Cybercriminals are starting 2026 with more targeted scams, big data breaches, and smarter social‑engineering, especially against regular people and small businesses. The good news is there are clear, simple preventative measures you can take this week to cut your risk dramatically.
1. Big data breaches keep exposing personal info
Recent breaches at companies that handle financial and healthcare data have exposed Social Security numbers and other sensitive details for millions of people, which criminals can use for identity theft and loan or credit fraud months or years later. Many of these incidents start through third‑party vendors with weak security, meaning your data can be exposed even if you have never heard of the company that was actually hacked.
BET-R Actions: Freeze your credit with Equifax, Experian, and TransUnion so new accounts cannot be opened in your name without your approval. Use a free credit report and bank/credit card alerts to spot unknown accounts or charges quickly, and act immediately on any breach notification letters or emails you receive. Avoid clicking “verify your identity” links in unsolicited emails or texts; go directly to the company website or app instead.
2. Ransomware hitting small and mid‑sized businesses
Ransomware attacks, where criminals lock up your files and demand payment, are increasingly hitting small and mid‑sized businesses because they are big enough to pay but often lack full‑time security teams. Reports show ransomware appears in a very high share of breaches at smaller organizations, often starting from vulnerabilities, stolen passwords, or malicious emails.
BET-R Actions: Keep at least one offline or cloud backup that is not permanently connected to your main systems, and test restoring from it regularly. Turn on automatic updates for computers, phones, point‑of‑sale systems, and routers to close known security holes. Train staff not to open unexpected attachments or enable macros on documents, especially on invoices, resumes, or shipping notices.
3. Smarter phishing, especially via social media and DMs
Attackers are using more convincing phishing messages, including urgent DMs that pretend to be angry customers, “support” staff, or delivery problems, to steal logins or install malware. These scams take advantage of small‑business owners’ desire to respond quickly and of individuals’ fear that accounts will be closed or orders canceled.
BET-R Actions: Never click a link in a message that pressures you to act immediately; instead, log in through your usual app or saved bookmark to check for issues. For businesses, verify “customer issues” in your order or ticketing system before opening links or files sent via social media or chat. Use unique, long passwords and turn on two‑factor authentication (2FA) for email, banking, social media, and any business admin accounts to limit damage if a password is stolen.
4. AI‑powered scams and deepfake voices
Experts warn that AI tools are making scam emails, texts, and even voice calls sound more natural and personalized, which increases the success of fraud attempts against individuals and small businesses. Criminals can clone a boss’s or family member’s voice or style and then request urgent payments, gift cards, or sensitive information.
BET-R Actions: Set a “shared secret” phrase or code word with family and key staff that must be used before acting on any urgent money or password request, even if the voice sounds right.For businesses, require a second person to approve unusual payments, changes to bank details, or large gift card purchases, and confirm such requests through a known phone number or in person. Be extra skeptical of any message that mixes urgency (“right now”) and secrecy (“don’t tell anyone”)—that combination is a major red flag.
START SMALL: Everyday habits that dramatically lower risk
Security groups and small‑business experts are urging people to treat 2026 as a fresh start for basic cyber hygiene, because simple habits block a large share of common attacks. Many incidents begin with weak or reused passwords, missing updates, overshared photos, or visible login details on desks and screens.
Start 2026 the right way and focus this week on strengthening security around Passwords, MFA and Social Media. Use a reputable password manager, change key account passwords to long passphrases, and stop reusing the same password across sites. Turn on 2FA wherever available, especially for email, banking, finance apps, and any system that holds customer data. Review your social media posts and office photos to make sure no screens, badges, or sticky notes with passwords or customer data are visible.
Recent Trends and Incidents
Several large organizations have disclosed or updated cyber incidents in the last week, mostly involving outsiders getting into systems and viewing or copying personal data. Here are a few of the most impactful breaches affecting individuals and small businesses, and key takeaways that can help you secure your data.
- Sentinel Security & Atlantic Coast Life (insurance)
Sentinel Security Life and Atlantic Coast Life, two life insurance companies, reported that an intruder was in parts of their computer network for about a week in April 2025 and may have accessed files with names, Social Security numbers, and medical details for policyholders and others. The companies finished reviewing what was taken in December and formally reported the data breach to regulators on December 30, 2025, then began notifying affected people.
What this mean for you: If you get a notice from these insurers, assume your Social Security number may be exposed and strongly consider placing a free credit freeze and fraud alerts on your credit files. Watch for insurance‑related or medical scam calls or emails using your correct personal details to sound convincing, and never share codes or full SSNs over the phone or email. - TriZetto / Cognizant (healthcare software platform)
TriZetto, a healthcare software platform owned by Cognizant, is facing lawsuits after a long‑running breach exposed sensitive health data held for health plans and providers. The incident involved personal and medical information tied to patients whose data moved through TriZetto’s systems, rather than a direct attack on small clinics themselves.
What this means for you: Even if your doctor or insurer was not “hacked,” a vendor they use can leak your data, so read any mailed breach letters carefully and enroll in free monitoring they may offer. For small healthcare or insurance businesses, ask software vendors to confirm how they protect data, whether they use encryption, and what they must do if they suffer a breach. - Coupang (large online retailer)
Coupang, a major e‑commerce company, continues to deal with fallout and lawsuits over a massive breach where a former employee kept access and pulled personal details from tens of millions of customer accounts. Exposed information included names, phone numbers, email addresses, and delivery addresses, but the company says full payment card details were not accessed.
