Friday Security Briefing: This Week's Biggest Breach — What Business Owners Must Know Before Monday

WilliamDeShon
2026-09-12 09:00
Friday Security Briefing: This Week's Biggest Breach — What Business Owners Must Know Before Monday
Katrina's Cyber Corner — Friday Security Briefing header banner Katrina's Cyber Corner — Friday Security Briefing

Friday Security Briefing: This Week's Biggest Breach — What Business Owners Must Know Before Monday

By Katrina, Wealth Horizons Academy Security Advisor  ·  September 12, 2026  ·  6 min read

It's Friday — and before you close your laptop, pour a glass of wine, and hand the keys over to the weekend, I need five minutes of your time. Because while you're off the clock, the people who want to get into your business systems absolutely are not.

This week handed us a sobering reminder. Ransomware attacks hit a record-breaking high in August 2026 — 997 confirmed attacks in a single month, or roughly 32 attacks every single day (Comparitech, Ransomware Roundup August 2026). September is tracking even higher. And a disturbing pattern is baked into every single one of those attacks: they almost always start on a Friday afternoon.

⚡ Key Takeaways
  • Ransomware attacks reached 997 in August 2026 alone — 23% up from July (Comparitech, 2026).
  • Hackers deliberately launch attacks on Friday evenings and weekends when business teams are understaffed.
  • This week's Amgen breach exposed patient health information and company data via a third-party cloud provider — a supply-chain risk every SMB shares.
  • One action you can take before you leave the office today: verify your backup ran successfully this week.

🔴 This Week's Threat: The Amgen Breach and the Cloud Storage Blind Spot

The headline breach of the week belongs to biotech giant Amgen. Hackers infiltrated cloud storage systems managed by a third-party provider and walked out with sensitive company data and patient health information. The investigation is still ongoing, but the attack method is one cybersecurity professionals have been warning about for years — and that's exactly what makes it so dangerous for small and mid-sized businesses like yours.

Here's what you need to understand: Amgen's attackers didn't break down the front door. They came in through a side entrance they didn't fully own. A third-party vendor — a cloud storage partner — became the breach point. This is known as a supply-chain attack, and it is now the fastest-growing attack vector in 2026.

You may think, "I'm not Amgen. I don't have patient data." But if your business uses any cloud-based tools — accounting software, CRM platforms, e-commerce integrations, shared document storage, payment processors — you have the same exposure. Every third-party app connected to your business is a potential open window.

🔍 Katrina's Observation In over a decade advising business owners on cyber risk, the most common phrase I hear after a breach is: "I didn't know that vendor had access to that." This week's Amgen incident is a textbook example. Map your third-party app connections this weekend — before an attacker does it for you.

📊 The Numbers You Need to Know

Let's make this concrete. These are the statistics you should carry into every security conversation with your team starting next week.

  • 997 ransomware attacks were recorded in August 2026 — a 23% increase from July and the highest monthly total on record (Comparitech, September 2026).
  • 76% of ransomware attacks are launched on a Friday, Saturday, or Sunday when IT teams are reduced or absent (Cybersecurity Dive).
  • 1.8 million people were confirmed affected in one healthcare breach in August 2026 that exposed not just medical records but biometric fingerprint and palm print data — filed as one of the largest U.S. healthcare breaches of the year (PKWARE, 2026 Data Breaches).
  • AI-powered phishing is now the primary delivery method for ransomware targeting small businesses, with hyper-realistic emails that bypass traditional spam filters (WIN Technology, 2026).
  • The average cost of a ransomware attack for a small business in 2026 now exceeds $185,000 when downtime, recovery, and reputational damage are factored in.

These numbers aren't meant to scare you into paralysis. They're meant to remind you that the threat is real, it is escalating, and it is specifically targeting businesses that haven't trained their teams.

✅ What To Do Before Monday

You don't need a six-figure IT department to significantly reduce your risk this weekend. Here are five targeted actions you or your team can complete before Monday morning.

