<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Incognito CyberSecurity</title>
	<atom:link href="https://incognitocybersecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://incognitocybersecurity.com</link>
	<description></description>
	<lastBuildDate>Mon, 05 Oct 2026 14:10:15 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://incognitocybersecurity.com/wp-content/uploads/2025/01/favicon-150x150.png</url>
	<title>Incognito CyberSecurity</title>
	<link>https://incognitocybersecurity.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hackearon a tu Proveedor de Software. ¿Están tus Datos Ahí?</title>
		<link>https://incognitocybersecurity.com/blog/proveedor-software-hackeado-riesgo-pequenas-empresas/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=proveedor-software-hackeado-riesgo-pequenas-empresas</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 05 Oct 2026 14:10:15 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/proveedor-software-hackeado-riesgo-pequenas-empresas/</guid>

					<description><![CDATA[<p>Una plataforma de facturación con 600,000 clientes fue atacada. Qué significa el riesgo de proveedores para tu negocio y qué hacer esta semana.</p>
The post <a href="https://incognitocybersecurity.com/blog/proveedor-software-hackeado-riesgo-pequenas-empresas/">Hackearon a tu Proveedor de Software. ¿Están tus Datos Ahí?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Hackearon a tu Proveedor de Software. ¿Están tus Datos Ahí?</h1>
<p style="margin:0 0 8px;font-size:14px;"><a href="https://incognitocybersecurity.com/blog/software-vendor-breach-small-business-risk/">🇺🇸 Read this article in English</a></p>
<p>A finales del mes pasado, una plataforma polaca de facturación llamada Fakturownia informó a sus clientes que atacantes entraron a sus servidores. La empresa atiende a más de 600,000 negocios. Según <a href="https://therecord.media/poland-cyberattack-invoice-software" target="_blank" rel="noopener">The Record</a>, los datos expuestos incluyen detalles de cuentas de empresas, contraseñas cifradas, datos bancarios, tokens de acceso e integración, información de clientes y socios, y facturas antiguas.</p>
<p>Lo importante para ti es esto: ninguno de esos 600,000 negocios hizo algo mal. Le pagaron a una empresa de software para manejar sus facturas, y esa empresa fue atacada. Su información se robó de todos modos.</p>
<p>Eso es riesgo de proveedores, y es uno de los problemas que más se pasan por alto en las pequeñas empresas del sur de Arizona.</p>
<p><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/10/vendor-breach-infographic-es.png" alt="Lista de 3 preguntas para cada proveedor de software" style="max-width:100%;height:auto;border-radius:8px;margin:12px 0 24px;" /></p>
<h2>Eres tan seguro como tus proveedores</h2>
<p>Piensa en cada empresa que guarda una parte de tu negocio: tu software de contabilidad, tu herramienta de facturación, tu proveedor de nómina, tu CRM, el hosting de tu sitio web, tu plataforma de correo, tu almacenamiento en la nube, incluso quien administra tus teléfonos. Cada uno guarda copias de tus datos. Cada uno tiene accesos conectados a tus otras herramientas.</p>
<p>Es como una casa con una excelente cerradura en la puerta principal. Puedes invertir en la cerradura, pero si le das copias de la llave a diez empresas, dependes de que las diez las cuiden bien.</p>
<p>Los atacantes lo saben. ¿Para qué entrar a miles de pequeños negocios uno por uno si puedes entrar a un solo proveedor y llevarte a todos a la vez?</p>
<h2>Qué se roban realmente en el ataque a un proveedor</h2>
<h3>Los datos de tu negocio</h3>
<p>Facturas, nombres de clientes, datos bancarios y contratos. En el caso de Fakturownia, también se incluyó información de los clientes de los negocios que usan la plataforma, no solo de los negocios. Los datos de tus clientes pueden filtrarse a través de una empresa que ni conocen.</p>
<h3>Contraseñas y tokens de acceso</h3>
<p>Las contraseñas cifradas robadas pueden descifrarse, sobre todo si son débiles o repetidas. Los tokens y las claves API son aún más peligrosos porque funcionan como un gafete pre-aprobado: quien tiene uno muchas veces puede entrar a sistemas conectados sin escribir una contraseña.</p>
<h3>Datos para la siguiente estafa</h3>
<p>Los detalles reales de una factura hacen que un correo falso se vea totalmente real. Un criminal que sabe a quién le pagas, cuánto y cuándo puede enviar un mensaje convincente de &#8220;cambiamos de cuenta bancaria&#8221;. Esto suele aparecer semanas o meses después del ataque, cuando la noticia ya se olvidó.</p>
