Ransomware, smarter phishing, and password attacks are driving this week’s biggest cybersecurity stories, especially for individuals and small businesses.[1][2][3] The good news is that a few practical steps—better passwords, stronger sign‑in methods, and simple checks on emails and invoices—go a long way.[4][5][6]
1. Ransomware hitting small businesses
Ransomware groups are increasingly going after small and mid‑sized businesses, using tactics like encrypting data and threatening to leak it if no ransom is paid.[1][2] These attacks often start through weak or reused passwords, fake emails, or unsecured remote access tools.[1][7]
BET-R Actions: Keep at least one backup that is offline or read‑only so criminals cannot encrypt it.[1] Use unique, strong passwords and turn on multi‑factor authentication (MFA) for email, remote access, and financial systems.[1][2] Limit who can log in remotely and remove accounts and access you no longer use.[2][7]
2. Password and account takeover warnings
Federal agencies and major tech companies are warning that passwords are being stolen and reused at record levels, putting Apple, Google, Microsoft, and banking accounts at high risk.[3][4] Criminals then take over accounts to move money, lock you out, or use your identity in other scams.[4][8]
BET-R Actions: Switch to a password manager and let it create long, random passwords, especially for email, cloud services, and banking.[4] Turn on MFA everywhere and prefer app‑based codes or hardware keys instead of text messages where possible.[4][9] Check account activity regularly and set up alerts for sign‑ins, payments, and password changes.[3][8]
3. Smarter phishing: email, text, and voice
Recent breaches and holiday‑season scams are fueling more convincing phishing attempts through email, SMS, and phone calls, including fake invoices, package notices, and “IT support” calls.[6][10][11] Attackers use exposed email addresses and business contact data to send messages that look highly personalized and trustworthy.[12][13]
BET-R Actions: Slow down on any unexpected message asking for payment, login, or urgent action; confirm using a known phone number or website, not links in the message.[6][11] Train staff—formally or informally—to spot red flags like pressure, spelling errors, or changes in payment details.[2][13] Use email security features such as spam filtering and flagging external senders, which most business email systems provide.[2][11]
4. Attacks that bypass basic MFA
Researchers are seeing more “man‑in‑the‑middle” phishing tools that sit between users and real websites, stealing both passwords and session cookies so attackers can get in even after the user completes MFA.[5][8] These techniques are showing up in organizations of all sizes and will increasingly affect individuals as criminals refine their tools.[5][14]
BET-R Actions: Where supported, turn on “phishing‑resistant” options like passkeys or hardware security keys instead of codes you type.[4][5] If anything feels off during login (unexpected prompts, new domain, certificate warnings), close the window and go directly to the site by typing the address.[5] If you suspect a phishing login, sign out of all sessions on that account, change your password, and review recovery options immediately.[3][5]
5. Why December is especially risky
Security experts report that December is one of the most dangerous times of the year online, with spikes in holiday‑themed phishing, fake invoices, and gift card scams targeting both consumers and small businesses.[6][8] Criminals count on busy schedules and year‑end pressure, making people more likely to click quickly or approve unusual payments.[6][15]
BET-R Actions: For businesses, require a second person to approve changes in bank details, large payments, or bulk gift card purchases.[6][15] For individuals, treat surprise “delivery problem,” “account locked,” or “holiday deal” messages with extra suspicion and go to the provider’s official app or site to verify.[6] Schedule a quick “year‑end security check” to update passwords, review who has access to key systems, and test that backups actually work.[1][2]
Recent Trends and Incidents
Several organizations have disclosed new or ongoing cyber incidents in the last week, ranging from financial data theft to silent spying through browser extensions.[16][17] Below are a few high‑level examples explained in plain language, along with what they mean for everyday people and small businesses.
- Marquis (financial data service)
A U.S. financial technology firm called Marquis reported that criminals broke into its systems earlier this year and are now notifying banks and credit unions whose customer data was stolen.[18][19] The attackers used ransomware, meaning they both locked parts of the system and copied sensitive information connected to bank and credit union customers.[18]
What this mean for you:
If a bank uses a third‑party company for analytics, marketing, or loan processing, that vendor’s breach can expose your data even if your own bank’s systems were not directly hacked.[18][19] Individuals should watch for unusual account activity and be extra cautious with emails or calls that reference their bank or credit union by name, since stolen data can be used to create very convincing scams.[18][20] - 700Credit (auto finance data)
700Credit, a company that provides credit and compliance services to car dealerships, disclosed that attackers accessed one of its systems and pulled customer data over several months in 2025.[21] Even though the vulnerable part of the system was shut down, the company said attackers still managed to copy a significant portion of consumer information used by dealerships.[21]
What this means for you:
