Security Squawk - The Business of Cybersecurity

Bryan Hornung Reginald Andre & Randy Bryan

Security Squawk is a business podcast dedicated to helping business people fight the war against cyber criminals.

  1. Oct 2

    1.3M Social Security Numbers Exposed, Microsoft Sounds the Alarm, Walmart Dragged Into a Breach

    One click on one email exposed 1.3 million Social Security numbers. If it can happen to a state Supreme Court, it can happen to the business you run. This week, the stories involve the Arizona courts, Microsoft, Walmart, Baxter, and Cardinal Health. *Your biggest cyber risk is the people and vendors you already trust.* Bryan Hornung, Randy Bryan, and Reginald Andre break down the cyber news executives, owners, and operators can't afford to miss. First, the Arizona Supreme Court. Attackers copied names and Social Security numbers for roughly 1.3 million people from debt records going back 30 years. It started when one employee opened a phishing email. IT shut the intrusion down in under two hours, but the attackers had already reached a backup server instead of the live system. An earlier wave of the disclosure was even worse: more than 150,000 reports on children in foster care. Your backups may be the least-watched copy of your most sensitive data. That's where these attackers went. Next, Microsoft's brand-new 2026 Digital Defense Report, built on more than 165 trillion security signals a day. One number should stop every owner: 97 percent of identity attacks still come down to a stolen password. AI has made phishing emails four to five times more effective. The "spot the typo" advice you've been giving your team is dead. And ransomware isn't just about locked files anymore. Almost two-thirds of break-ins now involve stolen data. Paying to unlock your systems does nothing about the copy that's already out the door. Finally, a vendor breach that should worry every company with suppliers. A Jacksonville freight company called TrailerBridge landed on the BrainCipher ransomware gang's leak site. The gang claims 76,200 files that name Walmart, Baxter, and Cardinal Health. Those giants did nothing wrong on their own systems. Their data was exposed because a mid-size partner holds their shipping and customs paperwork. One caution: the listing is unverified. A name on a leak site is an accusation, not proof. Verify the claim before you panic or dismiss it. • The Arizona Supreme Court breach that exposed 1.3 million Social Security numbers from one phishing email • Microsoft's 2026 report and why 97 percent of attacks still ride on a stolen password • The TrailerBridge leak that pulled Walmart, Baxter, and Cardinal Health into a ransomware gang's claims • Why your biggest risk is the people and vendors you already trust • How to protect your backups the way you protect your live systems • What to actually do when a vendor shows up on a leak site Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #DataBreach #Ransomware #Microsoft #Walmart #VendorRisk #Phishing #BusinessRisk #MSP #SmallBusiness #IdentityTheft

