Cybercriminals are heavily targeting individuals and small businesses this week with smarter phishing, fake online stores, and ransomware that often starts from a single stolen login. [1][2] Staying safe mostly comes down to slowing down before you click, tightening access to your accounts, and planning what you would do if a device or account was suddenly locked. [2][3]
1. Holiday shopping scams
Thousands of AI-generated fake shopping sites and scam emails are pushing “too good to be true” holiday deals to steal card details and personal info. These scams often copy real brands’ designs and use convincing domain names, ads, and social media posts to lure victims. [4][5]
BET-R Actions: Type website addresses yourself or use bookmarks; avoid clicking on deal links from texts, emails, or social media. Pay with credit cards or trusted payment services, and check statements weekly so you can quickly dispute unknown charges. If a new store is unfamiliar, search “[store name] reviews scam” and avoid sites with no history or only very recent reviews. [5][6][7]
2. Surge in small business attacks
Over 80% of small businesses report being hit by cybercrime in the past year, and many had to raise prices or eat large losses to recover. A big chunk of attacks now use AI to craft personalized phishing emails or messages that look like they come from real suppliers, customers, or staff. [2][3][8]
BET-R Actions: Train staff to verify any unexpected payment, bank change, or urgent request by calling a known number, not replying to the email. Turn on multi-factor authentication (MFA) for email, banking, and accounting tools so stolen passwords alone are not enough. Keep at least one backup of critical business data offline or in a separate cloud account that is not logged in all the time. [1][2][3]
3. Ransomware and data breaches
Ransomware groups continue to hit companies of all sizes, stealing data and locking systems; many incidents start with a reused or phished password or an unpatched system. Recent cases show stolen personal data often includes names, addresses, Social Security or national ID numbers, and payment information, which can later fuel identity fraud. [1][9][10][11]
BET-R Actions: Update devices, routers, and business software regularly and enable automatic updates wherever possible. Use unique, strong passwords plus a password manager so a breach of one site does not unlock everything. If a provider you use reports a breach, change passwords immediately, enable MFA, and place fraud alerts or credit monitoring where available. [1][2][7][9][10][12]
4. Identity and payment fraud spike
Identity fraud and card fraud are rising, especially around the holidays, with criminals using stolen or AI-generated personal data to open accounts and take out credit in other people’s names. Fraud databases in the UK have recorded hundreds of thousands of suspected cases this year, highlighting how widespread this problem has become. [3][7]
BET-R Actions: Turn on alerts from your bank and card provider for new sign-ins, card-not-present purchases, and large or foreign transactions. Regularly check your credit reports for new accounts you do not recognize and dispute anything suspicious right away. Be cautious with online quizzes, giveaways, and “account verification” forms that ask for full name, date of birth, address, or ID numbers. [3][7][13]
For individuals and small businesses, the biggest risks right now come from realistic-looking scams and login theft, not “Hollywood-style” hacks. Focusing on a few basics—MFA everywhere, careful clicking, strong unique passwords, and solid backups—will block or soften the impact of most of the threats making headlines this week. [1][2][3]
Recent Trends and Incidents
Several organizations disclosed or were linked to cyber incidents in the past week, affecting customers’ personal and financial information, mostly through ransomware or hacked vendor systems. Below is a high-level overview of a few notable cases and what they mean for everyday people and small businesses. [14][15][16][17][18]
- Fieldtex Products (manufacturing and medical supplies)
Fieldtex, a U.S. manufacturer and supplier of medical and safety products, reported a data breach tied to the Akira ransomware group. Attackers broke into company systems, accessed files, and exposed personal data for around 238,000 people connected to the business.
What this mean for you:
If you dealt with Fieldtex (as a customer or partner), watch for breach notices and be alert to unusual emails or account activity that reference your relationship with them. Consider changing passwords on related accounts and enabling multi‑factor authentication, since criminals may use stolen details to reset logins elsewhere. [14] - Marquis Software Solutions (financial services vendor)
Marquis is a U.S. fintech and marketing software provider that serves banks and credit unions; it disclosed that a ransomware attack in August led to data theft that is only now being fully reported. Files accessed in the breach contained personal and financial information from customers of many different financial institutions that rely on Marquis.
What this means for you:
Even if your bank was not directly hacked, your data can be exposed through a third‑party vendor like Marquis that your bank uses behind the scenes. Follow any bank notification instructions, enroll in offered credit monitoring, and set up alerts for new accounts or large transactions on your financial profiles. [15][16][18][19] - Freedom Mobile (telecom, Canada)
Freedom Mobile, a Canadian mobile phone provider, reported that an attacker used a subcontractor’s valid login to access its internal customer management tools. This allowed the attacker to view and collect data on some mobile subscribers before the account was shut down the same day.
