago, this is a replacement decision and not a patching one. There is no clever workaround for a device nobody maintains.
4. Close the remote access nobody uses. If you stopped working from the road two years ago, that VPN does not need to be answering the internet at all.
5. Deal with the default accounts. In one case documented in the Gunra advisory, attackers logged in using default credentials because account lockout had never been turned on. Rename or remove the account called "admin." Turn lockout on.
6. Prove your backups restore. Keep a copy that cannot be reached from the network, in a separate place, and actually test the restore. The advisory lists this among its first recommendations, and it is the reason recovery does not have to depend on paying.
7. Know who to call. If something has already happened, Michigan businesses can reach the Michigan Cyber Command Center at (877) MI-CYBER or [email protected]. It is free, and it exists for businesses, not just government agencies.
The quiet part
None of this makes a good story. There is no screenshot of a clever email. Just a device in a closet running software from four years ago, quietly doing its job, until it isn't.
I would rather you spend one afternoon finding that out than spend a week finding out the other way.