  2. Sep 29

    FBI Breached, AI Malware Hijacks Servers, Defense Supplier Hit by Ransomware

    FBI Breached, AI Malware Hijacks Servers, Defense Supplier Hit by Ransomware Hackers Claim They Breached the FBI and Stole Data on Nearly Every Agent A criminal crew says it stole data on nearly every FBI agent and job applicant through the bureau's hiring system. The reported way in was the kind of business software your company might run. "We're too small to be a target" doesn't hold up. *The tools you trust are now the attacker's way in.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to track cyber news but can't afford to be blindsided by it. First, the FBI. The extortion group ShinyHunters claims it stole more than two terabytes of data on almost every agent and job applicant. The bureau has confirmed it's investigating. The reported way in was a flaw in Oracle's PeopleSoft HR software, the kind thousands of mid-size companies run. From there, the attackers reportedly jumped into the FBI's cloud. That flaw has been disclosed since June and used all year. Any company still running an unpatched box faces the same risk. Leaked HR and applicant data could give the next attacker a ready-made kit for targeting people and their families. Next, malware that brings its own AI. Researchers found a botnet called Carbonato that hijacks Docker servers left exposed to the internet. It installs an AI agent on the machine and lets that agent decide what to do next. The attackers didn't build the AI. They took an open-source tool and rewrote a single 39-line instruction file to turn it hostile. Running an adaptive attack now takes little more than editing a text file. Its number-one target is your AI keys. The crew uses stolen keys to run its own bootleg AI service, so a leak costs you data and funds the attacker. The way in wasn't a nation-state exploit. It was a server left open with no password. Finally, a defense supplier on a ransomware leak site. A group calling itself Storm posted Applied Composites, a California company that makes composite parts for aircraft, missiles, and satellites. There's no ransom number yet and no list of stolen files. Posting the name first puts pressure on the victim; details can follow if it stays quiet. A 500-to-1,000-person manufacturer deep in the defense supply chain is an attractive target: pressure to pay, without a Fortune 500 security budget. For a supplier, a leak-site listing isn't just downtime. It's a customer-trust and compliance event that can cost contracts. None of these started with a genius hack. Trusted software left unpatched, a server left open, a supplier left under-protected. The attackers walked through the door. • How ShinyHunters claims it breached the FBI and what data is at risk • Why the software running your HR and cloud is now the front line • Carbonato: the malware that installs its own AI agent to hack for it • Why stolen AI keys are the new top prize for attackers • How a small defense manufacturer ended up on a ransomware leak site • Why attackers target the small supplier to reach the big customer • What business owners should do before their name is the one on the list Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #FBI #ShinyHunters #Ransomware #DataBreach #AI #Docker #VendorRisk #SupplyChainSecurity #MSP #BusinessRisk

  3. Sep 23

    AECOM Hit by Two Gangs at Once, CenterPoint Leaks 7.5M Records, Ransomware Sets a Record

    Two ransomware crews are claiming the same Fortune 500 company at the same time. It's the second week in a row this has happened. If you still think your business is too small to be worth a hacker's time, this is the week that idea dies. *You're not facing one attacker anymore, you're facing a market of them.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to follow cyber news but can't afford to be blindsided. First up: AECOM, a sixteen-billion-dollar engineering giant, is being claimed by two ransomware gangs in the same week. One lists 1.22 terabytes of stolen data. The other lists about 670 gigabytes. Same victim, side by side. More than 27,000 company email accounts are alleged to be floating around the dark web, and class-action lawyers filed before AECOM confirmed anything. For now, it all remains alleged. When a company this size gets picked over by two crews at once, budget and size aren't the shields many assumed they were. Then Randy takes CenterPoint Energy, the Houston utility serving about seven million customers across four states. A hacker walked off with 7.49 million customer records, including names, addresses, account numbers, and partial Social Security numbers. The wild part: there was no sophisticated break-in. The attacker simply counted upward through the ID numbers on CenterPoint's public website because nobody limited how many records it would return. Any business with a customer-facing app can have this exact hole. The lawsuits arrived before the company even disclosed the breach. Reginald closes with the number tying it all together. August 2026 was the worst month for ransomware ever recorded: 997 attacks, an all-time high averaging thirty-two a day. Business targets took the brunt, with law firms, tech companies, and finance firms rising fastest. Attacks on utilities doubled in a single month. Zoom out, and the picture gets worse: more than 7,500 victims over the past year, up nearly 25 percent, with over 60 brand-new gangs appearing. That's better than one a week. This flood of new crews is exactly why one victim now gets claimed by two of them. Here's the takeaway for owners: the boring basics still win. Turn on that second login code everywhere, quickly patch anything facing the internet, and keep backups you have actually tested. None of that requires a big budget. It stops the large majority of what we cover. • A Fortune 500 engineering firm gets claimed by two ransomware gangs in the same week • A utility leaks 7.5 million customer records through a wide-open public website • August 2026 becomes the worst month for ransomware ever recorded • Why you're now up against a whole market of attackers, not just one • The cheap, boring defenses that still stop most attacks • Why "we're too small to be a target" no longer holds up Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #AECOM #CenterPointEnergy #Ransomware #DataBreach #BusinessRisk #SmallBusiness #MSP #Utilities #Infosec #CyberRisk