What this means for you:
This kind of incident shows that stolen or misused logins at a partner company can expose your data, even when the main provider has strong security. Customers should watch for targeted scams (texts, emails, calls) that reference their mobile account or personal details and verify changes directly through official apps or phone numbers. [15] - Inotiv (pharmaceutical research company)
Inotiv, a contract research organization in the pharmaceutical sector, confirmed that a ransomware attack earlier in the year also involved theft of personal data for at least 9,542 people. The exposed information includes names, addresses, dates of birth, ID numbers, payment details, and in some cases medical or insurance-related information.
What this means for you:
If you worked for, did business with, or had studies conducted through Inotiv, the stolen data could be used for identity fraud or targeted phishing. Consider freezing or locking your credit where available and be cautious with any messages that reference medical services, benefits, or insurance tied to this company. [15][20]
These incidents show that attackers often do not go after individuals directly at first; instead, they break into companies that hold large amounts of personal data and then use that information for fraud and scams. Using strong, unique passwords, turning on multi‑factor authentication, and monitoring bank, card, and credit activity are practical steps that help reduce harm even when a company you rely on is breached. [14][15][16][17][18][19]
Citations:
[1] The Latest Small Business Ransomware Statistics (Dec 2025) https://programs.com/resources/small-business-ransomware-stats/
[2] 2025 Data Breach & Attack Recap – Bluefin Payment Systems https://www.bluefin.com/bluefin-news/2025-data-breach-attack-recap-what-broke-who-was-hit-and-how-to-fight-back-in-2026/
[3] Identity Theft Resource Center 2025 Business Impact Report https://finance.yahoo.com/news/identity-theft-center-2025-business-124300402.html
[4] Black Friday 2025 Scams: Brand Impersonation, Old … – Bitdefender https://www.bitdefender.com/en-us/blog/hotforsecurity/black-friday-2025-scams-brand-impersonation-old-scams-and-familiar-malware-drive-the-global-fraud-season
[5] It’s that time of the year: The holiday scams to avoid in 2025 https://moonlock.com/holiday-scams-2025
[6] Holiday scams 2025: These common shopping habits make you the … https://www.malwarebytes.com/blog/news/2025/11/holiday-scams-2025-these-common-shopping-habits-make-you-the-easiest-target
[7] Brits warned over new fraud threats ahead of Christmas period https://www.experianplc.com/newsroom/press-releases/2025/brits-warned-over-new-fraud-threats-ahead-of-christmas-period
[8] Cyberattacks force small firms to raise prices: ITRC https://www.cybersecuritydive.com/news/cyberattacks-force-small-firms-raise-prices-itrc/807619/
[9] Fieldtex Data Breach Impacts 238,000 – SecurityWeek https://www.securityweek.com/fieldtex-data-breach-impacts-238000/
[10] Pharmaceutical Firm Inotiv Discloses Ransomware Attack and Data … https://www.hipaajournal.com/inotiv-data-breach-ransomware-attack/
[11] Data Breaches 2025: Biggest Cybersecurity Incidents So Far https://www.pkware.com/blog/recent-data-breaches
[12] Top 10 Data Breaches of 2025 | Guardz.com https://guardz.com/blog/top-recent-data-breaches/
[13] [PDF] Holiday Shopping Cyber Threats 2025 | SOCRadar https://socradar.io/wp-content/uploads/2025/12/Holiday-Shopping-Cyber-Threats-2025.pdf
[14] Fieldtex Data Breach Impacts 238,000 – SecurityWeek https://www.securityweek.com/fieldtex-data-breach-impacts-238000/
[15] December 2025 Cybersecurity Breaches and Major Data Attacks https://firecompass.com/weekly-cybersecurity-intelligence-report-cyber-threats-breaches-2-dec-10-dec-2/
[16] Marquis Data Breach Exposes Dozens of Banks and Credit Unions … https://cyberpress.org/marquis-data-breach-exposes-dozens/
[17] The Data Breach Brief: Week of December 10, 2025 https://www.forthepeople.com/blog/data-breach-brief-week-december-10-2025/
[18] Fintech firm Marquis notifies affected business after ransomware … https://www.reuters.com/technology/fintech-firm-marquis-notifies-affected-business-after-ransomware-breach-2025-12-03/
[19] What the Marquis Software Breach Signals for Financial Institutions https://securityboulevard.com/2025/12/when-vendors-become-the-vulnerability-what-the-marquis-software-breach-signals-for-financial-institutions/
[20] Pharmaceutical Firm Inotiv Discloses Ransomware Attack and Data … https://www.hipaajournal.com/inotiv-data-breach-ransomware-attack/