People who applied for auto loans or financing at affected dealerships may have personal details—such as contact information and possibly finance‑related data—circulating among criminals.[21] Watch for loan or credit applications you did not make and consider placing fraud alerts or credit monitoring if notified by the company or your dealership.[20][21] - Time Bank and Valley Strong (banking sector notices)
Consumer‑protection and legal‑notice sites highlight that a number of U.S. financial institutions, including Time Bank and Valley Strong, are now listed as affected by vendor‑related incidents tied to Marquis.[20] These notices indicate that customer data belonging to these banks’ clients may have been accessed, even though the original breach occurred at the service provider, not the banks themselves.[18][20]
What this means for you:
For small banks and credit unions, a single vendor breach can cascade into many institutions needing to notify customers and strengthen their security reviews.[18][20] Customers should carefully read any mailed or emailed notices about data incidents and use offered identity‑protection or credit‑monitoring services, while staying alert for phishing that abuses the bank’s name.[20] - Spyware in browser extensions (Chrome and Edge)
Security researchers revealed that some browser extensions for Chrome and Microsoft Edge—previously seen as harmless tools—were secretly turned into spying software over time.[17] This long‑running campaign reportedly affected more than 4 million users, letting attackers track online activity and potentially capture sensitive information entered into websites.[17]
What this means for you:
Individuals and small businesses that install “free” browser add‑ons for productivity, coupons, or utilities may unknowingly give attackers a window into their browsing and online accounts.[17] Regularly review installed extensions, remove anything you do not recognize or no longer use, and prefer well‑known publishers with many reviews and a clear privacy policy.[17]
Even though these incidents involve larger vendors and platforms, the ripple effects hit everyday users and smaller organizations.[16][22] The most practical steps now are to use strong, unique passwords with a password manager, turn on multi‑factor authentication for banking and email, monitor accounts and credit reports for unusual activity, and treat unexpected emails, texts, or calls referencing banks, loans, or browser updates with extra caution.[17][23][24]
Citations:
[1] Ransomware 2025: Protection Essentials for Atlanta SMBs https://trueitpros.com/ransomware-2025-protection-essentials-for-atlanta-smbs/
[2] Small Business Cyberattacks Rise in 2025: Guardz Mid-Year Findings https://guardz.com/blog/small-business-cyberattacks-rise-in-2025-guardz-mid-year-findings/
[3] The Most Recent Data Breaches in 2025 – Breachsense https://www.breachsense.com/breaches/
[4] Feds Warn iPhone And Android Users—Change Apple, Google And … https://www.forbes.com/sites/zakdoffman/2025/12/05/feds-warn-iphone-and-android-users-change-apple-google-and-microsoft-passwords/
[5] Attackers have a new way to slip past MFA in educational orgs https://www.malwarebytes.com/blog/news/2025/12/attackers-have-a-new-way-to-slip-past-your-mfa
[6] December 2025 The Most Dangerous Time of the Year – 1Wire Fiber https://1wirefiber.com/business-data-services/network-optimization/cybercriminals-make-december-2025-the-most-dangerous-time-of-the-year/
[7] CISA, FBI update guidance on ransomware threat impacting small … https://insidecybersecurity.com/daily-news/cisa-fbi-update-guidance-ransomware-threat-impacting-small-businesses
[8] Cybersecurity Snapshot: December 5, 2025 | Tenable® https://www.tenable.com/blog/cybersecurity-snapshot-brickstorm-malware-ai-ot-12-05-2025
[9] NYDFS Cybersecurity Crackdown: New Requirements Now in Force … https://www.workforcebulletin.com/nydfs-cybersecurity-crackdown-new-requirements-now-in-force-are-you-compliant
[10] Data Breaches That Have Happened This Year (2025 Update) https://tech.co/news/data-breaches-updated-list
[11] 2025 Retail Data Breaches: Email Exposure Risks and Solutions. https://guardiandigital.com/resources/blog/how-exposed-emails-lead-to-breaches
[12] Data Breaches 2025: Biggest Cybersecurity Incidents So Far https://www.pkware.com/blog/recent-data-breaches
[13] Phishing Trends Report (Updated for 2025) – Hoxhunt https://hoxhunt.com/guide/phishing-trends-report
[14] 2025 Cyber Incident Trends: What Your Business Needs to Know https://www.mayerbrown.com/en/insights/publications/2025/10/2025-cyber-incident-trends-what-your-business-needs-to-know
[15] Committee on Small Business Holds Hearing on the Threat of Rising … https://smallbusiness.house.gov/news/documentsingle.aspx?DocumentID=407347
[16] The Most Recent Data Breaches in 2025 – Breachsense https://www.breachsense.com/breaches/
[17] 4.3M Hit by Extension Backdoor – eSecurity Planet https://www.esecurityplanet.com/newsletter/cybersecurity-insider/2025-12-04/
[18] Fintech firm Marquis notifies affected business after ransomware … https://www.reuters.com/technology/fintech-firm-marquis-notifies-affected-business-after-ransomware-breach-2025-12-03/
[19] Fintech firm Marquis alerts dozens of US banks and credit unions of … https://techcrunch.com/2025/12/03/fintech-firm-marquis-alerts-dozens-of-us-banks-and-credit-unions-of-a-data-breach-after-ransomware-attack/
[20] Time Bank Data Breach Compromises Sensitive Customer Data of … https://www.claimdepot.com/data-breach/time-bank-2025
[21] 700Credit’s Ken Hill on recent data breach and what dealers need to … https://www.cbtnews.com/700credits-ken-hill-on-recent-data-breach-and-what-dealers-need-to-know/
[22] List of Recent Cybersecurity Data Breaches in 2025 – Bright Defense https://www.brightdefense.com/resources/recent-data-breaches/
[23] Data Breaches That Have Happened This Year (2025 Update) https://tech.co/news/data-breaches-updated-list
[24] May 2025 Data Breaches: 184M Passwords, 364K SSNs Leaked https://www.pomerium.com/blog/may-2025-data-breaches
