Services Managed IT Cybersecurity Cloud & Microsoft 365 Network Infrastructure Backup & Disaster Recovery vCIO & IT Strategy Who We Serve Engineers & Architects Financial Services Professional Services Restaurants & Hotels Other Industries About Us Resources Contact Partners Submit a Ticket Free Consultation
Back to Resources
Newsletter · Security Update

digiWEST Security Update: July 2026

July 2026 · By Paul White, CEO · 5 min read

Over the last few months, the most consistent pattern across North American cyber incidents was not hackers “breaking in,” but rather hackers logging in. Across breaches affecting telecommunications companies, universities, healthcare systems, and technology platforms, attackers repeatedly entered through stolen credentials, piggybacked on trusted app connections, or tricked employees into handing over access. In the most notable cases, no firewall was defeated and no vulnerability was exploited. A phishing email, a reused password, or a third-party app permission was all it took.

For small and medium-sized businesses, this shift matters enormously. Many SMBs invest in antivirus software and firewalls but have not updated how they think about identity: who has access to what, which apps connect to employee accounts, and whether staff can recognize a login page designed to steal their credentials. As attackers increasingly use AI-powered tools to make phishing emails look legitimate and automate credential theft at scale, the gap between organizations with strong identity hygiene and those without is growing fast.

FBI Warns: Hackers Using PhaaS Platform to Bypass MFA and Access Microsoft 365 Environments

The FBI recently issued a warning about the Kali365 phishing-as-a-service (PhaaS) platform, which facilitates Microsoft 365 account hijacking by abusing OAuth device code authentication and adversary-in-the-middle (AitM) proxying.

Key Takeaways

Why it matters: The Kali365 platform subscription serves as an entry point for less sophisticated attackers. The FBI warning comes about a month after a report by Arctic Wolf on an operation that used the Kali365 platform. Other recent reports have found criminal actors using device-code phishing to gain access to Microsoft 365 accounts.

Ransomware by Landscape: Most Active Groups

Qilin Akira Dragonforce INC Ransom Play
North America ransomware trends: most targeted countries are the United States (90.3%), Canada (7.6%), and Mexico (2.2%); most targeted industries are legal and professional services (16.7%), construction and engineering (14.5%), manufacturing (12.2%), healthcare (9.4%), retail (8.3%), and other (38.9%).
North America ransomware trends: most targeted countries and industries.

Ransomware Spotlight: Akira

How they get in: Akira frequently partners with Initial Access Brokers, which are criminals who specialize in selling pre-obtained VPN and network credentials. This lets them skip the initial intrusion step entirely and go straight to spreading through a victim’s systems.

What they do once inside: Akira is known for rapid movement. Once credentials are secured, the group can encrypt a large network within hours. In some sectors, including financial services, Akira has shifted toward data theft and extortion rather than encryption — particularly exploiting ‘Shadow AI,’ where employees use unauthorized AI tools that inadvertently expose configuration data or credentials.

Who they are targeting in North America right now: Financial services, manufacturing, and technology companies, with a growing focus on mid-sized firms with less mature security programs.

Company Size Target Profile

51-200 employees
28.17%
11-50 employees
28.17%
201-500 employees
15.23%
1,001-5,000 employees
10.37%
501-1,000 employees
8.44%
1-10 employees
6.39%
10,001+ employees
4.19%
5,001-10,000 employees
2.31%

Small and medium-sized businesses remain the most frequently targeted in North America. While ransomware groups most often set sights on smaller businesses, the impact rarely stays contained — shared vendors, platforms, and service providers mean a breach at one company can ripple across its entire network of partners and clients.

digiWEST System and Operations Practices

Written by Paul White, CEO of digiWEST. The digiWEST Security Update is a recurring look at the threats affecting Pacific Northwest businesses — and what we’re doing about them.

Not sure where your defenses stand?

digiWEST helps Pacific Northwest businesses close the identity and credential gaps attackers are exploiting right now. Let’s take a look together.

Get a Free Consultation