  4. Sep 14

    Florida DMV Breached by a Stolen Police Login. 347K Trezor Users Phished

    A criminal crew broke into Florida's DMV database and proved it by leaking Jeffrey Epstein's driver record. They didn't hack the system. They used a police login stored on a personal device. If one stolen password can open a government database, what does that say about the logins running your business? Your security is only as strong as the login you handed someone else. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's cyber stories for executives, owners, and operators who can't afford to be blindsided. First, Florida. The state confirmed its DAVID driver database was breached after a crew called ShinyHunters used login credentials stolen from a single police officer. Those credentials were stored on the officer's personal device. The group claims it took more than 200,000 driver records. Full names, addresses, dates of birth, and license numbers can fuel identity theft and fraud for years. This wasn't a genius hack. It was one careless login. That's what should scare every business owner. Next, Trezor. The company makes hardware wallets designed to keep crypto offline and safe, yet 347,000 newsletter subscribers received a phishing email that sailed past every spam filter. It came through Trezor's own account after attackers breached Brevo, the marketing platform Trezor uses to send email. The message faked an urgent security alert to trick people into surrendering the secret backup that unlocks their crypto. BitBox and CoinTracking were hit through the same vendor. Trezor killed the fake link in about 20 minutes, but 2,500 people had already clicked. Your customers can be attacked through your brand even when everything you control is locked down. Finally, Interim HealthCare. The home-health provider operates across more than 40 states, and two separate ransomware gangs claimed they hit it this summer. Genesis said it took a full terabyte of medical records and patient data. Anubis claimed a separate haul of franchisee financials and internal audits. When the ransom went unpaid, the data was leaked anyway. Paying a criminal buys a promise, not your privacy back. If you run multiple locations, the attacker only needs your weakest one. In this episode, we discuss: • How a police login stored on a personal device opened Florida's DMV database to ShinyHunters. • How attackers phished 347,000 Trezor users by hijacking a trusted email vendor. • How two ransomware gangs hit Interim HealthCare and leaked the data despite the pressure. • Why your security is only as strong as the login you handed someone else. • What business owners should do about vendor access and stolen credentials before it's their turn. • Why paying a ransom is a promise from a criminal, not a recovery plan. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #DataBreach #Trezor #Ransomware #Phishing #VendorRisk #IdentityTheft #Healthcare #BusinessRisk #ShinyHunters #MSP

  5. Sep 8

    LA Metro Hit by Ransomware, 153M Licenses for Sale, AI Breaches a Network in 10 Hours

    LA Metro, the transit system that moves nearly 10 million people in Los Angeles, just appeared on a ransomware gang's extortion site. A dark-web service is selling 153 million scanned driver's licenses. And security researchers watched AI break into a company and steal the master keys in under 10 hours. Three stories, one uncomfortable pattern. *Cybercrime is now an industry, and speed is the whole game.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who can't follow every cyber headline but can't afford to be blindsided. First up: LA Metro. A fast-growing ransomware crew called The Gentlemen posted the country's second-busiest transit system to its leak site, claiming it stole internal data. Here's what most coverage skips: this is a claim on a leak site, not a confirmed breach. There's no ransom demand and no statement from the agency. Bryan explains how to read a scary headline without confusing an allegation for a fact. These crews choose targets based on how much disruption they can cause, and public infrastructure is squarely in their sights. If your business creates real-world chaos when it goes down, you fit the profile. Then Randy tackles the story that should worry every business that scans an ID. A service called Nexus appeared offering searchable access to more than 153 million driver's licenses from the US and Canada. Investigative reporter Brian Krebs traced the data to an identity-verification vendor called IDScan.net. The FBI's New Orleans office opened a case the same day, reportedly after finding IDs belonging to a US Defense Secretary and an FBI Assistant Director in the pile. The vendor runs 21 million ID checks a month for names like Hertz, Target, and FedEx, so a leak there becomes a problem for many other companies. If a business scanned your license, your photo and address may have passed through a vendor you never chose and can't see. Reginald closes with the story that connects everything. Palo Alto Networks' Unit 42 documented a real attack in which a person directed AI agents at a company and let them run the break-in. The agents mapped the network, raided passwords hidden in the company's own code, and grabbed the master credentials in under 10 hours. That work would take a human team about two weeks. One boring control stopped them cold: a basic protection on the code pipeline blocked the backdoor. The lesson for owners is blunt. The fundamentals still work, but your window to catch an attack is now hours, not days. In this episode, we discuss: • A ransomware gang claims LA Metro, and how to tell a claim from a confirmed breach • A dark-web service selling 153 million driver's licenses and the FBI probe into the vendor behind it • AI agents that breached a company and stole root access in under 10 hours • Why cybercrime now scales like a business, and why speed is the whole game • The internet-facing gear and hidden passwords attackers hit first • What to ask every vendor that touches your customers' data Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #LAMetro #DataBreach #FBI #ArtificialIntelligence #VendorRisk #BusinessRisk #SMB #IdentityTheft #MSP Security Squawk

