Phishing Surge and Credential Attacks Top Threat List for Small Business

by The Creator | Jul 15, 2026

Phishing training and credential attacks are now the primary entry point for ransomware at small businesses, accounting for 79% of incidents according to Sophos research. The FBI warns that the Kali365 platform is actively targeting Microsoft 365 users with fake login pages, already causing $12 million in losses in Florida alone.

Small business owners face mounting cyber threats as the FBI warns about the Kali365 phishing platform targeting Microsoft 365 users, which has already caused $12 million in losses in Florida alone. These sophisticated attacks use fake login pages nearly identical to Microsoft's legitimate site.

In a major shift, new Sophos research reveals that compromised credentials have overtaken software vulnerabilities as the primary ransomware entry point, now accounting for 79% of all incidents. This makes weak passwords, missing multi-factor authentication, and phishing the top risks for businesses.

Microsoft released its largest-ever Patch Tuesday update with 622 security fixes, including three actively exploited zero-days affecting BitLocker, SharePoint, and Active Directory. Immediate patching is critical for all Microsoft environments.

The NSA also issued warnings about Russian-backed hackers exploiting poorly configured routers. Simple security measures like changing default passwords, updating firmware, and restricting remote management can effectively block these attacks.

The key takeaway: Basic security hygiene and strong credential management are now more important than ever for protecting small businesses.

Why phishing training and credential attacks matter most to your business

Compromised credentials have surpassed software vulnerabilities as the leading ransomware attack vector. Sophos found that 79% of ransomware incidents now start with weak passwords, missing multi-factor authentication, or successful phishing attacks. The Kali365 phishing platform uses fake Microsoft 365 login pages nearly identical to the real sites, tricking employees into handing over access. Microsoft's July 2026 Patch Tuesday included 622 fixes with three actively exploited zero-days in BitLocker, SharePoint, and Active Directory. For manufacturers and professional services firms in Connecticut, the immediate action is clear: deploy MFA across all Microsoft accounts, apply patches within 48 hours, and run phishing awareness training showing staff how to spot fake login pages. CISA recommends staff verify login URLs and enable security features before clicking any links in email.

Key takeaways

  • Compromised credentials cause 79% of ransomware attacks; phishing is the fastest way attackers get them.
  • Microsoft's 622 July patches must be applied immediately; three zero-days are actively exploited in production systems.
  • MFA blocks 99.9% of credential-based attacks; it is the single most cost-effective control for small businesses.
  • Kali365 targets Microsoft 365 users with near-perfect fake login pages; staff training on URL verification prevents most breaches.

Frequently asked questions

What is the Kali365 phishing platform and who does it target?

Kali365 is an active phishing service that mimics Microsoft 365 login pages with near-perfect accuracy. It has already caused $12 million in losses in Florida by tricking employees into entering their credentials. It targets small and mid-size businesses across all industries.

How do I know if my team needs phishing training?

If your business uses Microsoft 365 and has not run phishing simulations in the past 6 months, training is overdue. Staff should be able to identify fake login pages, verify sender addresses, and know when to report suspicious emails to your IT team or MSP.

Which Microsoft patches should I apply first?

Prioritize patches for the three actively exploited zero-days: BitLocker, SharePoint, and Active Directory. Apply all 622 patches within 48 hours to critical systems. Your MSP can automate this process and verify completion across all devices.

Is multi-factor authentication (MFA) really necessary for small businesses?

Yes. Sophos research shows that MFA blocks 99.9% of credential-based attacks. At a small cost per user per month, MFA is the highest-return security investment you can make, especially for cloud services like Microsoft 365.

Sources

Keep reading