Issue #5 · July 26, 2026 · 13 min read

Issue #5 — The ransomware backup gap, a credential-stuffing wave, and a new EU AI-labeling rule

This week: the ransomware recovery gap that's leaving small businesses exposed, a credential-stuffing wave hitting everyday loyalty accounts, and a new EU deadline for labeling AI-generated content — plus what your vendors' security failures mean for your customers' data.

Corrected after review checked 2026-07-26

Four sections (big-one, threat-radar, privacy-watch, do-this-now) required one revision pass before passing; quick-hits was revised once but still carries a few minor, non-fabricated simplifications at the two-pass cap. The remaining two sections (ai-at-work, plain-english) passed on the first draft. No section reached major_issues or needs-review.

24 sources cited across this issue

top story Small Businesses Are Losing the Ransomware Recovery Race

New industry data puts a number on something small-business owners have long suspected: when ransomware hits, big companies bounce back and small ones often don’t — and the gap isn’t about who gets targeted.

Sophos’s newly released State of Ransomware 2026 report, based on a survey of over 2,100 IT and security leaders whose organizations were hit by ransomware in the past year, found that only about a third of small organizations (roughly 100 to 250 employees) managed to stop an attack before their files were encrypted or data was stolen for extortion. Among larger enterprises (3,001 to 5,000 employees), nearly half did. Sophos’s own conclusion: “scale is buying real defensive outcomes,” and smaller businesses are carrying more than their share of the damage.

Here’s the important part: this isn’t because criminals are picking on small businesses specifically. Much of ransomware activity is opportunistic — automated tools scan the internet for weak passwords, unpatched software, and misconfigured remote access, and attackers take whatever falls into that net rather than hand-picking every victim (though some campaigns do deliberately target specific sectors, like healthcare or critical infrastructure). For the broad run of attacks that hit small businesses, though, a five-person consulting firm and a Fortune 500 company can get caught by the exact same automated scan.

So why do bigger companies recover more often? Mostly two things: backups that actually work, and a written plan for what to do when something goes wrong. The same Sophos report found that recovery through backups jumped sharply this year — now used in about two-thirds of cases where data was encrypted — and that having a tested plan and validated backups in place before an attack correlated with faster, cheaper recovery across the board.

That word “tested” matters. A lot of small businesses assume they’re covered because files sync automatically to a cloud folder like Dropbox, OneDrive, or Google Drive. But sync isn’t a backup — if ransomware scrambles the files on your computer, the cloud folder will often dutifully sync the scrambled versions too. A real backup means a copy that ransomware on your machine can’t reach and touch, and that you know for certain will bring your files back.

If you can’t say with confidence today that your backup would actually restore your business’s files, that’s the single most important gap to close this week — not new software, not a bigger budget. We’ll walk through exactly how to check in this issue’s Do This Now.

Sources

Checked 2026-07-26 — every statistic (survey size, 34%/46% recovery rates, 66% backup-recovery rate) traced directly to Sophos’s State of Ransomware 2026 report, and the cloud-sync-is-not-a-backup advice reflects current best practice.

cyber Your Old, Leaked Password Is Being Tried on Your Business Accounts Right Now

In June, thousands of Chick-fil-A loyalty accounts were hijacked — but Chick-fil-A itself wasn’t hacked. Attackers never broke into the company’s systems. Instead, over a three-day span, automated software fed in email addresses and passwords stolen from other, unrelated breaches and quietly tested them on Chick-fil-A’s app and website. Every account where a customer had reused an old password let the attacker straight in, exposing names, loyalty balances, and partial payment card numbers. It was the second time this has happened to the chain in a few years.

This is called credential stuffing, and it’s not a targeted hack — it’s a numbers game played at enormous scale. Akamai, which tracks this kind of automated attack traffic, has reported tens of billions of these login attempts per month in its recent years of reporting, aimed at everything from retail apps to banking to ordinary business email. Attackers don’t need to know anything about you specifically; they just need one password you’ve reused somewhere that already leaked. Reusing passwords across multiple sites is a widely documented habit, and it’s exactly what makes this work at scale.

