<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Incognito CyberSecurity</title>
	<atom:link href="https://incognitocybersecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://incognitocybersecurity.com</link>
	<description></description>
	<lastBuildDate>Mon, 14 Sep 2026 14:17:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://incognitocybersecurity.com/wp-content/uploads/2025/01/favicon-150x150.png</url>
	<title>Incognito CyberSecurity</title>
	<link>https://incognitocybersecurity.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>El Celular Personal de un Empleado Acaba de Abrir una Brecha en una Agencia Estatal</title>
		<link>https://incognitocybersecurity.com/blog/dispositivos-personales-accesos-trabajo/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dispositivos-personales-accesos-trabajo</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 14:15:34 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/dispositivos-personales-accesos-trabajo/</guid>

					<description><![CDATA[<p>Un acceso de trabajo robado del celular personal de un empleado provocó una brecha estatal. Así encuentras la misma falla en tu negocio esta semana.</p>
The post <a href="https://incognitocybersecurity.com/blog/dispositivos-personales-accesos-trabajo/">El Celular Personal de un Empleado Acaba de Abrir una Brecha en una Agencia Estatal</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>El Celular Personal de un Empleado Acaba de Abrir una Brecha en una Agencia Estatal</h1>
<p style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/personal-devices-work-logins/" style="font-size:15px;color:#0F1E34;text-decoration:underline;">&#127482;&#127480; Read this article in English</a></p>
<p>El jueves pasado, el Departamento de Seguridad Vial y Vehículos Motorizados de Florida confirmó algo que vale la pena que cualquier dueño de negocio piense con calma. Un grupo criminal entró a los registros vehiculares del estado. No con un exploit sofisticado. No con nada de película. Entraron porque <strong>un policía tenía su acceso de trabajo guardado en su dispositivo personal</strong>, y alguien se lo robó.</p>
<p>Una persona. Un celular. Una contraseña en el lugar equivocado. Esa fue toda la historia.</p>
<p>Llevo en esto en Tucson desde 2011, y puedo decirte que casi todos los negocios pequeños que visito tienen el mismo problema. No porque alguien sea descuidado. Porque es cómodo, y nadie les dijo que no lo hicieran.</p>
<h2>Qué pasó realmente en Florida</h2>
<p>Las autoridades se enteraron de la brecha el 4 de septiembre. Su investigación determinó que un criminal pudo aprovechar las credenciales de un solo usuario de un departamento de policía que estaban &#8220;guardadas indebidamente en el dispositivo electrónico personal del empleado&#8221;. Ese empleado trabajaba para un departamento de policía de un pueblo pequeño a las afueras de Tampa. Lo que salió por el otro lado fueron registros vehiculares de todo el estado.</p>
<p>Lee esa cadena otra vez, porque ahí está lo importante. El empleado de una organización pequeña. Un dispositivo personal. Un sistema compartido. El atacante no necesitó vulnerar al estado. Solo necesitó vulnerar al eslabón más débil conectado a él.</p>
<p>Si eres contratista, despacho contable, clínica o compañía de títulos con un acceso a un portal de alguien más grande, <strong>tú eres el departamento de policía del pueblo pequeño en esa historia</strong>.</p>
<h2>Por qué esto debería preocuparte más a ti que a Florida</h2>
<h3>El dispositivo no es el problema. Lo que está guardado en él, sí.</h3>
<p>Nadie está diciendo que tu equipo no pueda usar sus propios celulares. La mayoría de los negocios pequeños no funcionarían de otra forma. El problema es lo que se va acumulando en esos teléfonos: la contraseña de QuickBooks en la app de notas, el acceso al banco guardado en un perfil personal de Chrome, la contraseña del portal del cliente en un mensaje de texto con la gerente de la oficina.</p>
<p>Eso es propiedad del negocio viviendo en equipo que no es tuyo, que no puedes borrar y que nunca vas a recuperar cuando esa persona se vaya. Escribimos sobre la parte del navegador en <a href="https://incognitocybersecurity.com/blog/contrasenas-guardadas-navegador/">Contraseñas Guardadas: La Puerta Más Fácil a tu Negocio</a>, y esta es la misma enfermedad con otra dirección.</p>
<h3>Los atacantes ahora se mueven en horas, no en semanas</h3>
<p>Aquí está lo que cambió hace poco. En un reporte de amenazas publicado el mismo día que la confirmación de Florida, Anthropic describió atacantes que usan herramientas de inteligencia artificial para buscar credenciales robadas, mapear sistemas que nunca habían visto y extraer datos. En un caso, un atacante pasó de un solo token de desarrollador robado a control administrativo total del entorno en la nube de la víctima <strong>en unas tres horas</strong>.</p>
<p>Tres horas. Eso es menos que una comida de trabajo. La vieja idea de que ibas a notar que algo andaba mal antes de que hubiera daño real ya no es una suposición segura.</p>
<h2>Dónde terminan los accesos de trabajo sin que te des cuenta</h2>
<p>Cuando hago un recorrido con un cliente nuevo, encuentro los mismos cuatro escondites casi siempre:</p>
<ul>
<li>La app de notas del celular personal, casi siempre titulada &#8220;contraseñas&#8221; o &#8220;trabajo&#8221;</li>
<li>Una cuenta personal de Google o Apple conectada a un navegador de trabajo, sincronizando todo a la laptop de la casa</li>
<li>Un mensaje de texto o WhatsApp donde alguien mandó una contraseña una vez y nadie la borró</li>
<li>Un correo personal que guarda ligas para restablecer contraseñas y códigos de respaldo de MFA</li>
</ul>
<p>Nada de eso es malintencionado. Todo eso es una brecha esperando a que se pierda un teléfono.</p>
<p><img fetchpriority="high" fetchpriority="high" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-dispositivos-personales-3-pasos-es.png" alt="Infografía con tres tarjetas: separa los accesos, activa MFA en todo y sabe quién tiene acceso, de Incognito Cyber Security." width="1200" height="640" style="max-width:100%;height:auto;display:block;margin:32px auto;border-radius:8px;" /></p>
<h2>Qué puedes hacer esta semana</h2>
<ol>
<li><strong>Haz la pregunta en voz alta.</strong> En tu próxima junta con el personal, pregunta dónde guardan sus contraseñas de trabajo. No lo conviertas en un regaño. Conviértelo en una investigación. Vas a aprender más en cinco minutos que con cualquier auditoría.</li>
<li><strong>Dales un lugar mejor.</strong> Nadie guarda contraseñas en la app de notas porque le encante. Lo hace porque no hay alternativa. Pon un gestor de contraseñas empresarial y la app de notas se vacía sola.</li>
<li><strong>Activa la autenticación multifactor en todo lo que se pueda.</strong> Correo, banco, contabilidad, acceso remoto. Una contraseña robada vale muy poco si todavía necesita un segundo factor. Eso sí, asegúrate de que tu gente sepa no aprobar avisos que no inició, algo que vimos en <a href="https://incognitocybersecurity.com/blog/fatiga-mfa-solicitud-acceso/">La Solicitud de Acceso que Nunca Debes Aprobar</a>.</li>
<li><strong>Separa la identidad de trabajo de la personal.</strong> Las cuentas de trabajo entran con perfiles de trabajo. Las cuentas personales de Google y Apple se quedan fuera de los navegadores de trabajo, y al revés también.</li>
<li><strong>Anota quién tiene acceso a qué.</strong> Cada sistema, cada persona, cada dispositivo. Si un nombre de esa lista se fue hace seis meses, ya encontraste tu primer arreglo.</li>
<li><strong>Confirma que tus respaldos de verdad restauran.</strong> El robo de credenciales normalmente es el paso uno. Los <a href="https://incognitocybersecurity.com/secure-data-backups/">respaldos probados</a> son los que deciden si el paso dos es una molestia o el fin del negocio.</li>
</ol>
<p>Si a tu personal nunca le explicaron esto con claridad, eso es una falta de capacitación, no un problema de personas. La <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">capacitación en concientización de seguridad</a> es la línea más barata de toda esta lista.</p>
<h2>En resumen</h2>
<p>Una agencia estatal sufrió una brecha porque un empleado de un departamento pequeño guardó un acceso de trabajo en un lugar cómodo. Tu negocio funciona con el mismo arreglo ahora mismo, y probablemente hace rato que no lo revisas.</p>
<p>No necesitas más presupuesto para arreglar esto. Necesitas <a href="https://incognitocybersecurity.com/end-point-protection/">dispositivos administrados</a>, <a href="https://incognitocybersecurity.com/spam-virus-filtering/">correo filtrado</a>, un gestor de contraseñas, MFA activado y una conversación honesta con tu equipo. Es una semana de trabajo que elimina, sin ruido, la forma más común en que le pegan a los negocios pequeños.</p>
<div style="background:#0F1E34;border:1px solid #22D3EE;border-radius:8px;padding:28px;margin:36px 0;">
<p style="color:#22D3EE;font-weight:700;text-transform:uppercase;letter-spacing:1px;font-size:13px;margin:0 0 10px;">¿No sabes qué hay en los celulares de tu equipo?</p>
<p style="color:#E2E8F0;margin:0 0 18px;">Recorremos tu negocio, encontramos dónde están viviendo realmente las credenciales de trabajo y te damos una lista en lenguaje sencillo de qué arreglar primero. Sin tecnicismos y sin presión.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="background:#22D3EE;color:#0F1E34;font-weight:700;padding:13px 26px;border-radius:6px;text-decoration:none;display:inline-block;">Agenda una visita sin costo</a></p>
</div>
<p>Atendemos a pequeñas empresas en Tucson, Marana, Oro Valley, Sahuarita y Nogales con <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">TI administrada y ciberseguridad</a> y soporte de emergencia 24/7. Hay más explicaciones en lenguaje sencillo como esta en <a href="https://incognitocybersecurity.com/blog/">nuestro blog</a>.</p>
<h2>Envíanos un mensaje</h2>
<p>¿Tienes una duda sobre tu propia configuración? Mándala y yo mismo te respondo.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_50_container">
			<label for="field_z00wq" >
				If you are human, leave this field blank.			</label>
			<input  id="field_z00wq" type="text" class="frm_form_field form-field frm_verify" name="item_meta[50]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCSoTYdhsfuxhK6c/xjOTt2bJIrTpl/AML1hykTOMQsFL" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="color:#F59E0B;text-transform:uppercase;letter-spacing:1px;font-size:12px;font-weight:700;margin:0 0 8px;">Sobre el autor</p>
<p style="color:#0F1E34;font-size:19px;font-weight:700;margin:0 0 12px;">Nemuel Cruz</p>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="color:#334155;margin:0;font-size:15px;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/dispositivos-personales-accesos-trabajo/">El Celular Personal de un Empleado Acaba de Abrir una Brecha en una Agencia Estatal</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>One Employee&#8217;s Personal Phone Just Breached a State Agency</title>
		<link>https://incognitocybersecurity.com/blog/personal-devices-work-logins/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=personal-devices-work-logins</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 14:14:23 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/personal-devices-work-logins/</guid>

					<description><![CDATA[<p>A stolen work login on one employee's personal phone led to a state motor vehicle data breach. Here is how to find the same gap in your business this week.</p>
The post <a href="https://incognitocybersecurity.com/blog/personal-devices-work-logins/">One Employee’s Personal Phone Just Breached a State Agency</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>One Employee&#8217;s Personal Phone Just Breached a State Agency</h1>
<p class="ics-lang-switch" style="margin:18px 0 28px;"><a href="https://incognitocybersecurity.com/blog/dispositivos-personales-accesos-trabajo/" style="background:#22D3EE;color:#0F1E34;font-weight:700;padding:11px 22px;border-radius:6px;text-decoration:none;display:inline-block;">&#127474;&#127485; Leer en Español &rarr;</a></p>
<p>Last Thursday, the Florida Department of Highway Safety and Motor Vehicles confirmed something a lot of small business owners should sit with for a minute. A cybercrime group got into state motor vehicle records. Not through a zero-day. Not through some Hollywood hack. They got in because <strong>one police officer had his work login sitting on his personal device</strong>, and somebody stole it.</p>
<p>One person. One phone. One set of credentials in the wrong place. That was the whole story.</p>
<p>I have been doing this in Tucson since 2011, and I can tell you that almost every small business I walk into has the same problem. Not because anybody is careless. Because it is convenient, and nobody ever told them not to.</p>
<h2>What actually happened in Florida</h2>
<p>Officials found out about the breach on September 4. Their investigation determined that a criminal was able to take advantage of a single police department user&#8217;s credentials that were &#8220;improperly housed on the employee&#8217;s personal electronic device.&#8221; That employee worked for a small-town police department outside Tampa. The data that came out the other end was state-level motor vehicle records.</p>
<p>Read that chain again, because it is the part that matters. A small organization&#8217;s employee. A personal device. A shared system. The attacker did not need to breach the state. They only needed to breach the weakest person connected to it.</p>
<p>If you are a contractor, a CPA firm, a clinic, or a title company with a portal login into somebody bigger, <strong>you are the small-town police department in that story</strong>.</p>
<h2>Why this should worry you more than it worries Florida</h2>
<h3>The device is not the problem. What is stored on it is.</h3>
<p>Nobody is saying your team cannot use their own phones. Most small businesses could not function otherwise. The problem is what quietly accumulates on those phones: the QuickBooks password in a notes app, the bank login saved in a personal Chrome profile, the client portal password in a text thread with the office manager.</p>
<p>That is business property living on hardware you do not own, cannot wipe, and will never get back when that person leaves. We wrote about the browser side of this in <a href="https://incognitocybersecurity.com/blog/saved-passwords-browser-security/">Saved Passwords: The Easiest Way Into Your Business</a>, and this is the same disease with a different address.</p>
<h3>Attackers now move in hours, not weeks</h3>
<p>Here is the part that changed recently. In a threat report published the same day as the Florida confirmation, Anthropic described attackers using AI tools to scan for stolen credentials, map systems they had never seen before, and pull data out. In one case an attacker went from a single stolen developer token to full administrative control of a victim&#8217;s cloud environment <strong>in about three hours</strong>.</p>
<p>Three hours. That is shorter than a lunch meeting. The old assumption that you would notice something was wrong before real damage happened is no longer a safe assumption.</p>
<h2>Where work logins quietly end up</h2>
<p>When I do a walkthrough for a new client, I find the same four hiding places almost every time:</p>
<ul>
<li>The notes app on a personal phone, usually titled &#8220;passwords&#8221; or &#8220;work stuff&#8221;</li>
<li>A personal Google or Apple account signed into a work browser, syncing everything to a home laptop</li>
<li>A text or WhatsApp thread where somebody sent a credential once and nobody ever deleted it</li>
<li>A personal email inbox holding password reset links and MFA backup codes</li>
</ul>
<p>None of that is malicious. All of it is a breach waiting for a lost phone.</p>
<p><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-personal-devices-3-steps-en.png" alt="Infographic with three cards: separate the logins, turn on MFA everywhere, and know who has access, from Incognito Cyber Security." width="1200" height="640" style="max-width:100%;height:auto;display:block;margin:32px auto;border-radius:8px;" /></p>
<h2>What you can do this week</h2>
<ol>
<li><strong>Ask the question out loud.</strong> In your next staff meeting, ask where people keep their work passwords. Do not make it a scolding. Make it a fact-finding mission. You will learn more in five minutes than from any audit.</li>
<li><strong>Give them somewhere better.</strong> Nobody keeps passwords in a notes app because they love it. They do it because there is no alternative. Put a business password manager in place and the notes app empties out on its own.</li>
<li><strong>Turn on multi-factor authentication everywhere it will go.</strong> Email, banking, accounting, remote access. A stolen password is worth very little if it still needs a second factor. Just make sure your people know not to approve prompts they did not trigger, which we covered in <a href="https://incognitocybersecurity.com/blog/mfa-fatigue-login-request/">The Login Request You Should Never Approve</a>.</li>
<li><strong>Separate work identity from personal identity.</strong> Work accounts sign in with work profiles. Personal Google and Apple accounts stay off work browsers, and vice versa.</li>
<li><strong>Write down who has access to what.</strong> Every system, every person, every device. If a name on that list left six months ago, you found your first fix.</li>
<li><strong>Confirm your backups actually restore.</strong> Credential theft is usually step one. <a href="https://incognitocybersecurity.com/secure-data-backups/">Tested backups</a> are what decide whether step two is an inconvenience or an extinction event.</li>
</ol>
<p>If your staff has never had this explained to them plainly, that is a training gap, not a people problem. <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">Security awareness training</a> is the cheapest line item on this whole list.</p>
<h2>The bottom line</h2>
<p>A state agency got breached because one employee at one small department kept a work login somewhere convenient. Your business runs on the same arrangement right now, and you probably have not looked in a while.</p>
<p>You do not need a bigger budget to fix this. You need <a href="https://incognitocybersecurity.com/end-point-protection/">managed devices</a>, <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtered email</a>, a password manager, MFA turned on, and one honest conversation with your team. That is a week of work that quietly removes the most common way small businesses get hit.</p>
<div style="background:#0F1E34;border:1px solid #22D3EE;border-radius:8px;padding:28px;margin:36px 0;">
<p style="color:#22D3EE;font-weight:700;text-transform:uppercase;letter-spacing:1px;font-size:13px;margin:0 0 10px;">Not sure what is on your team&#8217;s phones?</p>
<p style="color:#E2E8F0;margin:0 0 18px;">We will walk your business, find where work credentials are actually living, and give you a plain-English list of what to fix first. No jargon, no pressure.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="background:#22D3EE;color:#0F1E34;font-weight:700;padding:13px 26px;border-radius:6px;text-decoration:none;display:inline-block;">Book a complimentary visit</a></p>
</div>
<p>We serve small businesses across Tucson, Marana, Oro Valley, Sahuarita and Nogales with <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">managed IT and cybersecurity</a> and 24/7 emergency support. More plain-English breakdowns like this one are on <a href="https://incognitocybersecurity.com/blog/">our blog</a>.</p>
<h2>Send us a message</h2>
<p>Have a question about your own setup? Send it over and I will answer it personally.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_51_container">
			<label for="field_6wz5v" >
				If you are human, leave this field blank.			</label>
			<input  id="field_6wz5v" type="text" class="frm_form_field form-field frm_verify" name="item_meta[51]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCd6a2ZPpoC1pDkJbhOS8xrBzPHcmAk8SCMfQ0rXqUUSa" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="color:#F59E0B;text-transform:uppercase;letter-spacing:1px;font-size:12px;font-weight:700;margin:0 0 8px;">About the author</p>
<p style="color:#0F1E34;font-size:19px;font-weight:700;margin:0 0 12px;">Nemuel Cruz</p>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="color:#334155;margin:0;font-size:15px;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/personal-devices-work-logins/">One Employee’s Personal Phone Just Breached a State Agency</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>¿Quién Más Puede Ver Tus Archivos? El Error al Compartir en la Nube</title>
		<link>https://incognitocybersecurity.com/blog/quien-mas-puede-ver-tus-archivos-nube/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=quien-mas-puede-ver-tus-archivos-nube</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 14:11:32 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/quien-mas-puede-ver-tus-archivos-nube/</guid>

					<description><![CDATA[<p>La mayoría de las fugas de datos en pequeñas empresas no empiezan con un hacker. Empiezan con un enlace compartido que nadie apagó.</p>
The post <a href="https://incognitocybersecurity.com/blog/quien-mas-puede-ver-tus-archivos-nube/">¿Quién Más Puede Ver Tus Archivos? El Error al Compartir en la Nube</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>¿Quién Más Puede Ver Tus Archivos? El Error al Compartir en la Nube que Casi Todos Cometen</h1>
<p style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/who-else-can-see-your-files-cloud-sharing/">🇺🇸 Read this article in English</a></p>
<p>La mayoría de los dueños con los que hablo imaginan un robo cuando piensan en una fuga de datos. Alguien con capucha, adivinando contraseñas, entrando a la fuerza. Esa es la versión de película. La versión que yo veo en el sur de Arizona es mucho más silenciosa y bastante más vergüenza: nadie entró a la fuerza. Un archivo se compartió con &#8220;cualquiera que tenga el enlace&#8221; hace tres años, y ahí sigue, abierto en internet.</p>
<p>Una investigación publicada este mes lo explica mejor que yo. Una firma de seguridad revisó datos de configuración en la nube de 3,000 organizaciones que usan las plataformas de Amazon, Microsoft y Google. Los controles de acceso débiles aparecieron en entre el 80% y el 98% de las cuentas, según el proveedor. No hablamos de unas cuantas empresas descuidadas. Hablamos de casi todas.</p>
<h2>El problema no son los hackers. Son las configuraciones.</h2>
<p>&#8220;Mala configuración&#8221; es una palabra técnica para algo muy común: un interruptor que se activó por comodidad y nunca se volvió a apagar. Tu equipo necesitaba enviar una propuesta grande a un cliente, entonces alguien activó el acceso público. Funcionó. Todos siguieron con su día. El interruptor se quedó encendido.</p>
<p>Esto importa más que antes porque los criminales dejaron de adivinar contraseñas y empezaron a buscar puertas abiertas. Sale más barato rastrear internet en busca de archivos expuestos que atacar a una empresa de frente. Si tus cotizaciones, tu nómina o tus contratos se pueden abrir sin iniciar sesión, nunca vas a recibir una alerta. No hay alarma para una puerta que tú dejaste abierta a propósito.</p>
<h2>Tres formas en que se filtran archivos sin que nadie entre por la fuerza</h2>
<h3>El enlace que nunca expira</h3>
<p>En Microsoft 365, Google Drive y Dropbox, la forma más rápida de compartir algo es un enlace público. Es un solo clic, y por defecto ese enlace casi nunca tiene fecha de vencimiento. El proyecto termina, la relación con el cliente termina, el empleado que lo creó se va — y el enlace sigue funcionando.</p>
<h3>La cuenta que sobrevivió al empleado</h3>
<p>Cuando alguien se va, casi todas las pequeñas empresas se acuerdan de apagar el correo. Muchas menos se acuerdan de la carpeta compartida, del portal de contabilidad, de la aplicación de sincronización que sigue instalada en una laptop personal. He auditado negocios donde una persona que se fue hace dos años todavía podía abrir la carpeta financiera de la empresa desde su casa.</p>
<h3>Todos son administradores</h3>
<p>Esta casi siempre es accidental. Es más rápido darle acceso total a un empleado nuevo que averiguar qué necesita en realidad. Multiplica eso por cinco años de contrataciones, y ahora una sola contraseña robada abre todos tus archivos en lugar de una sola carpeta.</p>
<p><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-cloud-sharing-es-infographic.png" alt="Infografía con tres tarjetas: enlaces que nunca expiran, cuentas que siguen activas y permisos de administrador de más." width="1200" height="640" class="aligncenter size-full" /></p>
<h2>Por qué vale una hora de tu semana</h2>
<p>Los grupos de ransomware cambiaron su modelo de negocio. Antes sólo bloqueaban tus archivos y pedían dinero. Ahora primero copian tus datos, luego los bloquean, y después amenazan con publicar lo que se llevaron. Un buen respaldo te devuelve la operación — y deberías tener <a href="https://incognitocybersecurity.com/secure-data-backups/">respaldos probados y fuera del sitio</a> — pero un respaldo no &#8220;despublica&#8221; tu lista de clientes.</p>
<p>Eso cambia las cuentas. Una carpeta filtrada no es sólo un dolor de cabeza técnico. Es una llamada a cada cliente que esté en esa carpeta. Y rara vez empieza con algo dramático: en la mayoría de estos casos los atacantes simplemente usaron credenciales que ya estaban expuestas. Es el mismo patrón del que escribí cuando <a href="https://incognitocybersecurity.com/blog/brecha-de-proveedor-tus-datos/">la brecha de un proveedor puso en riesgo los datos de sus clientes</a> — el punto débil fue un acceso que nadie estaba vigilando.</p>
<h2>Qué puedes hacer esta semana</h2>
<ol>
<li><strong>Saca tu reporte de archivos compartidos.</strong> Tanto Microsoft 365 como Google Workspace permiten que un administrador liste cada archivo compartido públicamente. Córrelo una vez. A la mayoría de los dueños les sorprende lo que aparece.</li>
<li><strong>Elimina los enlaces públicos que ya no necesitas.</strong> Todo lo que sea más viejo que un proyecto terminado debería cambiar a &#8220;sólo personas específicas&#8221;. Configura los enlaces nuevos para que expiren en 30 días.</li>
<li><strong>Escribe una lista de salida de cinco líneas.</strong> Correo, carpeta compartida, software de contabilidad, gestor de contraseñas, equipo de la empresa devuelto. Cinco líneas le ganan a una política perfecta que nadie sigue.</li>
<li><strong>Cuenta tus administradores.</strong> Un negocio con diez empleados no necesita seis administradores. Necesita dos, y los demás reciben sólo lo que su trabajo requiere.</li>
<li><strong>Dedica quince minutos a tu equipo.</strong> Muéstrales la diferencia entre &#8220;compartir con María&#8221; y &#8220;compartir con cualquiera&#8221;. Una <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">capacitación corta en concientización de seguridad</a> previene más fugas que cualquier producto que yo te pueda vender.</li>
</ol>
<h2>En resumen</h2>
<p>No necesitas un presupuesto de seguridad más grande para arreglar esto. Necesitas una tarde y a alguien dispuesto a revisar. Los negocios que salen lastimados no son los que tienen tecnología débil — son aquellos donde nadie revisó nunca quién sigue teniendo las llaves. Suma <a href="https://incognitocybersecurity.com/end-point-protection/">protección de dispositivos</a> y <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtrado de correo</a> encima de permisos limpios, y habrás cerrado las puertas que los atacantes sí usan.</p>
<p>Si prefieres no andar buscando entre menús de administrador, se entiende. Para eso estamos. Hay más guías en lenguaje sencillo en <a href="https://incognitocybersecurity.com/blog/">nuestro blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:26px 28px;margin:36px 0;color:#E2E8F0;">
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#ffffff;">¿No sabes quién puede ver tus archivos?</p>
<p style="margin:0 0 16px;color:#9FB3C8;">Revisamos tu configuración de archivos compartidos, tus cuentas de usuario y tus permisos de administrador, y te entregamos una lista en lenguaje sencillo de lo que hay que arreglar. Sin tecnicismos y sin presión.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:12px 22px;border-radius:4px;text-decoration:none;">Agenda una visita sin costo &rarr;</a></p>
</div>
<p>¿Quieres el panorama completo para proteger tu empresa? Empieza por nuestras <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">soluciones de ciberseguridad para pequeñas empresas</a>.</p>
<h2>Envíanos un mensaje</h2>
<p>¿Tienes una pregunta sobre tu configuración en la nube, o quieres una segunda opinión sobre quién tiene acceso a qué? Mandámela y te respondo personalmente.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_52_container">
			<label for="field_d4i78" >
				If you are human, leave this field blank.			</label>
			<input  id="field_d4i78" type="text" class="frm_form_field form-field frm_verify" name="item_meta[52]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCfLGR7a+wkZHx9wfVR1GM+UKqSkNI8AxMTBMDJ6pY2Bm" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 8px;font-size:12px;letter-spacing:.09em;text-transform:uppercase;color:#F59E0B;font-weight:700;">Sobre el autor</p>
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 12px;color:#334155;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="margin:0;color:#334155;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/quien-mas-puede-ver-tus-archivos-nube/">¿Quién Más Puede Ver Tus Archivos? El Error al Compartir en la Nube</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Who Else Can See Your Files? The Cloud Sharing Mistake Small Businesses Keep Making</title>
		<link>https://incognitocybersecurity.com/blog/who-else-can-see-your-files-cloud-sharing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=who-else-can-see-your-files-cloud-sharing</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 14:10:26 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/who-else-can-see-your-files-cloud-sharing/</guid>

					<description><![CDATA[<p>Most data leaks at small businesses do not start with a hacker. They start with a sharing link nobody turned off. Here is how to find yours this week.</p>
The post <a href="https://incognitocybersecurity.com/blog/who-else-can-see-your-files-cloud-sharing/">Who Else Can See Your Files? The Cloud Sharing Mistake Small Businesses Keep Making</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Who Else Can See Your Files? The Cloud Sharing Mistake Small Businesses Keep Making</h1>
<p class="ics-lang-switch" style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/quien-mas-puede-ver-tus-archivos-nube/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:10px 18px;border-radius:4px;text-decoration:none;">🇲🇽 Leer en Español →</a></p>
<p>Most owners I talk to picture a break-in when they think about a data leak. Someone in a hoodie, cracking a password, forcing their way in. That&#8217;s the movie version. The version I actually see in Southern Arizona is quieter and a lot more embarrassing: nobody broke in at all. A file was shared with &#8220;anyone with the link&#8221; three years ago, and it&#8217;s been sitting open on the internet ever since.</p>
<p>New research out this month makes the point better than I can. A security firm reviewed cloud misconfiguration data from 3,000 organizations across Amazon, Microsoft, and Google&#8217;s cloud platforms. Weak access controls showed up in 80% to 98% of accounts, depending on the provider. That is not a handful of careless companies. That is nearly everybody.</p>
<h2>The problem isn&#8217;t hackers. It&#8217;s settings.</h2>
<p>&#8220;Misconfiguration&#8221; is a technical word for something very ordinary: a switch that got flipped for convenience and never got flipped back. Your team needed to send a big proposal to a client, so somebody turned on public sharing. It worked. Everyone moved on. The switch stayed on.</p>
<p>The reason this matters more than it used to is that criminals have stopped guessing passwords and started looking for open doors. It is cheaper to scan the internet for exposed files than it is to attack a business head-on. If your quotes, payroll records, or client contracts are reachable without a login, you never get an alert. There is no alarm for a door you left unlocked on purpose.</p>
<h2>Three ways files leak without anyone breaking in</h2>
<h3>The link that never expires</h3>
<p>In Microsoft 365, Google Drive, and Dropbox, the fastest way to share something is a public link. It&#8217;s one click, and by default that link usually has no expiration date. The project ends, the client relationship ends, the employee who created it leaves — and the link keeps working.</p>
<h3>The account that outlived the employee</h3>
<p>When someone leaves, most small businesses remember to turn off email. Far fewer remember the shared drive, the accounting portal, the file-sync app still installed on a personal laptop. I have audited businesses where a person who left two years earlier could still open the company&#8217;s financial folder from home.</p>
<h3>Everybody is an administrator</h3>
<p>This one is almost always accidental. It&#8217;s faster to give a new hire full access than to figure out what they actually need. Multiply that by five years of hiring, and now a single stolen password opens every file you own instead of one folder.</p>
<p><img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-cloud-sharing-en-infographic.png" alt="Infographic with three cards: links that never expire, accounts that outlive staff, and admin rights for everyone." width="1200" height="640" class="aligncenter size-full" /></p>
<h2>Why this is worth an hour of your week</h2>
<p>Ransomware crews changed their business model. They used to just lock your files and demand payment. Now they copy your data first, then lock it, then threaten to publish what they took. Good backups still get you running again — and you should absolutely have <a href="https://incognitocybersecurity.com/secure-data-backups/">tested, off-site backups</a> — but backups don&#8217;t un-publish your client list.</p>
<p>That changes the math. A leaked folder isn&#8217;t just an IT headache. It&#8217;s a phone call to every customer in that folder. And it rarely starts with anything dramatic: in most of these cases the attackers simply used credentials that were already exposed. It&#8217;s the same pattern I wrote about when <a href="https://incognitocybersecurity.com/blog/vendor-breach-your-data/">a vendor breach put client data at risk</a> — the weak point was access nobody was watching.</p>
<h2>What you can do this week</h2>
<ol>
<li><strong>Pull your sharing report.</strong> Microsoft 365 and Google Workspace both let an admin list every file shared publicly. Run it once. Most owners are genuinely surprised by what comes back.</li>
<li><strong>Kill the public links you don&#8217;t need.</strong> Anything older than a finished project should be switched to named-people-only. Set new links to expire in 30 days by default.</li>
<li><strong>Write a five-line offboarding checklist.</strong> Email, shared drive, accounting software, password manager, company device returned. Five lines beats a perfect policy nobody follows.</li>
<li><strong>Count your administrators.</strong> A business with ten employees does not need six admins. It needs two, and everyone else gets what their job requires.</li>
<li><strong>Spend fifteen minutes with your team.</strong> Show them the difference between &#8220;share with Maria&#8221; and &#8220;share with anyone.&#8221; Short, practical <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">security awareness training</a> prevents more leaks than any product I can sell you.</li>
</ol>
<h2>The bottom line</h2>
<p>You do not need a bigger security budget to fix this. You need an afternoon and someone willing to look. The businesses that get hurt aren&#8217;t the ones with weak technology — they&#8217;re the ones where nobody ever checked who still has the keys. Layer in <a href="https://incognitocybersecurity.com/end-point-protection/">endpoint protection</a> and <a href="https://incognitocybersecurity.com/spam-virus-filtering/">email filtering</a> on top of clean permissions, and you&#8217;ve closed the doors attackers actually use.</p>
<p>If you&#8217;d rather not go digging through admin menus yourself, that&#8217;s fair. It&#8217;s what we do. More plain-English guidance is on <a href="https://incognitocybersecurity.com/blog/">our blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:26px 28px;margin:36px 0;color:#E2E8F0;">
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#ffffff;">Not sure who can see your files?</p>
<p style="margin:0 0 16px;color:#9FB3C8;">We&#8217;ll review your cloud sharing settings, user accounts, and admin rights, then hand you a plain-English list of what to fix. No jargon, no pressure.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:12px 22px;border-radius:4px;text-decoration:none;">Book a complimentary visit &rarr;</a></p>
</div>
<p>Want the bigger picture on protecting your company? Start with our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">small business cyber security solutions</a>.</p>
<h2>Send us a message</h2>
<p>Have a question about your cloud setup, or want a second opinion on who has access to what? Send it over and I&#8217;ll answer personally.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_53_container">
			<label for="field_kf9bc" >
				If you are human, leave this field blank.			</label>
			<input  id="field_kf9bc" type="text" class="frm_form_field form-field frm_verify" name="item_meta[53]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCa99D60FkAVxUyUS6gZqXWtWTbRBdTf+l1FcYuciLKot" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 8px;font-size:12px;letter-spacing:.09em;text-transform:uppercase;color:#F59E0B;font-weight:700;">About the author</p>
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 12px;color:#334155;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="margin:0;color:#334155;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/who-else-can-see-your-files-cloud-sharing/">Who Else Can See Your Files? The Cloud Sharing Mistake Small Businesses Keep Making</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>El Falso Técnico de TI: Cuando el Acceso Remoto Es la Estafa</title>
		<link>https://incognitocybersecurity.com/blog/falso-tecnico-ti-acceso-remoto/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=falso-tecnico-ti-acceso-remoto</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 14:13:43 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/falso-tecnico-ti-acceso-remoto/</guid>

					<description><![CDATA[<p>Una campaña de phishing en 46 países engaña al personal para instalar herramientas reales de soporte remoto. Tu antivirus no lo detiene. Una regla sí.</p>
The post <a href="https://incognitocybersecurity.com/blog/falso-tecnico-ti-acceso-remoto/">El Falso Técnico de TI: Cuando el Acceso Remoto Es la Estafa</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>El Falso Técnico de TI: Cuando el Acceso Remoto Es la Estafa</h1>
<p style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/fake-it-guy-remote-access-scam/">🇺🇸 Read this article in English</a></p>
<p>La mayoría de las estafas buscan tu contraseña. Esta se salta ese paso por completo. Le pide a tu empleado que instale un programa &mdash; y después el atacante simplemente se sienta frente al teclado.</p>
<p>Los investigadores de ANY.RUN han estado siguiendo una campaña de phishing que ya abarca 46 países, y Estados Unidos es el principal objetivo con cerca del 45% de la actividad observada. Los correos son comunes a propósito: un aviso fiscal, una factura vencida, una actualización de envío, un PDF compartido. Al hacer clic, lo que llega a la computadora no es un virus. Es una herramienta de soporte remoto real y con licencia comercial &mdash; ScreenConnect, ConnectWise, LogMeIn Rescue. El mismo tipo de software que mi equipo usa para reparar tu laptop sin cruzar todo Tucson.</p>
<p>Por eso mismo funciona.</p>
<h2>Por qué tu antivirus no interviene</h2>
<h3>El software es genuinamente legítimo</h3>
<p>Son productos firmados, pagados y legales que usan departamentos de TI en todo el mundo. Tu antivirus no tiene una firma con qué compararlo ni motivo para levantar la mano. Bloquear toda la categoría rompería el soporte legítimo del que depende tu negocio. Por eso la <a href="https://incognitocybersecurity.com/end-point-protection/">protección de endpoints</a> que solo pregunta &laquo;¿este archivo es conocido como malo?&raquo; deja pasar esto sin problema. Lo que importa es lo que un programa <em>hace</em> después de instalarse, no cómo se llama.</p>
<h3>Una vez que corre, parece un día normal de trabajo</h3>
<p>Una sesión remota a media tarde no es sospechosa. Es martes. Siempre hay alguien arreglando algo. El atacante no está rompiendo tu firewall; está entrando por una puerta que tu negocio dejó abierta a propósito para TI. Y no se queda quieto &mdash; los investigadores encontraron que el 94% de la infraestructura de la campaña estuvo activa un solo día y luego desapareció, lo que hace casi inútil bloquearla por dirección.</p>
<p><img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-tecnico-falso-info-es.png" alt="Infografía con tres tarjetas: parece legítimo, el anzuelo es aburrido y un clic da control total de tu pantalla." width="1200" height="640" class="aligncenter size-full wp-image-3204" srcset="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-tecnico-falso-info-es.png 1200w, https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-tecnico-falso-info-es-980x523.png 980w, https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-tecnico-falso-info-es-480x256.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1200px, 100vw" /></p>
<h2>Cómo se ve esto en un negocio pequeño</h2>
<p>Esta es la versión que me preocupa. Tu contadora recibe un correo sobre una factura supuestamente vencida. Lo abre, le aparece un aviso para instalar un visor y poder leer el documento, y hace clic en sí &mdash; porque ha dicho que sí a cien avisos inofensivos antes. Diez minutos después, alguien que nunca ha visto está mirando su pantalla.</p>
<p>A esas alturas no necesitan robar ninguna contraseña. Ella ya está dentro del portal del banco, del sistema contable y del correo. Están dentro de una sesión en la que todo ya confía. De ahí pasan a cambiar instrucciones de transferencia, leer el historial de correos para aprender cómo habla tu empresa sobre dinero, o preparar en silencio un ataque de ransomware para la semana siguiente &mdash; que es el momento en que tus <a href="https://incognitocybersecurity.com/secure-data-backups/">respaldos seguros</a> dejan de ser una línea en una factura y pasan a ser el negocio entero.</p>
<h2>La regla que detiene casi todo esto</h2>
<p><strong>Nadie legítimo te va a contactar de la nada para pedirte que instales software de acceso remoto.</strong></p>
<p>Nosotros no. Microsoft tampoco. Ni tu banco, ni el proveedor de tu impresora, ni el IRS. El soporte de TI real es algo que <em>tú</em> solicitaste, de una empresa con la que ya trabajas, a un número que ya tenías. Si llega una solicitud de acceso remoto que nadie pidió &mdash; correo, ventana emergente, llamada o mensaje de texto &mdash; la respuesta es no, siempre. Después verificas llamando a la empresa a un número que tú mismo busques, no el que viene en el mensaje.</p>
<p>Es el mismo instinto detrás de <a rel="nofollow" href="https://incognitocybersecurity.com/fatiga-mfa-solicitud-acceso/">la solicitud de acceso que nunca debes aprobar</a>: si tú no lo iniciaste, no lo apruebes.</p>
<h2>Lo que puedes hacer esta semana</h2>
<ol>
<li><strong>Di la regla en voz alta en tu próxima junta.</strong> &laquo;Nunca te vamos a mandar un correo pidiéndote que instales software remoto. Si alguien lo hace, es falso, y me avisas.&raquo; Dos frases. Esa es toda la capacitación.</li>
<li><strong>Anota qué herramientas remotas usan de verdad.</strong> Si tu soporte de TI usa una herramienta específica, todos deberían saber su nombre. Cualquier otra cosa que aparezca en pantalla es una señal de alerta, no un misterio que resolver en silencio.</li>
<li><strong>Quita los permisos de administrador de las cuentas del día a día.</strong> Si tu contadora no puede instalar software sin ti, este ataque muere en el aviso. Es el cambio de mayor valor de esta lista y no cuesta nada.</li>
<li><strong>Refuerza la entrada.</strong> Un buen <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtrado de spam y virus</a> elimina la mayoría de estos anzuelos antes de que alguien tenga que decidir. No puedes hacer clic en lo que nunca llegó.</li>
<li><strong>Acuerden cómo se verifica el dinero.</strong> Cualquier cambio en datos de transferencia, cuentas bancarias o instrucciones de pago se confirma con una llamada a un número conocido. Sin excepciones, sin importar quién parezca estar pidiéndolo.</li>
<li><strong>Dale permiso a tu gente de equivocarse.</strong> El empleado que dice &laquo;creo que le di clic a algo&raquo; en los primeros diez minutos te ahorra una semana caretsísima. La <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">capacitación continua en seguridad</a> funciona porque vuelve normal el hablar a tiempo.</li>
</ol>
<h2>En resumen</h2>
<p>Este ataque no le gana a tu tecnología. Le gana a una costumbre &mdash; la de decir que sí a un aviso porque decir que sí es como transcurre el día normalmente. La solución no es un firewall más grande. Es una regla clara que todos en tu edificio conozcan, más el trabajo aburrido de limitar quién puede instalar qué.</p>
<p>Si ahora mismo no sabes quién puede instalar software en tus computadoras, vale la pena averiguarlo esta semana y no después de que alguien haga clic. Hay más explicaciones en lenguaje sencillo como esta en <a href="https://incognitocybersecurity.com/blog/">nuestro blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:26px 30px;margin:36px 0;">
<p style="margin:0 0 10px;font-size:20px;font-weight:700;color:#ffffff;">¿No sabes quién puede instalar software en tus computadoras?</p>
<p style="margin:0 0 16px;color:#9FB3C8;">Hacemos esto para pequeñas empresas en todo el sur de Arizona &mdash; limitar permisos de administrador, filtrar el correo malicioso y contestar el teléfono a las 2 de la mañana cuando algo sale mal. Conoce nuestras <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/" style="color:#22D3EE;">soluciones de ciberseguridad para pequeñas empresas</a>.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:12px 22px;border-radius:4px;text-decoration:none;">Agenda una visita sin costo &rarr;</a></p>
</div>
<h2>Envíanos un mensaje</h2>
<p>¿Tienes una pregunta sobre algo de este artículo, o quieres una segunda opinión sobre cómo están configurados tus sistemas? Mándala y te respondo personalmente.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_54_container">
			<label for="field_btoye" >
				If you are human, leave this field blank.			</label>
			<input  id="field_btoye" type="text" class="frm_form_field form-field frm_verify" name="item_meta[54]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCaQwQnFmn8Pwln2YyYp73hOkvscbyQ1Om6z9/3SUYmo6" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 10px;font-size:12px;font-weight:700;letter-spacing:0.08em;text-transform:uppercase;color:#F59E0B;">Sobre el autor</p>
<p style="margin:0 0 12px;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 14px;color:#334155;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="margin:0;color:#334155;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/falso-tecnico-ti-acceso-remoto/">El Falso Técnico de TI: Cuando el Acceso Remoto Es la Estafa</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Fake IT Guy: When Remote Access Software Is the Scam</title>
		<link>https://incognitocybersecurity.com/blog/fake-it-guy-remote-access-scam/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=fake-it-guy-remote-access-scam</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 14:12:26 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/fake-it-guy-remote-access-scam/</guid>

					<description><![CDATA[<p>A phishing campaign in 46 countries is tricking staff into installing real remote support tools. Your antivirus will not stop it. One simple rule will.</p>
The post <a href="https://incognitocybersecurity.com/blog/fake-it-guy-remote-access-scam/">The Fake IT Guy: When Remote Access Software Is the Scam</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>The Fake IT Guy: When Remote Access Software Is the Scam</h1>
<p style="margin:18px 0 26px;"><a href="https://incognitocybersecurity.com/blog/falso-tecnico-ti-acceso-remoto/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:10px 20px;border-radius:4px;text-decoration:none;">🇲🇽 Leer en Español &rarr;</a></p>
<p>Most scams are after your password. This one skips that step completely. It asks your employee to install a program &mdash; and then the attacker simply sits down at the keyboard.</p>
<p>Researchers at ANY.RUN have been tracking a phishing campaign that now spans 46 countries, and the United States is the top target at roughly 45% of the activity they observed. The emails are unremarkable on purpose: a tax notice, a past-due invoice, a shipping update, a shared PDF. Click through, and what lands on the machine is not a virus. It is a real, commercially licensed remote support tool &mdash; ScreenConnect, ConnectWise, LogMeIn Rescue. The same category of software my team uses to fix your laptop without driving across Tucson.</p>
<p>That is exactly why it works.</p>
<h2>Why your antivirus sits this one out</h2>
<h3>The software is genuinely legitimate</h3>
<p>These are signed, paid, above-board products used by IT departments everywhere. Your antivirus has no signature to match and no reason to raise its hand. Blocking the whole category outright would break the legitimate support your business depends on. This is why <a href="https://incognitocybersecurity.com/end-point-protection/">endpoint protection</a> that only asks &ldquo;is this file known to be bad?&rdquo; will wave this straight through. What matters is what a program <em>does</em> after it is installed, not what it is called.</p>
<h3>Once it is running, it looks like a normal workday</h3>
<p>A remote session in the middle of the afternoon is not suspicious. It is Tuesday. Somebody is always fixing something. The attacker is not smashing through your firewall; they are walking through a door your business deliberately left unlocked for IT. And they do not stay put &mdash; researchers found 94% of the campaign&rsquo;s hosting infrastructure was live for a single day and then vanished, which makes blocking it by address close to useless.</p>
<p><img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-fake-it-guy-info-en.png" alt="Infographic with three cards: it looks legitimate, the bait is boring, and one click gives full control of your screen." width="1200" height="640" class="aligncenter size-full wp-image-3202" srcset="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-fake-it-guy-info-en.png 1200w, https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-fake-it-guy-info-en-980x523.png 980w, https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-2026-09-fake-it-guy-info-en-480x256.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1200px, 100vw" /></p>
<h2>What this looks like in a small business</h2>
<p>Here is the version I worry about. Your bookkeeper gets an email about an invoice that is supposedly past due. She opens it, gets a prompt to install a viewer so she can read the document, and clicks yes &mdash; because she has clicked yes to a hundred harmless prompts before. Ten minutes later, someone she has never met is watching her screen.</p>
<p>They do not need to steal a password at that point. She is already signed into the bank portal, the accounting system, and email. They are inside a session that everything already trusts. From there it is changing wire instructions, reading the email history to learn how your company talks about money, or quietly preparing a ransomware deployment for the following week &mdash; which is the moment your <a href="https://incognitocybersecurity.com/secure-data-backups/">secure backups</a> stop being a line item on an invoice and start being the entire business.</p>
<h2>The one rule that stops almost all of it</h2>
<p><strong>Nobody legitimate will ever contact you out of the blue and ask you to install remote access software.</strong></p>
<p>Not us. Not Microsoft. Not your bank, your printer vendor, or the IRS. Real IT support is something <em>you</em> asked for, from a company you already work with, at a number you already had. If a request for remote access shows up unsolicited &mdash; email, popup, phone call, or text &mdash; the answer is no, every single time. Then you verify by calling the company back on a number you look up yourself, not one from the message.</p>
<p>It is the same instinct behind <a rel="nofollow" href="https://incognitocybersecurity.com/mfa-fatigue-login-request/">the login request you should never approve</a>: if you did not start it, do not approve it.</p>
<h2>What you can do this week</h2>
<ol>
<li><strong>Say the rule out loud at your next staff meeting.</strong> &ldquo;We will never email you and ask you to install remote software. If anyone does, it is fake, and you come tell me.&rdquo; Two sentences. That is the whole training.</li>
<li><strong>Write down which remote tools you actually use.</strong> If your IT support uses one specific tool, everyone should know its name. Anything else appearing on a screen is a red flag, not a mystery to be solved quietly.</li>
<li><strong>Take local admin rights away from day-to-day accounts.</strong> If your bookkeeper cannot install software without you, this attack dies at the prompt. This is the single highest-value change on the list, and it costs nothing.</li>
<li><strong>Tighten the front end.</strong> Good <a href="https://incognitocybersecurity.com/spam-virus-filtering/">spam and virus filtering</a> strips out most of these lures before anyone has a decision to make. You cannot click what never arrives.</li>
<li><strong>Agree on how you verify money.</strong> Any change to wire details, bank accounts, or payment instructions gets confirmed by a phone call to a known number. No exceptions, no matter who appears to be asking.</li>
<li><strong>Give people permission to be wrong.</strong> The employee who says &ldquo;I think I clicked something&rdquo; in the first ten minutes saves you a very expensive week. Ongoing <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">security awareness training</a> works because it makes speaking up normal.</li>
</ol>
<h2>The bottom line</h2>
<p>This attack does not beat your technology. It beats a habit &mdash; the habit of saying yes to a prompt because saying yes is how the day usually goes. The fix is not a bigger firewall. It is one clear rule that everyone in your building knows, plus the boring groundwork of limiting who can install what.</p>
<p>If you are not sure who can install software on your machines right now, that is worth finding out this week rather than after somebody clicks. More plain-English breakdowns like this one are on <a href="https://incognitocybersecurity.com/blog/">our blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:26px 30px;margin:36px 0;">
<p style="margin:0 0 10px;font-size:20px;font-weight:700;color:#ffffff;">Not sure who can install software on your computers?</p>
<p style="margin:0 0 16px;color:#9FB3C8;">We handle this for small businesses all over Southern Arizona &mdash; locking down admin rights, filtering the bad email out, and answering the phone at 2 a.m. when something goes wrong. See our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/" style="color:#22D3EE;">small business cyber security solutions</a>.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:12px 22px;border-radius:4px;text-decoration:none;">Book a complimentary visit &rarr;</a></p>
</div>
<h2>Send us a message</h2>
<p>Have a question about something in this article, or want a second opinion on how your systems are set up? Send it over and I will get back to you personally.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_55_container">
			<label for="field_1ax0w" >
				If you are human, leave this field blank.			</label>
			<input  id="field_1ax0w" type="text" class="frm_form_field form-field frm_verify" name="item_meta[55]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCTIvuKWXw7VNnQAQimyH/qAfmQ/BDTMKjD0VgUX/BsqO" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 10px;font-size:12px;font-weight:700;letter-spacing:0.08em;text-transform:uppercase;color:#F59E0B;">About the author</p>
<p style="margin:0 0 12px;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 14px;color:#334155;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="margin:0;color:#334155;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/fake-it-guy-remote-access-scam/">The Fake IT Guy: When Remote Access Software Is the Scam</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>La Solicitud de Acceso que Nunca Debes Aprobar</title>
		<link>https://incognitocybersecurity.com/blog/fatiga-mfa-solicitud-acceso/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=fatiga-mfa-solicitud-acceso</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 14:12:48 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/fatiga-mfa-solicitud-acceso/</guid>

					<description><![CDATA[<p>Los atacantes no pueden romper tu autenticacion multifactor, asi que inundan a tu personal con avisos de acceso hasta que alguien toca aprobar. Asi lo detienes esta semana.</p>
The post <a href="https://incognitocybersecurity.com/blog/fatiga-mfa-solicitud-acceso/">La Solicitud de Acceso que Nunca Debes Aprobar</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>La Solicitud de Acceso que Nunca Debes Aprobar</h1>
<p style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/mfa-fatigue-login-request/">🇺🇸 Read this article in English</a></p>
<p>Son las 10:40 de la noche de un martes. Tu gerente de oficina está en el sofá con la tele encendida. Su teléfono vibra: <em>¿Aprobar inicio de sesión?</em> Ella no intentó entrar a nada, así que toca Rechazar. Treinta segundos después vibra otra vez. Y otra. Para el aviso número doce ya está cansada, algo molesta y medio convencida de que el sistema está fallando. Toca Aprobar solo para que pare.</p>
<p>Ese es el ataque completo. Sin malware. Sin código sofisticado. Alguien ya tenía su contraseña y simplemente la agotó.</p>
<p>Tiene nombre y vale la pena conocerlo: fatiga de MFA, también llamado bombardeo de avisos. Microsoft contó unos 382,000 de estos ataques en un solo periodo de doce meses. Cerca del uno por ciento terminó con alguien tocando Aprobar. El uno por ciento suena a nada hasta que sacas la cuenta sobre 382,000.</p>
<h2>Cómo funciona el ataque en realidad</h2>
<p>La autenticación multifactor (MFA) es ese segundo paso que agregaste para que una contraseña robada no fuera suficiente por sí sola. Normalmente ese segundo paso es un aviso en el teléfono: te pregunta si el acceso realmente eres tú, y tú tocas sí o no.</p>
<p>Los atacantes no pueden romper eso. Así que ni lo intentan. En vez de eso, toman una contraseña que ya robaron y presionan el botón de acceso una y otra vez, lo cual envía un aviso nuevo al teléfono de tu empleada cada vez. Quince avisos. Cuarenta avisos. Avisos a las dos de la mañana. No están tratando de engañar a tu tecnología. Están tratando de agotar a una persona.</p>
<h3>De dónde salió la contraseña</h3>
<p>Esta es la parte que los dueños pasan por alto. Un ataque de bombardeo de avisos significa que alguien <em>ya tiene una contraseña que funciona</em> en tu negocio. Salió de un correo de phishing, de una contraseña reutilizada que se filtró en la brecha de otra empresa, o de malware que copió en silencio los accesos guardados en un navegador. Sobre esto último escribí hace poco en <a href="https://incognitocybersecurity.com/blog/contrasenas-guardadas-navegador/">Contraseñas Guardadas: La Puerta Más Fácil a tu Negocio</a>, y es el origen más común que veo en casos reales.</p>
<p>Así que un aviso inesperado nunca es solo una molestia. Es una alarma de humo.</p>
<h2>Por qué funciona con buenos empleados</h2>
<p>Quiero ser claro en algo, porque los dueños terminan enojados con la persona equivocada después de que esto pasa. La empleada que toca Aprobar no es descuidada. Es una persona normal a la que interrumpen en su casa, una y otra vez, con un sistema que le dijeron que era confiable.</p>
<p>Nadie le enseñó qué significa una ráfaga de avisos inesperados. Nadie le dijo a quién llamar a las 10:40 de la noche. El aviso no dice <em>alguien en otro país está usando tu contraseña en este momento</em>. Solo dice <em>¿Aprobar inicio de sesión?</em>, el mismo mensaje amable al que le da sí cada mañana.</p>
<p>Ese vacío es un problema de capacitación, no de carácter, y se resuelve en unos veinte minutos. Nuestra <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">capacitación en conciencia de seguridad para empresas</a> cubre exactamente este escenario, porque es el que sigue cayendo.</p>
<h2>Lo que cuesta cuando funciona</h2>
<p>Una vez que el atacante está dentro de una cuenta legítima, la mayoría de tus defensas dejan de verlo como atacante. Está dentro. Lee correos. Observa cómo se pagan tus facturas. Encuentra tu almacenamiento de archivos y tu sistema de nómina.</p>
<p>La versión famosa de esto fue Uber, donde un contratista recibió unos cuarenta avisos en treinta minutos, finalmente aprobó uno y entregó las llaves de los sistemas internos. Pero esto no es un problema de empresas grandes que luego gotea hacia abajo. La misma táctica se usó contra una cadena grande de tiendas, y los atacantes terminaron desplegando ransomware en cerca de mil sucursales. Nada de esta técnica requiere un objetivo grande. Requiere una persona cansada con un teléfono.</p>
<p><img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/mfa-fatigue-info-es.png" alt="Infografia con tres acciones contra la fatiga de MFA: nunca toques aprobar, activa la coincidencia de numeros, reporta todo aviso raro" width="1200" height="660" style="max-width:100%;height:auto;margin:32px 0;border-radius:6px;" /></p>
<h2>Lo que puedes hacer esta semana</h2>
<ol>
<li><strong>Activa la coincidencia de números.</strong> En vez de un toque de sí o no, la pantalla de acceso muestra un número de dos dígitos y tu empleada tiene que escribirlo en el teléfono. Un toque a ciegas ya no sirve, porque la pantalla del atacante no está frente a tu empleada. CISA recomienda esto específicamente si aún no puedes pasar a un MFA más fuerte. En Microsoft 365 y Google Workspace es una configuración, no una compra.</li>
<li><strong>Dale a tu equipo una sola frase que recordar.</strong> Si aparece un aviso y tú no acabas de intentar entrar, recházalo y avisa. Esa es toda la regla. Díganla en la próxima junta de personal y pónganla por escrito.</li>
<li><strong>Trata cada aviso inesperado como una contraseña robada.</strong> No basta con rechazarlo y seguir. Esa contraseña ya está quemada. Cámbiala ese mismo día, en todos los lugares donde se haya reutilizado.</li>
<li><strong>Asegúrate de que alguien conteste a las 10:40 de la noche.</strong> Tu equipo necesita un número al cual llamar cuando esto pasa fuera de horario. Si no lo tienes, para eso existen nuestras <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">soluciones de seguridad para pequeñas empresas</a> y nuestra línea de emergencia 24/7.</li>
<li><strong>Acorta el camino hacia la contraseña.</strong> Menos contraseñas robadas significa menos de estos ataques. Un buen <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtrado de spam y virus</a> detiene el correo de phishing, y la <a href="https://incognitocybersecurity.com/end-point-protection/">protección de endpoints</a> detiene el malware que cosecha los accesos guardados.</li>
</ol>
<p>Una más, menos urgente pero que vale la pena planear: si pasa lo peor y alguien sí logra entrar, tener <a href="https://incognitocybersecurity.com/secure-data-backups/">respaldos de datos seguros</a> ya probados es la diferencia entre una mala semana y un negocio cerrado.</p>
<h2>En resumen</h2>
<p>El MFA sigue valiendo la pena. Detiene la gran mayoría de los ataques, y jamás le diría a un cliente que lo apague. Pero la versión que la mayoría de las pequeñas empresas está usando — toca sí, toca no — se diseñó pensando en la comodidad, y los atacantes encontraron la costura.</p>
<p>Activar la coincidencia de números no te cuesta nada más que unos minutos en un menú de configuración. Decirle a tu equipo la regla de una sola frase no te cuesta absolutamente nada. Entre esas dos cosas, cierras una puerta que muchos negocios están dejando abierta de par en par.</p>
<p>Si no estás seguro de cómo está configurado tu MFA en este momento, es una respuesta justa, y es algo rápido de revisar. Hay más artículos prácticos como este en <a href="https://incognitocybersecurity.com/blog/">nuestro blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:26px 28px;margin:36px 0;color:#E2E8F0;">
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#ffffff;">¿No sabes cómo está configurado tu MFA?</p>
<p style="margin:0 0 16px;color:#9FB3C8;">Revisamos tu configuración de Microsoft 365 o Google Workspace, te decimos claramente si estás expuesto a esto y te mostramos qué cambiar. Sin costo y sin presión.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:12px 22px;border-radius:5px;text-decoration:none;">Agenda una visita sin costo &rarr;</a></p>
</div>
<h2>Envíanos un mensaje</h2>
<p>¿Preguntas sobre este artículo o quieres que revisemos tu configuración? Escríbenos y te respondemos.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_56_container">
			<label for="field_fh8ni" >
				If you are human, leave this field blank.			</label>
			<input  id="field_fh8ni" type="text" class="frm_form_field form-field frm_verify" name="item_meta[56]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCR68tTyveqAwlAqBRrYeOomslxTMff7CFbU03rwP1Mwo" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 8px;font-size:12px;letter-spacing:1px;text-transform:uppercase;color:#F59E0B;font-weight:700;">Sobre el autor</p>
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 12px;color:#334155;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="margin:0;color:#334155;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/fatiga-mfa-solicitud-acceso/">La Solicitud de Acceso que Nunca Debes Aprobar</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Login Request You Should Never Approve</title>
		<link>https://incognitocybersecurity.com/blog/mfa-fatigue-login-request/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mfa-fatigue-login-request</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 14:11:24 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/mfa-fatigue-login-request/</guid>

					<description><![CDATA[<p>Attackers cannot break your multi-factor authentication, so they flood your staff with approval prompts until someone taps yes. Here is how to shut that down this week.</p>
The post <a href="https://incognitocybersecurity.com/blog/mfa-fatigue-login-request/">The Login Request You Should Never Approve</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>The Login Request You Should Never Approve</h1>
<p style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/fatiga-mfa-solicitud-acceso/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:10px 20px;border-radius:5px;text-decoration:none;">🇲🇽 Leer en Español →</a></p>
<p>It is 10:40 on a Tuesday night. Your office manager is on the couch with the TV on. Her phone buzzes: <em>Approve sign-in?</em> She did not try to sign in to anything, so she taps Deny. Thirty seconds later it buzzes again. Then again. By the twelfth buzz she is tired, a little annoyed, and half convinced the system is glitching. She taps Approve just to make it stop.</p>
<p>That is the entire attack. No malware. No clever code. Somebody already had her password, and they simply outlasted her.</p>
<p>It has a name, and it is worth knowing: MFA fatigue, sometimes called push bombing. Microsoft counted roughly 382,000 of these attacks in a single twelve-month stretch. About one percent of them ended with somebody tapping Approve. One percent sounds like nothing until you run the math on 382,000.</p>
<h2>How the attack actually works</h2>
<p>Multi-factor authentication is the second step you added so a stolen password alone would not be enough. Usually that second step is a push notification: your phone asks if the login is really you, and you tap yes or no.</p>
<p>Attackers cannot break that. So they do not try. Instead they take a password they already stole and hammer the login button over and over, which sends a fresh approval request to your employee&#8217;s phone every time. Fifteen requests. Forty requests. Requests at two in the morning. They are not trying to trick your technology. They are trying to exhaust a human being.</p>
<h3>Where the password came from in the first place</h3>
<p>This is the part owners miss. A push bombing attack means someone <em>already has a working password</em> for your business. It came from a phishing email, a reused password exposed in somebody else&#8217;s breach, or malware that quietly scraped the logins saved in a browser. I wrote about that last one recently in <a href="https://incognitocybersecurity.com/blog/saved-passwords-browser-security/">Saved Passwords: The Easiest Way Into Your Business</a>, and it is the most common source I see in real cases.</p>
<p>So a stray approval prompt is never just an annoyance. It is a smoke alarm.</p>
<h2>Why it works on good employees</h2>
<p>I want to be clear about something, because owners get angry at the wrong person after this happens. The employee who taps Approve is not careless. She is a normal person being interrupted at home, repeatedly, by a system she was told to trust.</p>
<p>Nobody trained her on what a burst of unexpected prompts means. Nobody told her who to call at 10:40 at night. The prompt does not say <em>somebody in another country is using your password right now</em>. It just says <em>Approve sign-in?</em> — the same friendly message she taps yes to every morning.</p>
<p>That gap is a training problem, not a character problem, and it is fixable in about twenty minutes. Our <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">security awareness training for business</a> covers exactly this scenario, because it is the one that keeps landing.</p>
<h2>What it costs when it works</h2>
<p>Once an attacker is inside a legitimate account, most of your defenses stop seeing them as an attacker. They are logged in. They read email. They watch how your invoices get paid. They find your file storage and your payroll system.</p>
<p>The famous version of this was Uber, where a contractor got about forty prompts in thirty minutes, finally approved one, and handed over the keys to internal systems. But this is not a big-company problem that trickles down. The same playbook was run against a major retailer, and the attackers finished by deploying ransomware across roughly a thousand store locations. Nothing about the technique requires a large target. It requires one tired person with a phone.</p>
<p><img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/mfa-fatigue-info-en.png" alt="Infographic showing three moves that stop MFA fatigue: never tap approve, turn on number matching, report every surprise prompt" width="1200" height="640" style="max-width:100%;height:auto;margin:32px 0;border-radius:6px;" /></p>
<h2>What you can do this week</h2>
<ol>
<li><strong>Turn on number matching.</strong> Instead of a yes/no tap, the login screen shows a two-digit number and your employee has to type it into the phone. A blind tap no longer works, because the attacker&#8217;s screen is not in front of your employee. CISA specifically recommends this if you cannot move to stronger MFA yet. In Microsoft 365 and Google Workspace this is a setting, not a purchase.</li>
<li><strong>Give your team one sentence to remember.</strong> If a prompt shows up and you did not just try to log in, deny it and tell someone. That is the whole rule. Say it at your next staff meeting and put it in writing.</li>
<li><strong>Treat every surprise prompt as a stolen password.</strong> Do not just deny it and move on. That password is burned. Change it that day, everywhere it was reused.</li>
<li><strong>Make sure someone answers at 10:40 at night.</strong> Your team needs a number to call when this happens after hours. If you do not have one, that is precisely what our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">small business security service</a> and 24/7 emergency line exist for.</li>
<li><strong>Shorten the path to the password.</strong> Fewer stolen passwords means fewer of these attacks. Good <a href="https://incognitocybersecurity.com/spam-virus-filtering/">spam and virus filtering</a> stops the phishing email, and <a href="https://incognitocybersecurity.com/end-point-protection/">endpoint protection</a> stops the malware that harvests saved logins.</li>
</ol>
<p>One more, less urgent but worth planning: if the worst happens and someone does get in, tested <a href="https://incognitocybersecurity.com/secure-data-backups/">secure data backups</a> are the difference between a bad week and a closed business.</p>
<h2>The bottom line</h2>
<p>MFA is still worth having. It stops the overwhelming majority of attacks, and I would never tell a client to turn it off. But the version most small businesses are running — tap yes, tap no — was designed for convenience, and attackers found the seam.</p>
<p>Switching on number matching costs you nothing but a few minutes in a settings menu. Telling your team the one-sentence rule costs you nothing at all. Between those two, you close a door that a lot of businesses are leaving wide open.</p>
<p>If you are not sure what your MFA is set to right now, that is a fair answer, and it is a quick thing to check. More practical write-ups like this one are on <a href="https://incognitocybersecurity.com/blog/">our blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:26px 28px;margin:36px 0;color:#E2E8F0;">
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#ffffff;">Not sure how your MFA is configured?</p>
<p style="margin:0 0 16px;color:#9FB3C8;">We will look at your Microsoft 365 or Google Workspace setup, tell you plainly whether you are exposed to this, and show you what to change. No charge, no pressure.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;padding:12px 22px;border-radius:5px;text-decoration:none;">Book a complimentary visit &rarr;</a></p>
</div>
<h2>Send us a message</h2>
<p>Questions about this article, or want us to take a look at your setup? Send us a note and we will get back to you.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_57_container">
			<label for="field_jjxvv" >
				If you are human, leave this field blank.			</label>
			<input  id="field_jjxvv" type="text" class="frm_form_field form-field frm_verify" name="item_meta[57]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCQFBW2/0Z1mt3ciQco8i/kt7ZgBbMy9czh0GepRnhhe9" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>&mdash; Nemuel Cruz, Incognito Cyber Security</em></p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 8px;font-size:12px;letter-spacing:1px;text-transform:uppercase;color:#F59E0B;font-weight:700;">About the author</p>
<p style="margin:0 0 10px;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 12px;color:#334155;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="margin:0;color:#334155;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/mfa-fatigue-login-request/">The Login Request You Should Never Approve</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hackearon a tu proveedor. Tus datos se fueron con él.</title>
		<link>https://incognitocybersecurity.com/blog/brecha-de-proveedor-tus-datos/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=brecha-de-proveedor-tus-datos</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 14:13:55 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/brecha-de-proveedor-tus-datos/</guid>

					<description><![CDATA[<p>Un proveedor de software de salud perdió 9.5 millones de expedientes. Sus clientes no hicieron nada mal. Así controla un negocio pequeño el riesgo de proveedores.</p>
The post <a href="https://incognitocybersecurity.com/blog/brecha-de-proveedor-tus-datos/">Hackearon a tu proveedor. Tus datos se fueron con él.</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Hackearon a tu proveedor. Tus datos se fueron con él.</h1>
<p style='margin:0 0 24px;'><a href='https://incognitocybersecurity.com/blog/vendor-breach-your-data/' style='font-size:15px;text-decoration:none;color:#0F1E34;'>🇺🇸 Read this article in English</a></p>
<p>La semana pasada, una empresa de la que la mayoría de los dueños de negocios nunca ha oído hablar tuvo que avisarle a 9.5 millones de personas que les robaron su información privada. La empresa se llama Aesto Health y está en Birmingham, Alabama. No atienden pacientes. No operan una clínica. Venden software que ayuda a los consultorios médicos a mover expedientes viejos cuando cambian de sistema o compran otra práctica.</p>
<p>Los atacantes entraron al entorno de nube de Amazon de esa empresa y se llevaron nombres, números de Seguro Social, historiales médicos, registros de facturación y datos de seguros de pacientes de más de veinte organizaciones de salud distintas. Esas veinte organizaciones no hicieron nada mal. Sus contraseñas estaban bien. Sus firewalls estaban bien. Simplemente le entregaron datos a un proveedor, que es algo que todo negocio del mundo hace todos los días.</p>
<p>Esa es la parte que quiero que consideres, porque también aplica a tu negocio.</p>
<h2>Tus proveedores tienen tus datos en este momento</h2>
<p>Tómate sesenta segundos y cuenta. Tu empresa de nómina tiene los números de Seguro Social de tus empleados. Tu contador tiene los datos de tu banco. Tu aplicación de citas tiene tu lista de clientes. Tu agencia de marketing tiene tu base de correos. Tu CRM tiene cada nota que escribiste sobre un cliente. Tu almacenamiento de archivos tiene tus contratos firmados.</p>
<p>La mayoría de los dueños con los que me siento aquí en Tucson pueden nombrar tres proveedores de memoria. Cuando de verdad revisamos juntos el estado de cuenta de la tarjeta, el número real casi siempre está entre quince y cuarenta.</p>
<h3>Tus clientes no le llaman al proveedor</h3>
<p>Esta es la verdad incómoda de una brecha de proveedor: tus clientes no saben ni les importa quién es tu proveedor de software. Ellos le dieron su información a <em>ti</em>. Cuando salga la carta de notificación, tu nombre es el que van a recordar, y tu teléfono es el que va a sonar.</p>
<h3>Los reguladores y tu aseguradora tampoco</h3>
<p>Si trabajas en salud, finanzas o derecho, casi siempre sigues siendo responsable por los datos que le entregaste a alguien más. Y si tienes un seguro cibernético, espera que la aseguradora te pregunte qué revisión hiciste de ese proveedor antes de compartir cualquier cosa. &ldquo;Supuse que eran seguros&rdquo; no es una respuesta que pague un reclamo.</p>
<h2>Esto ya no es un caso raro</h2>
<p>El Informe de Investigaciones de Brechas de Datos 2026 de Verizon encontró que un tercero estuvo involucrado en el 48% de todas las brechas, casi el doble que el año anterior. Los investigadores que siguen estos incidentes también encontraron que, por cada proveedor que sufre una brecha, en promedio cinco empresas que dependen de él quedan expuestas públicamente.</p>
<p>Dicho claro: una de las formas que más crece para que te hackeen en 2026 es no ser hackeado en absoluto, y simplemente hacer negocios con alguien que sí lo fue.</p>
<figure style='margin:34px 0;'><img src='https://incognitocybersecurity.com/wp-content/uploads/2026/09/vendor-breach-infographic-es.png' alt='Infografia con tres tarjetas: pregunta antes de firmar, limita lo que guardan, conoce tu lista' width='1200' height='640' style='max-width:100%;height:auto;border-radius:6px;' /></figure>
<h2>Lo que puedes hacer esta semana</h2>
<ol>
<li><strong>Arma la lista.</strong> Abre los estados de cuenta del banco y de la tarjeta de los últimos doce meses y anota cada suscripción de software y cada proveedor de servicios que pagas. Esa lista es tu superficie de riesgo real, y a casi todos los dueños les sorprende lo larga que es.</li>
<li><strong>Marca quién guarda lo delicado.</strong> Señala cada proveedor que maneja expedientes de clientes, registros de empleados o información bancaria. Esos son los que importan. Los demás pueden esperar.</li>
<li><strong>Hazles tres preguntas a los que marcaste.</strong> ¿Exigen autenticación de múltiples factores en mi cuenta? ¿Mis datos están cifrados donde los guardan? ¿Qué tan rápido me avisan si sufren una brecha? Pregúntalo por correo para tener las respuestas por escrito.</li>
<li><strong>Apaga lo que ya no usas.</strong> Esa prueba gratuita que abandonaste hace dos años todavía tiene tus datos y probablemente todavía tiene un acceso activo. Cancélala y pide por escrito que borren lo que guardan.</li>
<li><strong>Decide a quién vas a llamar.</strong> Si un proveedor te escribe un martes por la tarde para avisarte que perdió tus datos, ¿a quién le llamas primero? ¿A tu abogado? ¿A tu corredor de seguros? ¿A nosotros? Decídelo ahora, mientras nada está en llamas.</li>
</ol>
<h2>Dónde se conecta esto con todo lo demás</h2>
<p>El riesgo de proveedores no es un problema aparte. Está justo al lado de lo básico que manejamos todos los días para nuestros <a href='https://incognitocybersecurity.com/small-business-cyber-security-solutions/'>clientes pequeños</a>. Una buena <a href='https://incognitocybersecurity.com/end-point-protection/'>protección de dispositivos</a> evita que un atacante use un acceso robado de un proveedor para extenderse a tus computadoras. Los <a href='https://incognitocybersecurity.com/secure-data-backups/'>respaldos seguros de datos</a> hacen que sigas teniendo tus registros aunque un proveedor pierda los suyos. Un buen <a href='https://incognitocybersecurity.com/spam-virus-filtering/'>filtrado de spam y virus</a> atrapa la ola de phishing que siempre viene después de una brecha grande, cuando los criminales usan los datos robados para sonar convincentes. Y la <a href='https://incognitocybersecurity.com/cybersecurity-awareness-for-business/'>capacitación en conciencia de seguridad</a> evita que tu personal se convierta en el eslabón débil de la cadena de otro.</p>
<p>Es la misma lección de <a href='https://incognitocybersecurity.com/blog/unpatched-software-open-door/'>la brecha de actualizaciones sobre la que escribí la semana pasada</a>, y la misma de casi todo lo que publico en <a href='https://incognitocybersecurity.com/blog/'>nuestro blog</a>: el mantenimiento aburrido es lo que te mantiene fuera de los titulares.</p>
<h2>En resumen</h2>
<p>No puedes auditar a un proveedor de nube como lo hace una empresa Fortune 500, y no deberías intentarlo. Pero sí puedes saber exactamente quién tiene tus datos, hacerles unas cuantas preguntas puntuales por escrito, y dejar de alimentar con información a empresas que ya no usas. Eso es una tarde de trabajo, y te pone por delante de la mayoría de los negocios de tu tamaño.</p>
<div style='background:linear-gradient(135deg,#091020 0%,#101E34 100%);border-left:6px solid #22D3EE;border-radius:6px;padding:28px 30px;margin:38px 0;'>
<p style='margin:0 0 10px;color:#F59E0B;font-weight:700;letter-spacing:.08em;text-transform:uppercase;font-size:13px;'>¿No sabes quién tiene tus datos?</p>
<p style='margin:0 0 20px;color:#E2E8F0;font-size:17px;line-height:1.6;'>Nos sentamos contigo, armamos juntos la lista de proveedores y te decimos con honestidad cuáles sí deberían preocuparte. Sin costo y sin presión.</p>
<p style='margin:0;'><a href='https://incognitocybersecurity.com/book-a-complimentary-visit/' style='display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;text-decoration:none;padding:13px 26px;border-radius:5px;'>Agenda una visita sin costo &rarr;</a></p>
</div>
<h2>Envíanos un mensaje</h2>
<p>¿Tienes dudas sobre algún proveedor, o quieres una segunda opinión sobre un contrato antes de firmarlo? Mándalo y te respondo personalmente.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_58_container">
			<label for="field_lot8t" >
				If you are human, leave this field blank.			</label>
			<input  id="field_lot8t" type="text" class="frm_form_field form-field frm_verify" name="item_meta[58]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCQfPA+5MD7w7ihsuDF6m1TCHHcZHI6EfsPqgJ9b9am1C" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p style='margin-top:30px;font-style:italic;color:#475569;'>&mdash; Nemuel Cruz, Incognito Cyber Security</p>
<div class='ics-author-bio' style='background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;'>
<p style='margin:0 0 8px;color:#F59E0B;font-weight:700;letter-spacing:.08em;text-transform:uppercase;font-size:12px;'>Sobre el autor</p>
<p style='margin:0 0 10px;font-size:19px;font-weight:700;color:#0F1E34;'>Nemuel Cruz</p>
<p style='margin:0 0 12px;color:#334155;line-height:1.65;'>Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style='margin:0;color:#334155;'>¿Preguntas sobre este artículo? Escríbeme a <a href='mailto:nemuel@incognitocybersecurity.com'>nemuel@incognitocybersecurity.com</a> o <a href='https://incognitocybersecurity.com/book-a-complimentary-visit/'>agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/brecha-de-proveedor-tus-datos/">Hackearon a tu proveedor. Tus datos se fueron con él.</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your Vendor Got Hacked. Your Data Went With It.</title>
		<link>https://incognitocybersecurity.com/blog/vendor-breach-your-data/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=vendor-breach-your-data</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 14:12:28 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/vendor-breach-your-data/</guid>

					<description><![CDATA[<p>A healthcare software vendor lost 9.5 million patient records. Its clients did nothing wrong. Here is how a small business gets a handle on vendor risk.</p>
The post <a href="https://incognitocybersecurity.com/blog/vendor-breach-your-data/">Your Vendor Got Hacked. Your Data Went With It.</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Your Vendor Got Hacked. Your Data Went With It.</h1>
<p class='ics-lang-switch' style='margin:0 0 26px;'><a href='https://incognitocybersecurity.com/blog/brecha-de-proveedor-tus-datos/' style='display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;text-decoration:none;padding:10px 20px;border-radius:5px;font-size:15px;'>🇲🇽 Leer en Español →</a></p>
<p>Last week a company most small business owners have never heard of had to tell 9.5 million people that their private information was stolen. The company is Aesto Health, based in Birmingham, Alabama. They do not treat patients. They do not run a clinic. They sell software that helps medical practices move old patient records around when they switch systems or buy another practice.</p>
<p>Attackers got into that company&#8217;s Amazon cloud environment and walked away with names, Social Security numbers, medical histories, billing records and insurance details belonging to patients at more than twenty different healthcare organizations. Those twenty organizations did nothing wrong. Their passwords were fine. Their firewalls were fine. They simply handed data to a vendor, which is something every business on earth does every single day.</p>
<p>That is the part I want you to sit with, because it applies to your business too.</p>
<h2>Your vendors are holding your data right now</h2>
<p>Take sixty seconds and count. Your payroll company has your employees&#8217; Social Security numbers. Your bookkeeper has your bank details. Your scheduling app has your customer list. Your marketing agency has your email database. Your CRM has every note you ever wrote about a client. Your file storage has your signed contracts.</p>
<p>Most owners I sit down with here in Tucson can name three vendors off the top of their head. When we actually walk through the credit card statement together, the real number is usually somewhere between fifteen and forty.</p>
<h3>Your customers do not call the vendor</h3>
<p>Here is the uncomfortable truth about a vendor breach: your customers do not know and do not care who your software provider is. They gave their information to <em>you</em>. When the notification letter goes out, your name is the one they remember, and your phone is the one that rings.</p>
<h3>Neither do regulators or your insurance carrier</h3>
<p>If you work in healthcare, finance, or law, you are usually still responsible for data you handed to somebody else. And if you carry cyber insurance, expect the carrier to ask what due diligence you performed on that vendor before you shared anything. &ldquo;I assumed they were secure&rdquo; is not an answer that pays a claim.</p>
<h2>This is not a rare event anymore</h2>
<p>Verizon&#8217;s 2026 Data Breach Investigations Report found that a third party was involved in 48% of all breaches, roughly double the share from the year before. Researchers tracking these incidents also found that for every vendor that gets breached, an average of five downstream companies are publicly exposed along with it.</p>
<p>Put plainly: one of the fastest growing ways to get hacked in 2026 is to not get hacked at all, and simply do business with somebody who did.</p>
<figure style='margin:34px 0;'><img src='https://incognitocybersecurity.com/wp-content/uploads/2026/09/vendor-breach-infographic-en.png' alt='Infographic with three cards: ask before you sign, limit what they hold, know your list' width='1200' height='640' style='max-width:100%;height:auto;border-radius:6px;' /></figure>
<h2>What you can do this week</h2>
<ol>
<li><strong>Build the list.</strong> Open your bank and credit card statements for the last twelve months and write down every software subscription and service provider you pay. That list is your real risk surface, and most owners are genuinely surprised by how long it is.</li>
<li><strong>Mark who holds the sensitive material.</strong> Star every vendor that touches customer records, employee records, or banking information. Those are the ones that matter. The rest can wait.</li>
<li><strong>Ask the starred vendors three questions.</strong> Do you require multi-factor authentication on my account? Is my data encrypted where you store it? How quickly will you notify me if you are breached? Ask by email so you have the answers in writing.</li>
<li><strong>Shut off what you stopped using.</strong> That trial you abandoned two years ago still has your data and probably still has an active login. Cancel it, and ask them in writing to delete what they hold.</li>
<li><strong>Decide who you would call.</strong> If a vendor emails you on a Tuesday afternoon to say they lost your data, who is your first call? Your attorney? Your insurance broker? Us? Decide that now, while nothing is on fire.</li>
</ol>
<h2>Where this connects to everything else</h2>
<p>Vendor risk is not a separate problem. It sits right next to the basics we handle for our <a href='https://incognitocybersecurity.com/small-business-cyber-security-solutions/'>small business clients</a> every day. Solid <a href='https://incognitocybersecurity.com/end-point-protection/'>endpoint protection</a> stops an attacker from using a stolen vendor login to spread onto your computers. Reliable <a href='https://incognitocybersecurity.com/secure-data-backups/'>secure data backups</a> mean you still have your records even when a vendor loses theirs. Good <a href='https://incognitocybersecurity.com/spam-virus-filtering/'>spam and virus filtering</a> catches the wave of phishing that always follows a big breach, when criminals use the stolen details to sound convincing. And <a href='https://incognitocybersecurity.com/cybersecurity-awareness-for-business/'>security awareness training</a> keeps your staff from becoming the weak link in somebody else&#8217;s supply chain.</p>
<p>It is the same lesson as <a href='https://incognitocybersecurity.com/blog/unpatched-software-open-door/'>the patching gap I wrote about last week</a>, and the same lesson in most of what I publish on <a href='https://incognitocybersecurity.com/blog/'>our blog</a>: the boring maintenance work is what keeps you out of the headlines.</p>
<h2>The bottom line</h2>
<p>You cannot audit a cloud provider the way a Fortune 500 company does, and you should not try. But you can know exactly who holds your data, ask them a few pointed questions in writing, and stop feeding information to companies you no longer use. That is an afternoon of work, and it puts you ahead of most businesses your size.</p>
<div style='background:linear-gradient(135deg,#091020 0%,#101E34 100%);border-left:6px solid #22D3EE;border-radius:6px;padding:28px 30px;margin:38px 0;'>
<p style='margin:0 0 10px;color:#F59E0B;font-weight:700;letter-spacing:.08em;text-transform:uppercase;font-size:13px;'>Not sure who has your data?</p>
<p style='margin:0 0 20px;color:#E2E8F0;font-size:17px;line-height:1.6;'>We will sit down with you, build the vendor list together, and tell you honestly which ones are worth worrying about. No charge and no pressure.</p>
<p style='margin:0;'><a href='https://incognitocybersecurity.com/book-a-complimentary-visit/' style='display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:700;text-decoration:none;padding:13px 26px;border-radius:5px;'>Book a complimentary visit &rarr;</a></p>
</div>
<h2>Send us a message</h2>
<p>Have a question about a vendor you are not sure about, or want a second opinion on a contract before you sign it? Send it over and I will get back to you personally.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="a8fc21b8fd2f794b28731df7b427e0ff">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="32eb7f1d65" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_59_container">
			<label for="field_ljvhj" >
				If you are human, leave this field blank.			</label>
			<input  id="field_ljvhj" type="text" class="frm_form_field form-field frm_verify" name="item_meta[59]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCR3QM8BRVBjpqIClcMzOwDGQN6Qelr8IiAUi+AyIELi1" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p style='margin-top:30px;font-style:italic;color:#475569;'>&mdash; Nemuel Cruz, Incognito Cyber Security</p>
<div class='ics-author-bio' style='background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;'>
<p style='margin:0 0 8px;color:#F59E0B;font-weight:700;letter-spacing:.08em;text-transform:uppercase;font-size:12px;'>About the author</p>
<p style='margin:0 0 10px;font-size:19px;font-weight:700;color:#0F1E34;'>Nemuel Cruz</p>
<p style='margin:0 0 12px;color:#334155;line-height:1.65;'>Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style='margin:0;color:#334155;'>Questions about this article? Email <a href='mailto:nemuel@incognitocybersecurity.com'>nemuel@incognitocybersecurity.com</a> or <a href='https://incognitocybersecurity.com/book-a-complimentary-visit/'>book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/vendor-breach-your-data/">Your Vendor Got Hacked. Your Data Went With It.</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
