Security
Ransomware Groups Are Calling Your Employees Now.
August 4, 2026 · Brock Griffin · 5 min read
July 2026 was a busy month for ransomware. Two competing criminal groups, Qilin and The Gentlemen, each claimed nearly 300 victims in a single quarter. A ransomware crew called Anubis shut down Coca-Cola dairy production at Fairlife. And ShinyHunters breached Abbott Laboratories by doing something remarkably low-tech: they called an employee on the phone.
What Is Happening
Voice phishing, also called vishing, has become one of the most reliable ways attackers get into a network. The playbook is straightforward. An attacker calls a company employee, often someone in IT support or finance, and impersonates a colleague, a vendor, or a help desk technician. The goal is to talk the employee into resetting credentials, approving an MFA push, or handing over access to a company account.
In the Abbott case, ShinyHunters used this exact method to compromise a Microsoft Entra single sign-on account tied to Abbott's Cancer Diagnostics business. Once inside, the group threatened to publish stolen data unless a ransom was paid.
AI is making these calls harder to spot. Voice cloning tools can produce a convincing replica of someone's voice from just a few seconds of audio. Attackers are already using deepfake audio to impersonate executives and IT staff over the phone and on platforms like Microsoft Teams. According to a 2026 threat intelligence report, deepfake audio in vishing attacks is a rising threat specifically targeting workplace collaboration tools.
Ransomware itself has also changed. Many crews no longer bother encrypting files. They steal the data, then threaten to publish it unless you pay. Your first sign that something went wrong may be the extortion demand itself, not a locked screen or a ransom note.
Why This Matters to Your Business
You do not have to be Abbott Laboratories to get targeted. U.S.-based small and mid-sized businesses continue to absorb the largest share of ransomware incidents. Attackers go after smaller organizations precisely because they tend to have fewer controls in place and less trained staff to recognize a social engineering call.
The financial stakes are real. SMB cyber incidents now cost businesses an average of $120,000 to over $1 million per attack. Forty percent of small businesses say an attack costing $100,000 or less could put them out of business entirely. And breach costs do not stop in year one. Nearly a quarter of the total financial impact from a breach persists beyond two years.
Here is the part that should get your attention as a business owner. Most of the organizations hit in July were not breached because their firewall failed. They were breached because a person answered a phone call and believed what they heard. Technical controls matter, but a single convincing phone call can render many of them irrelevant if your team does not know how to respond.
What You Should Do Right Now
Train your team on voice phishing specifically. General security awareness training is a starting point, but your employees need to know that a phone call or a Teams message is just as dangerous as a suspicious email. Teach them to verify identity through a separate, known channel before taking any action that involves credentials, money, or access. If someone calls claiming to be IT, hang up and call IT back on a number you already have.
Require phishing-resistant MFA on every account you can. Standard push-notification MFA can be bypassed by a determined attacker who talks an employee into approving a prompt. Move toward FIDO2 hardware keys or number-matching MFA wherever your software supports it. At minimum, enforce MFA on email, cloud apps, banking tools, and all admin accounts.
Lock down your Microsoft 365 environment. The phishing kits active in July 2026 were overwhelmingly targeting Microsoft 365 identities through OAuth device-code flow abuse. Review your tenant's conditional access policies. Restrict which applications can request OAuth tokens. Enable external sender banners so staff can see when an email originates outside your organization.
Apply the principle of least privilege. Standard users should not have local admin rights on their machines. Admin accounts should be separate from daily-use accounts. Service accounts should not share passwords. Limit what an attacker can reach if they do get in through one compromised account.
Test and verify your backups. Many crews now identify and delete backup sets before triggering their extortion. Your backups need an offline or immutable copy that your domain admin account cannot touch directly. Test restoration regularly. A backup you have never tested is not a backup.
Have a written incident response plan. Know who calls whom, in what order, when something goes wrong. Include your IT provider, your cyber insurance carrier's breach coach, and a legal contact. Practice the plan at least once a year. Companies that rehearse their response contain incidents faster and spend less recovering from them.
The Takeaway
The ransomware threat in summer 2026 is not coming through a single dramatic exploit. It is coming through a phone call to one of your employees, a stolen credential, or a poorly configured cloud account. The good news is that the defenses against this are not exotic. They are consistent training, strong identity controls, tested backups, and a plan for when things go wrong. Prevention costs a fraction of recovery. The gap between a secure business and a breached one is almost always a matter of preparation, not budget.
If you are not sure where your business stands, Gryphon Tech Advisors can help. We work with small and mid-sized businesses in the Plymouth area to close the gaps before attackers find them. Reach out to our team at Gryphon Tech Advisors for a straightforward conversation about your current security posture and what practical next steps look like for your organization.