Warning signs to watch for: a login or “new device” alert you didn’t trigger, an account that locks you out unexpectedly, a loyalty or gift-card balance that’s suddenly lower than it should be, or a password-reset email you never requested.

What this means for you: any account where you’ve reused a password — your business email, bank login, vendor portals, rewards accounts — is a target, whether or not that business itself was ever breached.

Do this: use a password manager (Bitwarden and Apple’s and Google’s built-in password managers all have solid free tiers) to give every account a unique, random password, and turn on multi-factor authentication wherever it’s offered — preferring an authenticator app or security key over text-message codes. This is a one-time habit change, not an ongoing chore.

Sources

Checked 2026-07-26 — Chick-fil-A incident details and Akamai’s credential-stuffing volume figures verified against independent reporting; security advice matches current CISA/FBI-endorsed guidance.

ai The EU Now Requires Labeling AI-Generated Marketing Content — Starting in Days

AI tools that generate product photos, video clips, and voiceovers have become genuinely useful for small businesses that can’t afford a studio or a full marketing team. That’s not changing. But if any of your marketing reaches customers in the European Union, a new rule is about to affect how you use those tools.

On July 20, the European Commission finalized guidance on Article 50 of the EU’s AI Act — the law’s transparency rule. Starting August 2, 2026, if you create a “deepfake” (an AI-generated or altered image, video, or audio clip realistic enough to look or sound like a real person, place, or event) and it reaches an EU audience, you must disclose that it’s AI-made. The disclosure has to be visible or audible to the viewer — not buried in a website’s terms of service or a hidden menu — and it has to appear the first time someone sees or hears it.

This is triggered by your audience, not your location. A US-based business is covered if it sells to EU customers, runs ads targeting EU users, or otherwise knowingly puts this content in front of EU viewers. If your customers are entirely domestic, this rule doesn’t apply to you yet — there’s no equivalent US-wide requirement.

What this means for you: First, check whether you actually have an EU audience — EU customers, EU ad targeting, or a meaningful share of EU site traffic. If you do, and you use AI to generate realistic images, video, or voiceovers of people, places, or events for that audience, add a simple, plain-sight label: an on-screen caption (“AI-generated”) or a short spoken disclosure at the start of a video or audio clip.

The maximum fine (up to €15 million or 3% of global revenue) is the ceiling for large, repeat violators, not a realistic outcome for a small business’s first oversight — but a visible label costs you nothing and settles the question either way.

Sources

Checked 2026-07-26 — every legal claim about Article 50’s finalized guidance, its August 2, 2026 effective date, its EU-audience trigger, and its fine structure was independently verified.

privacy This Month’s Breaches Weren’t Your Fault — But They’re Still Your Problem

Look past the headlines from this month’s breach reports and a pattern shows up: the company whose name is on the notice often isn’t where the failure happened.

The accounting firm Ernst & Young recently told clients that tax documents had been exposed — not because its own network was broken into, but because a third-party IT support-ticket system used by its staff was compromised, and documents attached to those support tickets went out the door with it. Estée Lauder disclosed a breach of employee Social Security numbers, payroll records, and passport details that traced back to a flaw in Oracle’s E-Business Suite — a broad back-office system used to run finance, supply chain, and HR functions together, the same category of all-in-one business software that smaller companies also rely on, just from different vendors. And financial firm Pinnacle Financial Partners had client data exposed when its outside accounting firm’s network was hacked.

None of these companies mishandled the data themselves. They handed it to a vendor, and the vendor’s weak spot became their weak spot.

The same logic applies at any size. If you use a support-desk tool, payroll or HR software, or a scheduling app that stores customer or employee information, that vendor’s security is now part of your security — whether you ever thought about it or not.

What to do: Pick two vendors that hold your customers’ or employees’ personal information. Look at their website for a security or trust page, or just email and ask two questions: how is this data protected, and will you tell me if it’s breached? A vendor that can’t answer plainly is worth reconsidering.

