
Cybersecurity Threat Report — July 2026
A 29-slide briefing on what is actually hitting small and mid-size businesses this month: ransomware economics, AI-driven phishing and deepfake fraud, the supply-chain breaches that reached SMBs through their vendors, the six edge-device flaws under active exploitation, and what insurers and regulators now expect. Written by engineers, not marketers, and it ends with eight prioritized moves you can act on.
This month at a glance
- 96% of ransomware victims whose size was known were small or mid-size firms (Verizon 2026 DBIR)
- 79% of ransomware attacks began with a compromised identity (Sophos, State of Ransomware 2026)
- ~5 days average time from a flaw going public to being exploited in 2023 (Mandiant / industry analysis)
- +89% rise in attack volume from AI-enabled threat actors vs. 2024 (CrowdStrike 2026 Global Threat Report)
- $3.05B in reported business-email-compromise losses, a record (FBI IC3 2025 Internet Crime Report)
- 69% of ransomware victims refused to pay (Verizon 2026 DBIR)
Bottom line up front
Ransomware crews are hunting smaller organizations on purpose, attackers now break in through unpatched software more often than stolen passwords, and AI has collapsed the cost of a convincing attack. Threat level: Elevated, driven by identity-based intrusions and edge-device exploitation. The three highest-value fixes:
- Phishing-resistant MFA on email, VPN and every admin account.
- Backups you have actually restored from, tested on a schedule.
- Same-week patching of anything facing the internet.
Ransomware & digital extortion
Ransomware now appears in 48% of confirmed breaches, and average recovery cost reached $1.7 million. Smaller teams stop attacks before encryption 34% of the time, against 46% at large enterprises (Sophos, The State of Ransomware 2026). The gap is detection speed, not effort; managed detection and tested backups close it.
What we're watching: Qilin and fast-rising "The Gentlemen" are neck-and-neck for the top spot, and Akira is deploying ransomware in under an hour against unpatched SonicWall VPNs. Nearly every major intrusion this month traced back to an unpatched gateway, and attacks are timed for evenings and weekends. Wins: two Scattered Spider members were sentenced to 5.5 years each, and police dismantled a "bulletproof" VPN service used across dozens of ransomware operations.
AI-driven threats
AI has removed the cost and skill needed to run old attacks at scale. AI-written phishing went from 4% to 56% of reported phishing in one month (Hoxhunt 2026 Phishing Trends Report), and the FBI logged $893M in AI-enabled fraud losses. Spelling mistakes and odd grammar are no longer a reliable warning sign.
Deepfakes are a working criminal tool: one firm lost $25.6M to a video call of AI clones. The defense is procedural: a mandatory call-back to a known number stops it.
"Shadow AI" is already inside your business: 45% of employees use AI tools at work, and 63% of organizations have no AI policy (Industry survey data, 2026). A one-page policy plus an approved business-tier tool solves most of it.
Breaches & headlines
Your vendors are now your attack surface: more than half the time, a small-business breach starts with someone else's failure.
- DentaQuest: a dental-benefits administrator breach exposed 2.6 million accounts, including 1.7M Social Security numbers.
- Oracle 0-day: one PeopleSoft zero-day targeted 100+ organizations, and Nissan confirmed employee records were taken.
- Salesforce: CRM-integration thefts showed how one platform's OAuth tokens sweep up unrelated companies.
- Nayax: a cashless-payment terminal provider used by small retailers and laundromats, meaning direct SMB exposure.
Three numbers set the tone: 24B stolen credential records in one exposed database (Cybernews, June 2026), a 60% year-over-year jump in third-party and supply-chain breaches (Verizon 2026 DBIR), and a record 570 flaws in Microsoft's July Patch Tuesday (BleepingComputer, July 2026).
