There is a box in your closet you have not thought about in three years
Almost every small business has one. It sits on a shelf or hangs on the wall next to the modem. It is a black rectangle with a blinking light and a name on it that nobody remembers. Sometimes it is a firewall. Sometimes it is a VPN appliance, the thing that lets someone work from home. Sometimes it is both.
It is the device that lets you pull up the schedule from your kitchen table, or lets your bookkeeper log in from hers, or lets a vendor fix the copier without driving over. Someone set it up years ago. It worked. Nobody has touched it since.
That box is a front door to everything your business owns. Right now it is one of the most common ways attackers get into companies your size.
They are not breaking in. They are logging in.
On August 10, 2026, the FBI and CISA published a joint advisory about a ransomware operation called Gunra. The part worth your attention is how it gets in. These attackers go after internet-facing devices, meaning firewalls and VPN appliances, the equipment that accepts connections from outside your building.
In one case described in that advisory, attackers got into the administrator account on a company's VPN appliance using the credentials the device shipped with, on a system where account lockout was not turned on. They did not have to be clever. The door was already standing open.
Security researchers at Huntress described a similar pattern in a newer ransomware variant called Settra, first seen in June 2026. In the incidents they investigated, the way in was compromised VPN credentials and unpatched systems.
Plain version: the password that lets someone reach your network from anywhere is doing a lot of quiet work, and in most small businesses nobody has looked at it since the day it was installed.
The part almost nobody warns you about
Here is the piece that should change how you think about backups.
Once attackers are inside, their goal is not only to lock your files. It is to make sure you cannot get them back. In the two Settra incidents Huntress investigated, in July and September 2026, the attackers disabled Windows Recovery, removed the recovery partition, cleared the event logs, and in one of the two wiped the free space on the drive so deleted files could not be recovered.
Read that list again. Restore points. Recovery options. The record of what happened. These are the settings nobody thinks about, and they were attacked on purpose, before employees knew anything was wrong.
That is why "we have backups" is not the same sentence as "we can recover." A backup the attacker can reach, using the same administrator account they just walked in with, is not a way out. It is one more file to encrypt.
It happened in the Upper Peninsula
In February 2025, a ransomware attack shut down all five casinos of a tribal nation in the Upper Peninsula. Gaming was dark for more than two weeks. The same attack disrupted tribal computer and phone systems, healthcare services, and government operations, and the FBI opened an investigation.
That is an organization with staff whose job is to think about security, and it still took weeks to come back. A fifteen person business with one person doing the books after hours does not have weeks.
What to check this week
You do not need to buy anything to do these five things. You need someone to go look.
Find every way in from outside. Not just the VPN. Remote Desktop, remote support tools, the program an old IT person installed so they could help from their office. Write them down.
Open that device and look at the password. If it is still the one on the sticker, or the same one you use everywhere else, change it today. Turn on lockout so repeated failed logins stop the attempt.
Ask whether it still receives security updates. Devices reach end of life and the manufacturer stops patching them. Equipment that stopped getting updates two years ago is not a firewall. It is a door with a broken lock.
Count your administrator accounts. Every extra one is another way in, and every one that belongs to someone who left is a way in nobody is watching.
Say the backup question out loud. If someone got in tonight and deleted everything, where is the copy they cannot reach, and when did we last prove we could restore from it? A backup job that reported success is not the same as a restore that worked.
The honest version
None of this is exotic. The way in is usually a device nobody has thought about in years, and the damage gets worse because the recovery path was never tested. Both of those are fixable this month, and neither one requires a large project.
Most small businesses I talk to do not need more software. They need to know where they stand, then fix the two or three things that actually matter. That is a conversation, and it is usually shorter than people expect.