Sources

Checked 2026-07-26 — all three named breaches (Ernst & Young, Estée Lauder, Pinnacle Financial Partners) independently verified with matching causes, data types, and July 2026 disclosure timing.

action Do This Now: Test That Your Backup Actually Restores

This week’s lead story looked at why small businesses bounce back from ransomware so much less often than large companies do. The gap usually comes down to two things: whether backups actually work, and whether there’s a written plan for what to do. You can check the backup part right now, in about 15 minutes.

  1. Find out where your important files really live. That might be a cloud folder (like Google Drive, Dropbox, or OneDrive), an external hard drive, or your accounting software’s own storage. Make a quick mental list of what’s actually backed up versus what’s just sitting on one computer.

  2. Look for “version history” or “restore” in that storage. Don’t assume that a folder syncing across your devices counts as a backup — syncing can copy damage along with your files. Look specifically for a feature that lets you go back to an older version, and keep in mind that most free-tier cloud services only keep that history for about the last 30 days.

  3. Restore one real file to a separate, temporary location and open it. Confirm it opens properly and isn’t an old, outdated copy. This is the step that actually proves your backup works, rather than just trusting that it does.

  4. Write down today’s date somewhere you’ll see it, so you know when you last checked. Repeat this every few months — since version history has a rolling window, checking regularly is what keeps you covered.

This one habit is often the difference between a business that recovers and one that doesn’t.

Sources

Checked 2026-07-26 — this section is synthesized directly from the Sophos data discussed in the Big One above; the 30-day free-tier version-history claim was independently verified against Google, Dropbox, and Microsoft documentation, and the steps reflect current backup-testing best practice.

explainer Plain English: What Is “Credential Stuffing”?

Credential stuffing is when criminals take a giant list of usernames and passwords stolen from one breached website and try them, automatically, on other websites — often millions of attempts in a matter of hours. It works because so many people reuse the same password across multiple accounts. If your email-and-password combo leaked from some retailer years ago, and you used that same password on another site, an automated tool can find that out in seconds.

This is different from “hacking” in the sense most people picture — someone breaking through a lock or exploiting a flaw in a company’s system. With credential stuffing, the target site itself isn’t broken into at all. The criminals are simply logging in with real, working passwords that happen to have leaked somewhere else.

It’s worth knowing this week because it’s exactly the method behind the Chick-fil-A loyalty-account breach covered in this issue’s Threat Radar: no flaw in Chick-fil-A’s systems, just reused passwords doing the damage.

Sources

Checked 2026-07-26 — definition and mechanism match standard industry usage, and the Chick-fil-A cross-reference is consistent with independent reporting.

roundup Quick Hits

  • Patch your on-premises SharePoint server now — CISA has confirmed active attacks against several flaws in self-hosted SharePoint Server (the version you or an IT contractor would install on your own machine, not the cloud “SharePoint Online” most small businesses actually use), so if that’s you, get the latest Microsoft patches installed immediately.
  • A SonicWall VPN flaw lets attackers in with no password — SonicWall’s SMA1000 remote-access appliances (used by some IT providers to let staff work from home) have a maximum-severity bug under active attack, so ask your provider directly whether yours is patched.
  • The FTC’s one-line scam test — if someone insists you pay only by wire transfer, cryptocurrency, payment app, or gift card, it’s a scam; the FTC says people lost over $4 billion last year to bank-transfer and crypto scams alone.
  • Google’s Gemini can now summarize how your business is doing — if you already use Google Business Profile, you can ask its Gemini assistant “how did my business do this month?” and get an answer built from your reviews, calls, and search traffic, no dashboard-digging required.
  • Three more states’ privacy laws took effect in 2026 — Indiana, Kentucky, and Rhode Island now have consumer privacy laws that mainly target larger operations (Indiana and Kentucky kick in at 100,000 residents’ data, Rhode Island at 35,000), but each has a much lower alternate threshold — as few as 10,000 to 25,000 residents — if a meaningful share of your revenue comes from selling personal data, so fast-growing or data-selling small businesses shouldn’t assume they’re automatically exempt.

Sources

Checked 2026-07-26 — all five items independently verified as substantially accurate; a few minor simplifications noted (SonicWall exploit chaining, state privacy-law revenue thresholds) but no unsafe advice or fabricated statistics.