  1. Verify your last backup. Check that your most recent automated backup ran successfully and that you can actually restore from it. A backup you can't restore is not a backup.
  2. Audit your third-party app list. Open your cloud accounts and list every connected integration. Ask yourself: does this vendor need the access level it currently has? Revoke anything you don't recognize or no longer use.
  3. Enable multi-factor authentication (MFA) on email. If your business email doesn't have MFA turned on, do it now. Over 80% of account compromises involve stolen credentials — MFA blocks most of them.
  4. Send a phishing heads-up to your team. A quick Friday-afternoon message to staff saying "Be extra vigilant this weekend with any login requests or unusual emails" takes two minutes and can prevent a disaster.
  5. Check for pending software updates. Unpatched systems are the #1 entry point for ransomware. Approve and run any pending updates before you leave for the weekend.

One of those five is your immediate action for today. Pick the one that's most overdue and do it before you close your computer. If you're not sure where to start, start with your backup.

🔒 Limited-Time Offer — Expires September 24, 2026

Corporate Cybersecurity Training License

Give your entire team the skills to recognize and stop attacks before they happen. Our hands-on corporate training covers phishing defense, cloud security, ransomware response, and more — built specifically for business owners and their staff.

$1,747 Regular price: $2,496 ⏰ 30% OFF — Offer ends September 24, 2026 Claim 30% Off Now →

Frequently Asked Questions

Why do hackers target businesses on weekends?

Cybercriminals deliberately time attacks for Friday evenings, weekends, and public holidays because security teams are smaller or absent. According to Cybersecurity Dive, 76% of ransomware attacks are initiated outside of normal business hours. With fewer people monitoring systems, attacks can run unchallenged for hours before anyone notices.

What is a supply-chain cyberattack and how does it affect my small business?

A supply-chain attack happens when hackers breach a vendor or partner who has access to your systems — rather than attacking you directly. The 2026 Amgen breach is a recent example. Even if your own defenses are strong, a vulnerability in a connected cloud tool or software provider can expose your business data. Regularly reviewing which third-party apps have access to your accounts is a critical defense step.

How much does a ransomware attack actually cost a small business?

In 2026, the average total cost of a ransomware incident for a small business exceeds $185,000 when you factor in operational downtime, data recovery, legal notifications, and reputational damage. Many businesses never fully recover. Cybersecurity training is one of the highest-ROI investments a business owner can make — far cheaper than a single incident.

Is multi-factor authentication really enough to stop a breach?

MFA alone doesn't guarantee security, but it blocks over 99% of automated account-takeover attacks, according to Microsoft's 2025 Security Intelligence Report. It's the single fastest and most affordable step a business can take. Combined with staff training and regular backups, MFA is a critical layer in your overall defense strategy.

How often should my business run cybersecurity training?

Cybersecurity threats evolve constantly — and so should your team's knowledge. Security professionals recommend at minimum annual comprehensive training, with monthly briefings like this one keeping staff aware of current threats. Businesses that run regular training reduce their risk of a successful phishing attack by up to 70%, according to industry benchmarks.

Stay informed. Stay protected. And take five minutes today to make your business a harder target.

Have a safe and secure weekend — Katrina, Wealth Horizons Academy Security Advisor

References

1. Comparitech — "Ransomware Roundup: August 2026", updated September 8, 2026, https://www.comparitech.com/news/ransomware-roundup-august-2026/

2. Tech.co — "Data Breaches That Have Happened This Year (2026 Update)", retrieved 2026-09-11, https://tech.co/news/data-breaches-updated-list

3. PKWARE — "2026 Data Breaches: Cybersecurity Incidents", August 10, 2026, https://www.pkware.com/blog/2026-data-breaches

4. Cybersecurity Dive — "Cybercriminals strike understaffed organizations on weekends and holidays", retrieved 2026-09-11, https://www.cybersecuritydive.com/news/cyberattacks-weekends-holidays/636956/

5. WIN Technology — "AI-Powered Cyberattacks Are Targeting Small Businesses in 2026", retrieved 2026-09-11, https://www.wintechnology.ai/insights/ai-cyberattacks-small-business-2026-southern-california/