<h2>Por qué las pequeñas empresas se ven sorprendidas</h2>
<p>La mayoría de los dueños con quienes hablo no pueden enumerar todas las herramientas de software que usa su equipo. Alguien abrió una prueba gratis, alguien conectó una herramienta al correo de la empresa y nadie lo anotó. Esas cuentas olvidadas no se actualizan, no se revisan y a veces todavía tienen el acceso de un ex empleado.</p>
<p>Luego llega un aviso de ataque y tienes que responder una pregunta sencilla: ¿qué guardamos ahí? Muchos negocios no pueden responderla.</p>
<h2>Qué puedes hacer esta semana</h2>
<ol>
<li><strong>Haz una lista de proveedores.</strong> Anota cada empresa que guarda tus datos o se conecta a tus sistemas. Revisa los estados de cuenta de tu tarjeta para encontrar suscripciones, ahí se esconden las olvidadas.</li>
<li><strong>Marca las cinco principales.</strong> Señala las que manejan dinero, datos de clientes o de empleados. Esas se atienden primero.</li>
<li><strong>Activa acceso fuerte en todas.</strong> Usa autenticación de varios factores en cada cuenta y una contraseña única por proveedor, guardada en un administrador de contraseñas.</li>
<li><strong>Revisa y reduce las integraciones.</strong> Mira qué está conectado a qué. Elimina las claves API y conexiones que ya no uses, y cambia las que conserves.</li>
<li><strong>Haz tres preguntas.</strong> ¿Qué datos tienen de nosotros?, ¿cómo nos avisarán si sufren un ataque? y ¿cómo sacamos nuestros datos si nos vamos? Un buen proveedor responde rápido.</li>
<li><strong>Cuidado con estafas posteriores.</strong> Si un proveedor reporta un ataque, desconfía de cualquier cambio de pago hasta confirmarlo por teléfono con un número que ya tengas.</li>
<li><strong>Ten tu propia copia.</strong> Asegúrate de que tus registros clave tengan respaldo fuera del sistema del proveedor, para que un mal día de ellos no sea un mal día tuyo.</li>
</ol>
<h2>Si tu proveedor reporta un ataque</h2>
<p>No entres en pánico, pero tampoco lo ignores. Cambia las contraseñas de esa cuenta y de cualquier otra que use la misma. Revoca y reemplaza las claves API o apps conectadas. Busca accesos o mensajes enviados extraños. Luego avisa a tu equipo y a tus clientes si su información estuvo involucrada. Mientras más rápido cambies las claves, menos tiempo tiene un atacante para usarlas.</p>
<h2>Lo esencial</h2>
<p>No puedes evitar que hackeen a un proveedor. Sí puedes controlar qué guardas con él, qué tan bien protegida está la puerta a tu cuenta y qué tan rápido reaccionas cuando algo sale mal. Saber quién tiene tus datos es el primer paso, y la mayoría de los negocios no lo ha dado.</p>
<div style="background:#0B1220;border-left:6px solid #22D3EE;border-radius:8px;padding:24px 28px;margin:32px 0;color:#FFFFFF;">
<p style="font-size:20px;font-weight:700;margin:0 0 8px;color:#22D3EE;">¿No sabes quién tiene tus datos?</p>
<p style="margin:0 0 12px;color:#E2E8F0;">Ayudamos a pequeñas empresas a mapear sus proveedores, proteger sus cuentas con <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/" style="color:#22D3EE;">capacitación de seguridad para el personal</a> y a tener <a href="https://incognitocybersecurity.com/secure-data-backups/" style="color:#22D3EE;">respaldos de datos seguros</a> bajo su control. Conoce nuestras <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/" style="color:#22D3EE;">soluciones de ciberseguridad para pequeñas empresas</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="color:#F59E0B;font-weight:700;">agenda una visita sin costo</a>.</p>
<p style="margin:0;color:#9FB3C8;font-size:14px;">Relacionado: <a href="https://incognitocybersecurity.com/blog/acceso-robado-mfa-resistente-phishing-pequenas-empresas/" style="color:#22D3EE;">por qué tu MFA debe ser más fuerte</a> y la <a href="https://incognitocybersecurity.com/end-point-protection/" style="color:#22D3EE;">protección de equipos</a>. Más en nuestro <a href="https://incognitocybersecurity.com/blog/" style="color:#22D3EE;">blog</a>; un buen <a href="https://incognitocybersecurity.com/spam-virus-filtering/" style="color:#22D3EE;">filtro de spam y virus</a> ayuda a frenar las estafas posteriores.</p>
</div>
<h2>Envíanos un mensaje</h2>
<p>¿Tienes preguntas sobre tus proveedores o quieres ayuda para empezar tu lista? Escríbenos.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_50_container">
