1 / 8
Monthly Briefing · September 2026

Nobody got an alert.

Three incidents this month where the protection was in place, working exactly as designed, and still produced nothing. None of them required a clever exploit.

8 SLIDES~4 MIN READPREPARED FOR OHIO PROFESSIONAL FIRMS
Use → or swipe
The month in three numbers

Everything below was working correctly.


That is what these three incidents have in common, and why none of them tripped an alarm. A control that isn't running doesn't fail loudly — it just goes quiet. Here is the month in the only terms that matter: what actually happened, and how long it took anyone to notice.

7 min
From the first failed login to a successful one, against a VPN account with no MFA.
Akira · via Huntress
401,796
Messages delivered to a placeholder domain a researcher simply bought.
noreply.net · since Dec 2024
98 days
Between spotting an intrusion and finishing patient notification.
Mar 20 → Jun 26, 2026

Every figure on this page traces to a named source. Nothing here is an estimate.

Adlumin monitoring dashboard showing identity and compliance detections
Layered monitoring is what still sees a host when its endpoint agent never starts.
Lead story · Ransomware

The server rebooted, and the endpoint protection never came back.


Credential spraying against an internet-facing SonicWall SSL VPN found an account without MFA in about seven minutes. Two hours later the operator was on the domain controller. Files were archived with WinRAR and pushed to attacker-controlled cloud storage — all before any encryption began.

Then the operator added AnyDesk to the Windows Safe Boot registry key, forced a reboot into Safe Mode with Networking, and ran the ransomware there. Safe Mode loads only essential services, and third-party security products are excluded by design.

Key insight

The EDR was installed, licensed, and correctly configured. It produced no telemetry because Windows never loaded it.

No SonicWall vulnerability was involved and no CVE was exploited. An account with a password and nothing else was enough. A server booting into Safe Mode without a change ticket is one of the cleanest alarms you can set.

Read the full attack chain →

Lead story · Data exposure

The “no reply” address in your software may belong to a stranger.


A researcher owns noreply.net and noreply.us — addresses that look like throwaway placeholders but are real, registrable domains anyone can buy. One has taken in 401,796 messages since December 2024, roughly 700 a day, from more than 14,000 sending addresses across some 6,200 root domains. 28,365 of them carried attachments.

What arrives is ordinary business mail: account-setup messages, injury reports from a city government, meeting invitations from a government agency, credentials from test systems. A second researcher registered deleteduser.com for about fifteen dollars; three organizations emailed it within the first hour.

Key insight

Nothing in email verifies that the domain in a From field belongs to the sender. Delivery succeeds, and no alert fires on either end.

For a practice, the exposure list is short and specific: practice management, your EHR, appointment reminders, the client portal, e-signature and intake tools. If any sends from a domain you don't own, every activation link and temporary password it has mailed went somewhere you can't see.

Read the analysis and checklist →

A closed binder on a boardroom table in late afternoon light
Sender-domain ownership is the kind of detail that only surfaces in an audit — or a breach.
Lead story · Healthcare / HIPAA

Three months between finding it and telling anyone.


Texas Hearing Institute, a pediatric audiology provider, notified 29,744 patients after the Interlock ransomware group took files from its network. Interlock claims 540 GB, including names, Social Security numbers, diagnosis and treatment records, and financial account details. The ransom went unpaid, so the data was published.

Mar 20
Suspicious network activity spotted
Apr 22
Forensics confirm the scope
Jun 19
Affected-individual list finalized
Jun 26
Notification letters sent
98 days between “something is wrong on our network” and patients learning their records were involved.

The ransomware isn't the instructive part — the calendar is. Almost all of that time goes to answering one question: whose data was actually in those 540 GB. That answer is only as fast as your logging. If you can't show what was accessed and when, it has to be reconstructed from whatever evidence survived, and the clock runs the whole time.

HIPAA allows 60 days from discovery for breaches affecting 500 or more people, which also pulls in HHS's Office for Civil Rights. When “discovery” legally occurred is exactly the kind of question that gets argued afterward — a good reason not to be in a position to argue it.

Read the full breakdown →

One thing to do this month

Check who actually owns your “no reply” domain.

Ten minutes, no IT help required, and it closes the one exposure on this list that you can verify yourself.

  1. Open the last automated email one of your systems sent a patient or client — an appointment reminder, a portal invitation, a signature request.
  2. Look at the From and Reply-To addresses. You are checking one thing: is the domain after the @ one your firm owns?
  3. [email protected] is exactly right. noreply.net, or any domain that isn't yours, means that mail has been going to whoever owns it.
  4. Repeat for each system that emails your clients. If you find one, rotate anything it has ever mailed — treat those credentials as public.
Have us check it for you Read the full briefing

Evidence, not assurances.

We implement the controls regulated firms need — managed firewalls, immutable backups, 24/7 monitoring, security awareness training — then maintain the quarterly evidence packages that examiners, insurers, and clients actually ask for.

Brian Sammons
Brian Sammons · Founder Managing IT for Ohio professional service firms — medical, dental, legal, accounting, and financial — since 2002. Questions about how any of this affects your environment? Reply to this email, or grab fifteen minutes on my calendar.
Capstone Technologies Group · 2071 N Bechtle Ave, Box 143 · Springfield, OH 45504-1583
captechgroup.com · (937) 319-1211 · Threat Intelligence Center
You're receiving this because you asked for the Capstone Monthly Briefing.