News Roundup: Why St. Louis Small Businesses Are Hackers’ Favorite Targets Right Now

Let me ask you something: When you leave your office for the weekend, do you lock the front door?

Of course you do. You may check the alarm, close the windows, and make sure nobody has access to the building after hours.

Now imagine leaving one back door unlocked because you were busy. A stranger notices, walks in quietly, and uses your own equipment to move around the building.

That is what is happening digitally to small businesses across St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and throughout Missouri.

This week’s news makes one thing clear: Hackers are not always trying to smash through your digital walls. Increasingly, they are stealing a key, tricking someone into opening the door, or abusing a trusted vendor that already has access.

And small businesses are paying attention.

Small-business attacks are up approximately 45%

Industry reports show that cyber attacks against small businesses have risen by roughly 45% over the past year.

Why does that matter to you?

Because many small businesses do not have the cash reserves, staff, or downtime needed to absorb a major ransomware event, stolen customer database, or extended technology outage. A larger corporation may have dedicated incident response teams and legal departments ready to act.

Your business may have a much smaller margin for error.

That does not mean hackers are personally targeting your company. It means they are looking for the easiest path to a valuable result.

Your accounting system, email, customer records, payroll information, and vendor accounts can all be useful to an attacker. If your business has weak security in one of those areas, you may become the path of least resistance.

Small-business manager reviewing a suspicious digital notification with a security key nearby

News item #1: Ransomware is becoming an identity problem

Here’s one of the most important findings from this week’s security research: Approximately 79% of ransomware attacks now begin with stolen or compromised credentials.

In plain language, attackers are often logging in rather than breaking in.

A compromised credential may be a stolen password, a reused login, an exposed session token, or an account taken over through phishing. Once attackers get access, they may use legitimate tools and valid accounts to move through your environment.

That can make the activity look normal at first.

The solution is not simply telling employees to choose longer passwords. Start with:

  • Require multi-factor authentication on email, cloud applications, VPNs, and administrator accounts.
  • Move toward passwordless authentication where practical.
  • Use phishing-resistant login methods, such as security keys or passkeys.
  • Monitor for exposed business credentials.
  • Disable accounts immediately when employees leave.
  • Review administrator access and remove unnecessary privileges.

MFA is important, but not all MFA is equally strong. Phishing-resistant authentication can prevent an attacker from capturing the second factor through a fake login page.

That distinction matters.

News item #2: A global phishing wave is installing remote-control software

Researchers are tracking a phishing campaign spanning approximately 46 countries, with the United States listed as the top target.

The campaign tricks employees into installing malicious remote monitoring and management software, commonly called RMM software.

RMM tools are not automatically dangerous. Businesses and IT providers use legitimate RMM platforms to manage computers, install updates, and troubleshoot problems remotely.

Here’s the problem: Once an attacker gets a trusted remote-control tool onto a business computer, they may be able to operate that computer from a distance while appearing to use normal business software.

Imagine giving a stranger a key to your office because they claimed to be from your alarm company. They do not need to break a window. They already have access.

Your defensive steps should include:

  • Approve only known RMM tools.
  • Keep an inventory of every remote-access application.
  • Block unauthorized software installations.
  • Alert on new or unusual RMM activity.
  • Require administrator approval for remote-control tools.
  • Train employees to verify unexpected support requests.

This is where professional St. Louis managed IT services can help. A managed IT partner can maintain an approved software list, monitor endpoints, and investigate tools that do not belong in your environment.

News item #3: StyleSmuggler puts Magento and Adobe Commerce retailers on alert

This week also brought urgent news for retailers using Magento or Adobe Commerce.

Researchers disclosed a critical zero-day vulnerability known as “StyleSmuggler.” The vulnerability reportedly allows unauthenticated remote code execution, meaning an attacker may be able to run code on a vulnerable store without logging in.

As of this weekend, no official vendor patch has been confirmed.

That is serious.

Your online store may be fully updated according to your normal schedule and still require emergency attention if the platform itself has an active, unpatched vulnerability.

If you operate a Magento or Adobe Commerce store:

  • Contact your ecommerce developer or IT security provider immediately.
  • Follow trusted vendor and security researcher mitigation guidance.
  • Review web server, application, and authentication logs.
  • Scan for unexpected files, templates, and administrator accounts.
  • Rotate credentials and API keys if compromise is suspected.
  • Apply the official patch as soon as one becomes available.
  • Keep your payment environment and customer data isolated where possible.

Do not assume that “we patched last month” means “we are safe today.” Patch management is an ongoing process, especially when public-facing applications handle customer information.