What this means for you: This shows how dangerous “insider” access can be; small businesses should quickly remove system access when employees or contractors leave. If you shop online, regularly review which sites store your address and card info and remove saved cards you no longer need, then turn on alerts for new logins or purchases where available. - Covenant Health (hospital system ransomware impact update)
Covenant Health updated its numbers and now says a ransomware‑related breach from July 2025 ultimately affected over 478,000 people, far more than initially reported. Attackers got into systems, disrupted operations, and were able to access files containing personal and medical data before the incident was contained.
What this means for you: For patients, this kind of breach increases risk of medical and identity fraud, so keep any “explanation of benefits” letters and bills, and question charges for care you never received. For clinics and small practices, ransomware often starts with a single stolen password or unpatched system; using multi‑factor authentication and timely software updates is critical. - University of Phoenix (education sector breach)
The University of Phoenix disclosed a breach affecting nearly 3.5 million people after criminals got into its systems and accessed student and staff information. Data included personal identifiers and contact details, which can be reused for targeted phishing emails and scam calls.
What this means for you: Current and former students should be wary of messages that look like school communications asking them to “verify” accounts or payment details and should log in only via the official website or app. Any small school, training program, or tutoring business that stores student details should limit who can access records, use strong unique passwords with two‑factor authentication, and back up key data.
Recent cyber incidents highlight how attackers often target small businesses that manage sensitive personal data but lack robust protections. When these businesses are compromised, the fallout can be severe—customers’ personal information may be exposed, and day-to-day operations can grind to a halt due to data loss or system downtime.
Small businesses should operate under the assumption that breaches can occur through their own systems or through trusted suppliers, insurers, or technology partners. Now is the time to plan: know who to contact, how to secure accounts, and how you’ll communicate with affected customers if personal data is at risk.
Reduce your vulnerability by collecting only the data you truly need, storing it securely in as few places as possible, and protecting those systems with multi-factor authentication and frequent, tested backups. Quick, honest communication after an incident shows responsibility and helps preserve customer trust.
Strong cybersecurity hygiene—regular updates, employee awareness, and proactive data protection—can make the difference between a quick recovery and a lasting business disruption.
Citations:
Trends & Predictions from the Latest Ransomware Statistics 2026
Inside the Cyber Extortion Boom: Phishing Gangs and Crime-as-a-Service – Infosecurity Magazine
Cybersecurity resolutions to act on for a safer 2026 online experience | Fox News
Kickstarting 2026: Cybersecurity Hot Topics Every Small Business Must Know | U.S. Small Business Administration
700Credit data breach exposes 5.8 million people’s Social Security numbers | Fox News
700Credit data breach impacts 5.8M individuals
Covenant Health Data Breach Exposes Personal Information: Murphy
Consumer Action INSIDER – January 2026
Cybersecurity Risks in 2026: What Florida Businesses Need
Look ahead to 2026 in January: Businesses urged to prepare now as cyber security threats intensify – SME BUSINESS NEWS
6 Social Media Habits That Put Small Businesses at Risk of Cyberattacks – CPA Practice Advisor|
What Cyber Experts Fear Most in 2026: AI-Powered Scams, Deepfakes, and a New Era of Cybercrime
Cybersecurity News, Insights and Analysis | SecurityWeek
Cybersecurity new data breach study 2026; how to protect your identity?
7 of the biggest threats to small businesses in 2026 (and how to avoid them)
National Cybersecurity Alliance
WXOW – Small businesses face rising risks in 2026,…
10 New Ransomware Groups Of 2025 & Threat Trends For 2026
On the Ninth Day of Data… State of the States: This Year’s Key Privacy Law Developments Across the U.S. States | Ropes & Gray LLP – JDSupra
Interesting Cybersecurity News of the Week Summarised – Reddit
Sentinel Security & Atlantic Coast Life Insurance Companies Data Breach
TriZetto Data Breach Triggers Class-Action Lawsuits Against Cognizant
Covenant Health data breach after ransomware attack impacted over 478,000 people
Ankura CTIX FLASH Update – December 30, 2025 – Ankura.com
Coupang faces U.S. lawsuit, fallout widens after data breach
Coupang Offers $1 Billion Compensation for Data Breach Victims
St. Anthony Regional Hospital Data Breach Exposes PII & PHI
New Liberty Hospital; New York Blood Center; Memorial Blood Centers Settle Data Breach Lawsuits
Korean Air Data Compromised in Oracle EBS Hack – SecurityWeek
Data Breaches 2025: Biggest Cybersecurity Incidents So Far – PKWARE®
Lynn Community Health Center Data Breach Investigation – Strauss Borrelli PLLC
Ransomware Attack 2025 Recap – From Critical Data Extortion to Operational Disruption | Cryptika Cybersecurity
Resecurity | Knownsec Data Breach: A Trove of Espionage Tradecraft with an Insider Narrative
Ransomware.live
The 10 Biggest Data Breach Fines and Settlements of 2025 – Infosecurity Magazine
Top Data Breaches of December 2025- Security Boulevard
Office of Public Affairs | Two Americans Plead Guilty to Targeting Multiple U.S. Victims Using ALPHV BlackCat Ransomware | United States Department of Justice
Largest Healthcare Data Breaches of 2025
NEWS ROUNDUP – 31st December 2025 – Digital Forensics Magazine
Hacks, thefts, and disruption: The worst data breaches of 2025