  6. Aug 28

    Boston Scientific Frozen by Hackers, Microsoft Wipes 171,000 Nonprofits, ATF Ransomed

    Your business can be taken down in three completely different ways, and only one involves a hacker. This week, a cyberattack froze Boston Scientific, the company that ships pacemakers and defibrillators to hospitals worldwide. Microsoft ended a free program, and roughly 171,000 nonprofits lost everything in their cloud storage. And a ransomware gang breached a federal agency that kept running. *Control what a disaster can reach, before it reaches everything.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to follow cyber news but can't afford to be blindsided. Start with Boston Scientific. On August 25th, a cyberattack knocked out the systems this medical-device giant uses to process and ship orders worldwide, sending thousands of staff in Ireland home. The factories were never the problem. The systems that take and fulfill orders were, leaving hospitals waiting on pacemakers and stents. A group called ShinyHunters claims it stole more than 9 million records of personal data. Boston Scientific now faces two disasters: an outage it can fix and stolen data it cannot un-steal. Then there is Microsoft, where nobody got hacked. Microsoft ended a free software grant that about 400,000 nonprofits relied on. During the transition, roughly 171,000 of them lost everything in their OneDrive. One nonprofit leader had a paid renewal good through October 2026, and his data was deleted anyway. Here is what every owner needs to hear: Microsoft 365 does not back up your data. Microsoft keeps the service online, but protecting the actual files is entirely on you. Most people have that exactly backwards. We close with the ATF. The federal agency over firearms and explosives confirmed the Qilin ransomware gang hit a system holding information about the targets of its investigations, and the Department of Justice called it a "major incident." Yet the agency kept running because that sensitive system was deliberately walled off from everything else. One box got hit instead of the whole agency. Qilin is the most active ransomware brand of 2026, with victim counts up around 443 percent and North America accounting for more than half its targets. This is the playbook coming for businesses of every size. Three different villains. One lesson: you don't control when trouble arrives, only how far it gets once it does. In this episode, we discuss: • How a cyberattack froze Boston Scientific and stalled hospital device shipments worldwide • Why 171,000 nonprofits lost their data when Microsoft ended a grant, no hacker required • How the ATF survived a Qilin ransomware breach because one system was walled off • Why your cloud provider is not your backup, and what that means for your files • The one idea connecting all three: control what a disaster can reach before it reaches everything • Practical moves owners can make this week on backups, segmentation, and vendor notices Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #BostonScientific #Microsoft #Ransomware #DataBreach #Qilin #ShinyHunters #VendorRisk #BackupStrategy #BusinessRisk #MSP

  7. Aug 26

    AI Attacks US Water Plants, Apollo Beaten by a Phone Call, Kids' Hospital Breached Again