News item #4: Social engineering and supply-chain attacks keep spreading

ShinyHunters and other threat groups continue to rely on social engineering and supply-chain attacks.

Social engineering means manipulating people into taking an action that benefits the attacker. That action might be clicking a link, approving a login, changing payment details, or sharing information with someone who appears trustworthy.

Supply-chain attacks take a different route. Instead of attacking your business directly, criminals compromise a vendor, service provider, software platform, or logistics partner that already connects to your organization.

A recent logistics-provider breach exposed tens of thousands of customer records. The lesson is uncomfortable but important: Your risk does not stop at your firewall.

You also need to understand the security practices of companies that process your data.

Ask your vendors:

  • What information do you store about our customers?
  • Who can access it?
  • Do you use MFA for administrator accounts?
  • How do you notify customers after a breach?
  • Do you test your backups and recovery plans?
  • What happens when our contract ends?

You may not be able to eliminate third-party risk. You can reduce it through better questions, limited access, and careful vendor selection.

News item #5: SPACEBEARS is targeting familiar industries

The SPACEBEARS ransomware group has launched a fresh wave affecting U.S. retail, legal, and healthcare organizations.

Why should a Missouri small business owner care if the victim is in another state?

Because these campaigns show where criminals believe the money and pressure points are strongest. Retailers have customer and payment data. Legal practices hold confidential documents. Healthcare organizations manage highly sensitive records.

Many businesses in St. Louis and St. Charles County operate in or serve these same industries.

Ransomware protection needs multiple layers:

  • Endpoint protection that detects suspicious behavior.
  • Segmented networks that limit how far an attacker can move.
  • Tested backups that are isolated from ordinary user accounts.
  • Patch management for operating systems, applications, firewalls, and remote-access tools.
  • A written incident response plan.
  • 24/7 monitoring for critical alerts.

Backups are essential, but an untested backup is only a hope.

Schedule recovery tests. Confirm that you can restore important files, applications, and systems without relying on the same compromised credentials an attacker may have stolen.

IT professional reviewing secure network activity in a modern server room

News item #6: U.S. breach notices have already reached the hundreds of millions

Midyear data from 2026 shows hundreds of millions of U.S. data breach notices during the first half of the year.

That number is being driven partly by very large incidents, but the practical takeaway is still personal: Customer information is being exposed at a pace that affects every business connected to a larger platform, provider, or software ecosystem.

Your customers may not understand which company caused the breach. They may only remember that your business was involved.

That is why data protection should include:

  • Limiting the customer data you collect.
  • Removing information you no longer need.
  • Encrypting sensitive data.
  • Monitoring unusual access.
  • Reviewing cloud permissions.
  • Training employees on privacy and phishing.
  • Maintaining a recovery plan.

What you should do this week

You do not have to fix every security issue in one afternoon.

Start with this short list:

  1. Confirm MFA: Verify that email, cloud, VPN, banking, and administrative accounts are protected.
  2. Review remote tools: Identify every RMM, remote desktop, and support application installed on business devices.
  3. Check backups: Confirm that backups are running and that at least one copy is isolated from the network.
  4. Update critical systems: Prioritize internet-facing applications, firewalls, ecommerce platforms, and remote-access tools.
  5. Train your team: Explain how phishing messages, fake support requests, and urgent payment changes work.
  6. Review vendors: Ask which partners can access your data or systems.
  7. Create an emergency contact plan: Know who to call before a ransomware event happens.

If you need a starting point, Platinum Web Services offers cybersecurity solutions for small business built around practical protection, proactive monitoring, and clear communication.

You can also review why businesses choose managed IT when they need more than occasional troubleshooting. Our earlier guide to ransomware protection explains the layered approach in more detail.

The local takeaway: You do not need to face this alone

The news can feel overwhelming.

One week brings a credential theft campaign. The next brings a zero-day, a ransomware group, or a breach at a vendor you rely on every day.

But the answer is not panic. It is preparation.

For businesses looking for St. Louis cybersecurity, St. Louis IT support for small business, or dependable Missouri technology consulting, the first step is understanding where your real exposure exists.

Platinum Web Services provides personalized protection for businesses in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and throughout Missouri. We offer 24/7 IT support and list our business hours as 24/7, because technology emergencies do not follow a convenient schedule.

If you would like help reviewing your security posture, contact Platinum Web Services.

Our office is located at 7827 Town Square Ave, 104-1184, O'Fallon, MO 63368.

You lock your physical doors because protecting your business matters. Your digital doors deserve the same attention.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *