Three incidents this month where the protection was in place, working exactly as designed, and still produced nothing. None of them required a clever exploit.
That is what these three incidents have in common, and why none of them tripped an alarm. A control that isn't running doesn't fail loudly — it just goes quiet. Here is the month in the only terms that matter: what actually happened, and how long it took anyone to notice.
Every figure on this page traces to a named source. Nothing here is an estimate.
Credential spraying against an internet-facing SonicWall SSL VPN found an account without MFA in about seven minutes. Two hours later the operator was on the domain controller. Files were archived with WinRAR and pushed to attacker-controlled cloud storage — all before any encryption began.
Then the operator added AnyDesk to the Windows Safe Boot registry key, forced a reboot into Safe Mode with Networking, and ran the ransomware there. Safe Mode loads only essential services, and third-party security products are excluded by design.
The EDR was installed, licensed, and correctly configured. It produced no telemetry because Windows never loaded it.
No SonicWall vulnerability was involved and no CVE was exploited. An account with a password and nothing else was enough. A server booting into Safe Mode without a change ticket is one of the cleanest alarms you can set.
A researcher owns noreply.net and noreply.us — addresses that look like throwaway placeholders but are real, registrable domains anyone can buy. One has taken in 401,796 messages since December 2024, roughly 700 a day, from more than 14,000 sending addresses across some 6,200 root domains. 28,365 of them carried attachments.
What arrives is ordinary business mail: account-setup messages, injury reports from a city government, meeting invitations from a government agency, credentials from test systems. A second researcher registered deleteduser.com for about fifteen dollars; three organizations emailed it within the first hour.
Nothing in email verifies that the domain in a From field belongs to the sender. Delivery succeeds, and no alert fires on either end.
For a practice, the exposure list is short and specific: practice management, your EHR, appointment reminders, the client portal, e-signature and intake tools. If any sends from a domain you don't own, every activation link and temporary password it has mailed went somewhere you can't see.
Texas Hearing Institute, a pediatric audiology provider, notified 29,744 patients after the Interlock ransomware group took files from its network. Interlock claims 540 GB, including names, Social Security numbers, diagnosis and treatment records, and financial account details. The ransom went unpaid, so the data was published.
The ransomware isn't the instructive part — the calendar is. Almost all of that time goes to answering one question: whose data was actually in those 540 GB. That answer is only as fast as your logging. If you can't show what was accessed and when, it has to be reconstructed from whatever evidence survived, and the clock runs the whole time.
HIPAA allows 60 days from discovery for breaches affecting 500 or more people, which also pulls in HHS's Office for Civil Rights. When “discovery” legally occurred is exactly the kind of question that gets argued afterward — a good reason not to be in a position to argue it.
Managed environments absorb this in the normal cycle. The machines worth worrying about are the unmanaged ones — the personal laptop used for remote work, the back-office workstation nobody replaced.
Read →It hijacks Chrome to steal session cookies alongside credentials. Stolen sessions matter because they arrive already authenticated — nobody gets prompted for a second factor.
Read →Carrying an affiliate-fraud payload. An extension reads every page the user opens — including your practice management system. Removal from the store isn't permanent.
Read →Full analysis on all three lives in the Threat Intelligence Center, updated daily.
Ten minutes, no IT help required, and it closes the one exposure on this list that you can verify yourself.
We implement the controls regulated firms need — managed firewalls, immutable backups, 24/7 monitoring, security awareness training — then maintain the quarterly evidence packages that examiners, insurers, and clients actually ask for.