Vulnerabilities & phishing
Exploited flaws now drive 31% of breaches, up from 20%, beating stolen credentials for the first time; stolen credentials fell to 13% from 22% (Verizon 2026 DBIR). Yet only 26% of known-exploited flaws had been fully fixed. The average window from disclosure to exploitation fell to about five days in 2023, down from 63 in 2018 (Mandiant / industry exploitation analysis), and 28% of new flaws are exploited within 24 hours.
| Product | Issue | Status | Do this |
|---|---|---|---|
| MS SharePoint | Actively exploited remote-code-execution chain | Exploited | Patch now; take the server off the public internet |
| Fortinet FortiGate | FortiBleed: ~86,000 devices' credentials exposed | Exploited | Reset all VPN and admin passwords |
| SonicWall SMA1000 | Unauthenticated flaw, CVSS 10.0 | Exploited | Apply the vendor patch immediately |
| MS Exchange | Triggered by viewing a malicious email in OWA | Exploited | Apply June/July cumulative updates |
| Palo Alto GlobalProtect | Authentication bypass into VPN sessions | High | Patch; review VPN logs |
| Citrix NetScaler | "CitrixBleed"-style memory disclosure | Exploited | Patch and rotate session tokens |
The inbox got harder to defend: 8.3B email phishing threats in a single quarter and a 146% rise in QR-code "quishing" (Microsoft Threat Intelligence, Q1 2026). 43% of BEC emails are now a simple request to get in touch, moving the conversation to text or another channel (LevelBlue, 2026). MFA-bypass kits routinely defeat SMS and app-push, so move privileged accounts to passkeys or FIDO2.
Compliance, insurance & the bottom line
Regulators and insurers are converging on the same short list of controls, so doing the work once satisfies both. What changed in 2026:
- Privacy: new state laws took effect Jan 1 in Indiana, Kentucky and Rhode Island.
- FTC Safeguards: now expects documented proof (written program, tested IR plan, MFA) from tax preparers, auto dealers, lenders and advisers.
- PCI 4.0.1: first full enforcement cycle; MFA into any card-data environment and 12-character passwords are mandatory for every merchant.
- CIRCIA: federal 72-hour incident reporting is targeted to finalize in September.
Carriers now require MFA, managed detection, immutable backups, a rehearsed IR plan and formal patching; one insurer reported zero Akira ransomware claims among clients running managed detection. The average claim hit a record $221K in 2025, 1 in 4 small businesses said an attack threatened survival, and only 47% carry cyber insurance, against 76% of large corporations (NAIC / Munich Re data, compiled 2026).
The NetSys action plan
Eight moves, ranked by impact for a business with 10 to 250 people. The first three remove most of the risk.
- Turn on phishing-resistant MFA everywhere.
- Put managed detection on every endpoint, not DIY antivirus.
- Fix immutable backups and restore-test them quarterly.
- Patch internet-facing devices within days and rotate credentials.
- Mandate call-back verification for money and access.
- Inventory vendors and app integrations; revoke stale OAuth access.
- Refresh awareness training for 2026 threats.
- Get, or right-size, cyber insurance.
Sources and method: figures are drawn from industry and government sources published in 2026: Verizon 2026 Data Breach Investigations Report; Sophos State of Ransomware 2026; CrowdStrike 2026 Global Threat Report; FBI IC3 2025 Internet Crime Report; Mandiant M-Trends 2026; Microsoft Threat Intelligence; Hoxhunt 2026 Phishing Trends; Coveware, Black Kite and ReliaQuest ransomware tracking; Cybernews; Hiscox Cyber Readiness 2026; At-Bay 2026 InsurSec Report; IBM Cost of a Data Breach; and CISA advisories. Where trackers differ in methodology, we cite the most directly verifiable figure.
The designed PDF edition, with charts, is free. One short form on the main report page unlocks this edition and every other one. Get the PDF
Discuss the security controls behind the headlines.
Share the systems, data and risks your business needs to protect. A NetSys engineer can discuss monitoring, identity protection, backups and incident response within an agreed scope.
