Filed under: Cybersecurity · Ransomware · July 2026
What happened
Security researchers are tracking an active phishing campaign in which criminals pose as Interpol’s cybercrime unit. The emails claim your company is under investigation and link to a password-protected Proton Drive archive that supposedly holds “video evidence.” The file inside is really a program disguised as a video — opening it installs custom-built ransomware that encrypts your files and demands payment. Businesses across the U.S., Europe, Asia, and the Middle East have already been hit, spanning legal, medical, finance, media, and other everyday industries.
Why it matters to your business
This campaign is aimed squarely at small businesses without a dedicated IT or security team — exactly the kind of Phoenix companies most at risk. A “law enforcement is investigating you” email is engineered to make a busy owner or bookkeeper panic and click before thinking. There is no fixed ransom: the attackers size up your business only after they have locked your files, so even a small firm can face a painful demand — on top of downtime that stops billing, payroll, and QuickBooks cold.
What to do this week
Treat any unsolicited “law enforcement” email as a scam — real agencies don’t email you a Proton Drive link and a password. Turn on file extensions in Windows (File Explorer → View → Show → File name extensions) so a file named “evidence.mp4.exe” gives itself away. Never open password-protected archives from outside your company, and never run a file that asks you to “enable” or “unzip and open” it. Confirm your backups are running and kept offline or in a separate cloud account, and that MFA is on for email and Microsoft 365 or Google Workspace. Finally, give the people who handle email and invoices a quick heads-up that this exact scam is circulating.
The bigger picture
Ransomware crews keep leaning on fear and urgency because it works far better than any technical exploit, and once files are encrypted, paying rarely gets everything back cleanly. The only dependable “recovery” is not getting hit in the first place — layered email filtering, tested backups, and trained staff. → Why the Only True Recovery from Ransomware Is Prevention
Would your backups actually survive a ransomware hit — or just look like they would? Book a free consult → https://micro1tech.com/contact/
Filed under: Cybersecurity · Network Security · July 2026
What happened
Researchers investigating “FortiBleed” — a massive credential-theft operation against Fortinet FortiGate firewalls — have now tied it directly to the INC and Lynx ransomware gangs. The attackers planted a traffic-sniffing tool on compromised firewalls to intercept VPN usernames and passwords as employees logged in, harvesting credentials from more than 73,000 devices; the operation targeted over 430,000 firewalls worldwide. Roughly 11,000 devices are believed to still be compromised, and investigators found backdoor admin accounts named “adminin” left behind on affected systems. This is confirmed real-world activity, not a proof of concept.
Why it matters to your business
FortiGate firewalls are common in small offices, often installed by a vendor years ago and rarely touched since. If yours was compromised, the passwords your staff use to connect remotely are sitting in a criminal database — and the groups holding them are ransomware operators whose business is getting into networks and encrypting everything. A firewall that was “fixed” by only changing passwords can still be compromised: if the sniffer is still on the device, new passwords get stolen too.
What to do this week
If your office firewall is a Fortinet: update it to the latest FortiOS firmware for your model, then — in that order — reset every VPN and admin password, since credentials changed before patching may already be captured. Check System → Administrators for any account you don’t recognize (especially “adminin”) and remove it. Turn on multi-factor authentication for VPN logins, and make sure the management interface isn’t reachable from the internet. Not sure what brand your firewall is or who manages it? Find out today — that answer shouldn’t be a mystery.
The bigger picture
Stolen credentials are the raw material of ransomware: gangs don’t need to hack your network if they can simply log in. Once they’re inside, recovery gets expensive fast — prevention is the only plan that reliably works. → Why the Only True Recovery from Ransomware Is Prevention
Who last checked what’s running on your office firewall — and when? Book a free consult → https://micro1tech.com/contact/
Filed under: Cybersecurity · Ransomware · July 2026
What happened
A flaw in Microsoft SharePoint Server (CVE-2026-45659) is being actively exploited, and CISA added it to its Known Exploited Vulnerabilities list on July 1 with a July 4 patch deadline for federal agencies — about as urgent as those deadlines get. The bug lets attackers run their own code on the server remotely, and at least one group exploiting it, Storm-2603, follows up by deploying Warlock ransomware. Important: this affects on-premises SharePoint Server only — SharePoint Online, the version included with Microsoft 365, is not affected.
Why it matters to your business
Plenty of small businesses had a SharePoint server installed years ago for file sharing and haven’t touched it since — which is exactly the profile this gang targets. An old server sitting in a closet, reachable from the internet, missing patches: that’s not a file server anymore, it’s a ransomware entry point. If you’re fully on Microsoft 365, you can relax on this one. If you’re not sure which you have, that uncertainty is itself the finding.
What to do this week
Ask one question: “Do we run SharePoint on our own server?” If yes, apply Microsoft’s latest SharePoint Server security update now — not at the next maintenance window — and check whether the server actually needs to be reachable from the internet at all. If the server is old enough that it no longer gets updates, it’s time to plan a migration to SharePoint Online, where Microsoft does the patching for you.
The bigger picture
Ransomware gangs don’t break in through your newest system — they scan for the oldest thing you forgot you owned. Once files are encrypted, options shrink fast; the only reliable recovery is never letting them in. → Why the Only True Recovery from Ransomware Is Prevention
Do you know every server your business still runs — and who’s patching them? Book a free consult → https://micro1tech.com/contact/