
Cybersecurity Threat Report — August 2026
The August 2026 edition covers the threats hitting small and mid-size businesses over the past month: AI-written phishing and deepfake wire fraud, ransomware aimed squarely at firms your size, the SaaS supply-chain breaches of the summer, and edge-device flaws being exploited before patches ship. Written by NetSys engineers for owners and one-person IT teams — every section ends with something you can act on.
The month in six numbers
- 1 in 4 malicious breaches are now AI-enabled (IBM Cost of a Data Breach 2026)
- $6.0M average cost of an AI-enabled breach, vs $4.99M overall (IBM 2026)
- 86% of phishing attacks now use AI in some way (KnowBe4 Vol. 7, 2026)
- $769K median ransom paid — but recovery averages $1.7M (Sophos State of Ransomware 2026)
- $3.05B in business-email-compromise losses in 2025 (FBI IC3 2025 Report)
- −7 days time-to-exploit: flaws are hit before a patch exists (Mandiant M-Trends 2026)
Bottom line up front: identity is the front door
Most attacks this summer didn't break in — they logged in. AI has made phishing and voice fraud convincing enough that a person, not a firewall, is the target. Threat level: elevated. Three habits blunt most of it: phishing-resistant MFA on email, VPN, RDP and cloud admin; tested, offline backups — the reason most victims avoid paying; and call-back verification before any money moves.
Ransomware: you are the target, not collateral
Only 34% of small and mid-size firms stop an attack before encryption, versus 46% at enterprise scale (Sophos 2026). The median ransom fell to $769K, but recovery averages $1.7M — downtime, rebuild and lost business dwarf the ransom itself. 66% of encrypted victims restored from backups instead of paying. 79% of attacks start with email, phishing or stolen credentials; June alone saw 707 victims across 63 active crews, led by The Gentlemen, Qilin and the new DeadLock (Breachsense). Silent Ransom is phoning SMB help desks posing as IT support.
AI & wire fraud: the "bad grammar" tell is gone
86% of phishing now uses AI, so every message looks polished; 30% impersonate a coworker, and Teams-based attacks rose 41% (KnowBe4 2026). Shadow AI featured in 43% of breaches, and 68% of breached firms lacked AI governance (IBM 2026). Business-email-compromise and funds-transfer fraud account for 58% of cyber-insurance claims (Coalition 2026); a single deepfake-CFO video call cost one company $25.6M (Arup / CNN, 2024).
One rule stops most wire fraud: verify by voice on a number you already had — before anything moves. Assume voice and video can be faked; require two approvers over a set threshold. "Urgent + confidential + new payment details" means stop.
Incidents: breaches came through the side door
This summer's biggest breaches never touched the victims' networks — they came in through trusted cloud apps. 195 organizations were exposed through a Salesforce-connected vendor's dormant test login that sat active and unrevoked for four years (Cloud Security Alliance, Jul 2026). In the same SaaS campaign, attackers claim to have taken 4.9M records from Brinks and 21M from Fluke, and LastPass had limited data exposed via a third-party CRM compromise. The lesson: audit and revoke unused SaaS and OAuth connections and old test logins the same way you disable a departed employee.
Vulnerabilities: patch these this week
Exploited flaws are now the #1 breach vector at 31% (Verizon 2026 DBIR), flaws are exploited about a week before a fix ships (Mandiant 2026), and stolen access is resold in as little as 22 seconds. Internet-facing firewalls, VPNs and RMM tools are the prize.
| Product | What's exposed | Status |
|---|---|---|
| SimpleHelp RMM (CVE-2026-48558) | Auth bypass that skips MFA | Exploited (SecurityWeek) |
| Cisco Secure FMC (CVE-2026-20131) | Unauthenticated remote code execution | Ransomware (Dark Reading) |
| SonicWall SMA1000 (CVE-2026-15409/410) | Request forgery to admin command injection | On CISA KEV |
| SharePoint Server (CVE-2026-56164) | Missing-auth privilege escalation | Exploited (Microsoft, Jul 2026) |
| Ivanti Sentry (CVE-2026-10520) | Pre-auth command injection | On CISA KEV |
Also this month: 30,000 FortiGate admin passwords were recovered from exposed configs — rotate credentials (Arctic Wolf 2026) — and July's Patch Tuesday shipped ~570 Microsoft fixes including three zero-days. Rule of thumb: anything reachable from the internet gets patched in days, and every admin login goes behind MFA.
Insurance & what changed
Only 10–20% of small firms carry cyber insurance, versus 62% overall (Munich Re 2026). Ransom demands rose 47%, yet 86% of firms refused to pay (Coalition 2026); premiums may climb 15–20% this year. Insurers now expect MFA (~80%) and EDR (~65%) as a condition of coverage — treat both as prerequisites, not discounts (Marsh 2026). Quiet rule changes: PCI DSS 4.0.1 payment-page script controls and MFA are now mandatory for any site taking cards; DoD subcontractors need CMMC Level 2 certification from November 10, 2026; and three more state privacy laws (IN, KY, RI) went live in January — 20 states total.
The eight-move action plan
- Turn on phishing-resistant MFA everywhere — email, VPN, RDP and every cloud-admin account; prefer passkeys or FIDO2.
- Keep tested, offline backups — the top reason victims avoid paying; two-thirds restore from backups.
- Patch edge gear in days — firewalls, VPNs, RMM, mail and NAS; the exploit window is now negative.
- Verify every money move by voice — call a known number; require two approvers over a set threshold.
- Audit and revoke unused SaaS logins — kill dormant OAuth tokens and old test accounts.
- Write a one-page shadow-AI policy — name allowed tools and the data that must never be pasted in.
- Put EDR on every endpoint — now table stakes for cyber-insurance coverage.
- Run a 30-minute tabletop — who to call, how to restore, how to verify a wire, before you need it.
Sources and method: every figure above is anchored to a named, dated report — Sophos State of Ransomware 2026, Coveware Q2 2026, IBM Cost of a Data Breach 2026, KnowBe4 Phishing Threat Trends Vol. 7, FBI IC3 2025, Verizon 2026 DBIR, Mandiant M-Trends 2026, Coalition 2026 Cyber Claims Report, Munich Re Cyber 2026, and the CISA KEV catalog, with incident reporting from BleepingComputer, Arctic Wolf, SecurityWeek, Dark Reading, Cloud Security Alliance and SharkStriker (June–July 2026). Where trackers disagreed we used the most verifiable primary source. The designed PDF edition of this report, with charts, is free below.
The designed PDF edition, with charts, is free. One short form on the main report page unlocks this edition and every other one. Get the PDF
Discuss the security controls behind the headlines.
Share the systems, data and risks your business needs to protect. A NetSys engineer can discuss monitoring, identity protection, backups and incident response within an agreed scope.