			<label for="field_i3ajj" >
				If you are human, leave this field blank.			</label>
			<input  id="field_i3ajj" type="text" class="frm_form_field form-field frm_verify" name="item_meta[50]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCdQdDgedHoy/ZA5Q41nfNdbJIrTpl/AML1hykTOMQsFL" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>Fuentes: <a href="https://therecord.media/poland-cyberattack-invoice-software" target="_blank" rel="noopener">The Record</a>; <a href="https://this.weekinsecurity.com/this-week-in-security-october-4-2026-edition" target="_blank" rel="noopener">This Week in Security</a>.</em></p>
<p>— Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<div style="font-size:12px;letter-spacing:.12em;text-transform:uppercase;color:#F59E0B;font-weight:700;margin-bottom:6px;">Sobre el autor</div>
<div style="font-size:19px;font-weight:700;color:#0F1E34;margin-bottom:8px;">Nemuel Cruz</div>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="color:#334155;margin:0;font-size:15px;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com" style="color:#0E7490;">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="color:#0E7490;">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/proveedor-software-hackeado-riesgo-pequenas-empresas/">Hackearon a tu Proveedor de Software. ¿Están tus Datos Ahí?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your Software Vendor Got Hacked. Is Your Data in the Pile?</title>
		<link>https://incognitocybersecurity.com/blog/software-vendor-breach-small-business-risk/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=software-vendor-breach-small-business-risk</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 05 Oct 2026 14:10:15 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/software-vendor-breach-small-business-risk/</guid>

					<description><![CDATA[<p>A Polish invoicing platform serving 600,000 businesses was breached. Here is what vendor risk means for your small business and what to do this week.</p>
The post <a href="https://incognitocybersecurity.com/blog/software-vendor-breach-small-business-risk/">Your Software Vendor Got Hacked. Is Your Data in the Pile?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Your Software Vendor Got Hacked. Is Your Data in the Pile?</h1>
<p style="margin:8px 0 22px;"><a href="https://incognitocybersecurity.com/blog/proveedor-software-hackeado-riesgo-pequenas-empresas/" style="display:inline-block;background:#22D3EE;color:#0B1220;font-weight:700;text-decoration:none;padding:8px 16px;border-radius:6px;font-size:15px;">🇲🇽 Leer en Español →</a></p>
<p>Late last month, a Polish invoicing platform called Fakturownia told its customers that attackers had gotten into its servers. The company serves more than 600,000 businesses. According to <a href="https://therecord.media/poland-cyberattack-invoice-software" target="_blank" rel="noopener">The Record</a>, the exposed data includes company account details, password hashes, bank account details, login and integration tokens, customer and partner information, and older invoices.</p>
<p>Here is the part that matters for you: none of those 600,000 businesses did anything wrong. They paid a software company to handle their invoices, and that company got hit. Their information was stolen anyway.</p>
<p>That is vendor risk, and it is one of the most overlooked problems I see in small businesses around Southern Arizona.</p>
<p><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/10/vendor-breach-infographic-en.png" alt="Checklist of 3 questions to ask every software vendor" style="max-width:100%;height:auto;border-radius:8px;margin:12px 0 24px;" /></p>
<h2>You Are Only as Safe as Your Vendors</h2>
<p>Think about every company that holds a piece of your business: your accounting software, your invoicing tool, your payroll provider, your CRM, your website host, your email platform, your cloud storage, even the company that manages your phones. Each one keeps copies of your data. Each one has logins that connect to your other tools.</p>
<p>It works like a house with a great front door lock. You can spend money on the lock, but if you hand spare keys to ten different companies, you are depending on all ten of them to keep those keys safe.</p>
<p>Attackers know this. Why break into thousands of small businesses one at a time when you can break into one vendor and collect all of them at once?</p>
<h2>What Actually Gets Stolen in a Vendor Breach</h2>
<h3>Your business data</h3>
<p>Invoices, customer names, bank details, and contracts. In the Fakturownia case, that included information about the customers of the businesses using the platform, not just the businesses themselves. Your customers&#8217; data can leak through a company they have never heard of.</p>
<h3>Passwords and login tokens</h3>
<p>Stolen password hashes can be cracked, especially weak or reused passwords. Tokens and API keys are even more dangerous because they act like a pre-approved badge: whoever holds one can often get into connected systems without typing a password at all.</p>
<h3>Details for the next scam</h3>
<p>Real invoice details make a fake email look completely real. A criminal who knows who you pay, how much, and when can send a convincing &#8220;we changed our bank account&#8221; message. This often shows up weeks or months after the breach, long after the news cycle has moved on.</p>
<h2>Why Small Businesses Get Caught Off Guard</h2>
<p>Most owners I talk to cannot list every software tool their team uses. Someone signed up for a free trial, someone connected a tool to the company email, and nobody wrote it down. Those forgotten accounts do not get updated, do not get reviewed, and often still have an ex-employee&#8217;s login attached.</p>
<p>Then a breach notice shows up, and you have to answer a simple question: what did we put in there? Many businesses cannot answer it.</p>
<h2>What You Can Do This Week</h2>
<ol>
<li><strong>List your vendors.</strong> Write down every company that stores your data or connects to your systems. Check your credit card statements for subscriptions, since that is where the forgotten ones hide.</li>
<li><strong>Mark the top five.</strong> Circle the ones that hold money, customer data, or employee data. Those get attention first.</li>
<li><strong>Turn on strong sign-in everywhere.</strong> Use multi-factor authentication on each account, and give every vendor a unique password stored in a password manager.</li>
<li><strong>Find and trim integrations.</strong> Look at what is connected to what. Remove API keys and app connections you no longer use, and rotate the ones you keep.</li>
<li><strong>Ask three questions.</strong> What data do you hold about us, how will you tell us if you are breached, and how do we get our data out if we leave? A good vendor answers these quickly.</li>
<li><strong>Watch for follow-up scams.</strong> If a vendor reports a breach, treat any payment change request from anyone as suspicious until you confirm it by phone using a number you already have.</li>
<li><strong>Keep your own copy.</strong> Make sure your key records are backed up outside the vendor&#8217;s system, so one bad day on their side does not become a bad day on yours.</li>
</ol>
<h2>If Your Vendor Reports a Breach</h2>
<p>Do not panic, and do not ignore it. Change the passwords for that account and anything that shares the password. Revoke and replace any API keys or connected apps. Check for strange logins or sent messages. Then warn your team and your customers if their information was involved. The faster you rotate the keys, the less time an attacker has to use them.</p>
<h2>The Bottom Line</h2>
<p>You cannot stop a vendor from being hacked. You can control what you store with them, how well their door to your account is locked, and how fast you react when something goes wrong. Knowing who holds your data is the first step, and most businesses have not taken it.</p>
<div style="background:#0B1220;border-left:6px solid #22D3EE;border-radius:8px;padding:24px 28px;margin:32px 0;color:#FFFFFF;">
<p style="font-size:20px;font-weight:700;margin:0 0 8px;color:#22D3EE;">Not sure who holds your data?</p>
<p style="margin:0 0 12px;color:#E2E8F0;">We help small businesses map their vendors, lock down accounts with <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/" style="color:#22D3EE;">staff security training</a>, and set up <a href="https://incognitocybersecurity.com/secure-data-backups/" style="color:#22D3EE;">secure data backups</a> you control. See our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/" style="color:#22D3EE;">small business cyber security solutions</a>, or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="color:#F59E0B;font-weight:700;">book a complimentary visit</a>.</p>
<p style="margin:0;color:#9FB3C8;font-size:14px;">Related: <a href="https://incognitocybersecurity.com/blog/stolen-login-phishing-resistant-mfa-small-business/" style="color:#22D3EE;">why your MFA needs to be stronger</a> and <a href="https://incognitocybersecurity.com/end-point-protection/" style="color:#22D3EE;">endpoint protection</a>. More on our <a href="https://incognitocybersecurity.com/blog/" style="color:#22D3EE;">blog</a>, and a good <a href="https://incognitocybersecurity.com/spam-virus-filtering/" style="color:#22D3EE;">spam and virus filter</a> helps catch the follow-up scams.</p>
</div>
<h2>Send us a message</h2>
<p>Have a question about your vendors or want help getting a list started? Send us a note.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_51_container">
			<label for="field_qzlcn" >
				If you are human, leave this field blank.			</label>
			<input  id="field_qzlcn" type="text" class="frm_form_field form-field frm_verify" name="item_meta[51]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCUC8iQ23MuvweKV5nzPDsN5zPHcmAk8SCMfQ0rXqUUSa" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>Sources: <a href="https://therecord.media/poland-cyberattack-invoice-software" target="_blank" rel="noopener">The Record</a>; <a href="https://this.weekinsecurity.com/this-week-in-security-october-4-2026-edition" target="_blank" rel="noopener">This Week in Security</a>.</em></p>
<p>— Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<div style="font-size:12px;letter-spacing:.12em;text-transform:uppercase;color:#F59E0B;font-weight:700;margin-bottom:6px;">About the author</div>
<div style="font-size:19px;font-weight:700;color:#0F1E34;margin-bottom:8px;">Nemuel Cruz</div>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="color:#334155;margin:0;font-size:15px;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com" style="color:#0E7490;">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="color:#0E7490;">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/software-vendor-breach-small-business-risk/">Your Software Vendor Got Hacked. Is Your Data in the Pile?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Un acceso robado pasa a otro hacker en 22 segundos: ¿tu MFA es lo bastante fuerte?</title>
		<link>https://incognitocybersecurity.com/blog/acceso-robado-mfa-resistente-phishing-pequenas-empresas/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=acceso-robado-mfa-resistente-phishing-pequenas-empresas</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 14:07:46 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/acceso-robado-mfa-resistente-phishing-pequenas-empresas/</guid>

					<description><![CDATA[<p>Los hackers ahora se pasan un acceso robado en segundos. Esto significa un MFA más fuerte para tu pequeña empresa, en lenguaje sencillo.</p>
The post <a href="https://incognitocybersecurity.com/blog/acceso-robado-mfa-resistente-phishing-pequenas-empresas/">Un acceso robado pasa a otro hacker en 22 segundos: ¿tu MFA es lo bastante fuerte?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Un acceso robado pasa a otro hacker en 22 segundos: ¿tu MFA es lo bastante fuerte?</h1>
<p><a href="https://incognitocybersecurity.com/blog/stolen-login-phishing-resistant-mfa-small-business/" style="font-size:14px;">🇺🇸 Read this article in English</a></p>
<p>Imagina esto: la contraseña de un empleado se filtra un martes. Antes de que termines tu café, otra banda de criminales ya tiene las llaves de tu correo. No días después. Segundos después. Así trabajan hoy las pequeñas empresas, y octubre, el Mes de la Concientización sobre Ciberseguridad, es buen momento para verlo con honestidad.</p>
<p><img fetchpriority="high" fetchpriority="high" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/10/ics-mfa-infographic-es.png" alt="Infografía: tres hábitos contra accesos robados - MFA resistente al phishing, proteger cinco acciones de riesgo, revisar herramientas de IA" width="1200" height="640" style="max-width:100%;height:auto;" /></p>
<h2>Los hackers ya no fuerzan la puerta. Entran con tu llave.</h2>
<p>Un <a href="https://www.forbes.com/sites/terdawn-deboe/2026/09/23/small-business-security-now-depends-on-what-happens-after-login/" target="_blank" rel="noopener nofollow">artículo reciente de Forbes sobre seguridad en pequeñas empresas</a> reunió cifras que me llamaron la atención. El equipo Mandiant de Google encontró que el tiempo entre que un atacante logra el primer acceso y se lo entrega a un segundo grupo criminal bajó a solo <strong>22 segundos en 2025</strong>. En 2022, esa entrega tardaba cerca de ocho horas. Piensa en una carrera de relevos donde el testigo es tu contraseña robada, y los corredores se han vuelto ridículamente rápidos.</p>