    Five federal agencies just warned that hackers are using AI to attack the computers running America's water plants and factories. That same week, a trillion-dollar investment firm was breached, not by a virus, but by a phone call. The hard part of hacking is disappearing. Every business owner needs to understand why. What used to keep attackers out is now what lets them in. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided. Start with the story that should stop you cold. The NSA, CISA, the FBI, the Department of Energy, and the EPA issued a rare joint warning: hackers are using AI to write code that attacks Siemens industrial controllers, the small computers that physically run water systems, power, and manufacturing. They took free, legitimate engineering tools and had AI turn them into custom attack software. The agencies say this dramatically cuts the skill and time an attack like this used to require. Difficulty was the wall that kept amateurs out of industrial systems. AI is tearing it down. And it is not theoretical. Security firm Dragos already documented a real intrusion where someone with no industrial background used commercial AI to go after a water utility's controls. The advisory names six sectors in the line of fire, from energy and water to food and manufacturing. These attacks are as weak as they will ever be, because the AI only gets better from here. Then Randy takes on Apollo Global Management, the Wall Street giant with about a trillion dollars under management. Attackers didn't break its technology. They called employees pretending to be internal IT, then guided them to fake login pages that captured their passwords and security codes. From there, they reached names, birth dates, home addresses, and Social Security numbers. This was not a lone hacker. Google ties it to a professionalized extortion crew that moves from one industry to the next running the same script, with demands that often start around three million dollars. A firm with a massive security budget was beaten by a convincing conversation, and a class-action lawsuit started forming within days. If a phone call works on Apollo, it can work on your team too. Reginald closes with SickKids, one of the most respected children's hospitals in the world. No patient records were touched. Employee and job-applicant data leaked through a flaw in third-party software the hospital didn't even build. Consider that last group: job applicants who handed over Social Security numbers to a place they did not even work yet. This repeat victim has now been burned by outside software three times, and it fits a bigger pattern: through the first half of 2026, vendors were involved in 43 percent of healthcare breaches. Another vendor breach this year hit 1.8 million people. Your biggest risk is often a company you'll never meet, inside a tool you already trust. • How hackers are using AI to attack the industrial controllers behind US water and power • Why Apollo Global Management got breached by a phone call, not a virus • How SickKids leaked employee and applicant data through a vendor's software • Why the skill it takes to attack a business is collapsing fast • What "verify who's really calling" actually looks like for your team • How to find the vendors quietly holding your most sensitive data • The one thread connecting all three: what used to keep attackers out now lets them in Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #AI #CriticalInfrastructure #Apollo #DataBreach #SocialEngineering #VendorRisk #SickKids #BusinessRisk #MSP #SmallBusiness

  8. Aug 17

    Delta Fake Wi-Fi, a Hospital's Hijacked Facebook, US Lets Firms Hack Back

    A fake Wi-Fi network at 35,000 feet turned a Delta flight into a crime scene. Someone on a flight out of Las Vegas set up a fake network to steal passengers' logins, a ransomware gang seized a hospital's Facebook page to post its ransom note, and a White House memo would let private firms hack foreign cybercriminals back for the first time in U.S. history. *Cybercrime is out in the open now, and so is the fight back.* Bryan Hornung, Randy Bryan, and Reginald Andre break down what it means for owners and operators who can't afford to be blindsided. On a Delta flight from Las Vegas to Atlanta, a passenger set up a fake network posing as the plane's Wi-Fi, and the crew pulled the real one offline. It's an "evil twin," a lookalike network that tricks you into connecting so an attacker can steal your logins. A man in Australia did exactly this on real flights and got more than seven years. A nonprofit hospital system, AnMed, got hit with malware and had to close nearly 80 facilities. Then a ransomware crew took over its verified Facebook page and posted the ransom demand in public. When criminals can post from your own account, they steal your megaphone, not just your data. For the first time ever, a White House memo would let vetted private firms strike foreign cybercriminals, with a million-dollar escrow and sign-offs from Justice and Homeland Security. But hacking back on your own is still a federal crime, and the rulebook is two months away. Support the show: buymeacoffee.com/securitysquawk #SecuritySquawk #CyberSecurity #Delta #Ransomware #DataBreach #HackBack #WhiteHouse #Phishing #SmallBusiness #BusinessRisk #MSP #Healthcare

Ratings & Reviews

5
out of 5
5 Ratings

About

Security Squawk is a business podcast dedicated to helping business people fight the war against cyber criminals.