<p>El mismo artículo cita datos de Verizon 2026: <strong>el 96% de las víctimas de ransomware son pequeñas y medianas empresas</strong>, y en el <strong>38% de esos casos</strong> los atacantes tenían credenciales comprometidas. En palabras sencillas, no rompieron la ventana. Usaron una llave.</p>
<h3>Por qué tu MFA actual podría no bastar</h3>
<p>Probablemente ya usas autenticación de varios factores, o MFA: el código por mensaje de texto o el toque de &#8220;¿Aprobar este inicio de sesión?&#8221; en tu teléfono. Bien. Manténlo. El artículo de Forbes indica que el MFA moderno reduce más de un 99% el riesgo de que roben una identidad. Pero la palabra clave es &#8220;moderno&#8221;. Los criminales han aprendido a esquivar las versiones débiles:</p>
<ul>
<li><strong>Bombardeo de notificaciones:</strong> le llenan el teléfono a tu empleado con solicitudes de aprobación a las 11 de la noche hasta que un dedo cansado toca &#8220;Aprobar&#8221;.</li>
<li><strong>Páginas de inicio de sesión falsas:</strong> el empleado escribe la contraseña y el código en una copia convincente del sitio real, y el criminal usa ambos al instante. Cubrí una versión de esto en mi artículo sobre el <a href="https://incognitocybersecurity.com/blog/phishing-codigo-dispositivo-microsoft/">phishing de código de dispositivo</a>.</li>
<li><strong>Códigos por mensaje de texto:</strong> se los pueden sacar a las personas con engaños o interceptarlos.</li>
</ul>
<p>La opción más fuerte se llama <strong>MFA resistente al phishing</strong>: llaves de acceso (passkeys) o llaves de seguridad físicas. Solo funcionan en el sitio web verdadero, así que una página falsa no tiene nada que robar. Es la diferencia entre un código que alguien puede leer por encima de tu hombro y una llave que solo abre una cerradura.</p>
<h2>Protege los momentos que más importan</h2>
<p>No puedes vigilar cada clic de tu equipo, ni deberías intentarlo. En cambio, el artículo sugiere elegir una lista corta de acciones donde un extraño te costaría dinero de verdad. Para la mayoría de las oficinas pequeñas la lista se ve así:</p>
<ul>
<li>Cambiar una contraseña o el correo de recuperación</li>
<li>Agregar un nuevo administrador</li>
<li>Exportar tu lista de clientes</li>
<li>Cambiar datos de pago o de banco</li>
<li>Crear reglas de reenvío en un buzón de correo</li>
</ul>
<p>Para esas cinco, pide una verificación extra, como volver a iniciar sesión o una llamada a un número conocido, en lugar de molestar a la gente por cada cosa pequeña. Con demasiados avisos, las personas aprenden a aceptarlos todos sin leer.</p>
<h3>No olvides tus herramientas de IA</h3>
<p>Muchos negocios agregaron asistentes de IA este año, y algunos actúan dentro de sesiones ya iniciadas: leen correos, abren archivos, llenan formularios. El consejo del artículo es directo. Revisa cada herramienta de IA que hayas activado y pregunta a cada proveedor qué puede hacer dentro de una sesión iniciada y quién más puede acceder a ella. Si nadie sabe responder, esa es tu respuesta.</p>
<h2>Qué puedes hacer esta semana</h2>
<ol>
<li><strong>Activa el MFA en todas partes.</strong> Empieza con correo, banco, nómina y tu software de contabilidad.</li>
<li><strong>Cambia las cuentas de dueño y administrador a passkeys o llaves de seguridad.</strong> Son las cuentas que más quieren los criminales.</li>
<li><strong>Activa la coincidencia de números</strong> si tu aplicación la ofrece, para que un toque ciego en &#8220;Aprobar&#8221; no funcione.</li>
<li><strong>Anota tus cinco acciones de riesgo</strong> y decide qué verificación extra necesita cada una.</li>
<li><strong>Haz una lista de tus herramientas de IA</strong> y pregunta a los proveedores quién puede ver dentro de una sesión iniciada.</li>
<li><strong>Refuerza la defensa de tu correo.</strong> Un buen <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtro de spam y virus</a> detiene muchos correos que roban credenciales antes de que alguien los vea.</li>
<li><strong>Capacita a tu equipo en 15 minutos.</strong> Nuestra <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">capacitación de concientización en ciberseguridad</a> enseña a reportar una solicitud de aprobación extraña en lugar de tocarla.</li>
</ol>
<h2>La conclusión</h2>
<p>No puedes evitar que se filtre cada contraseña. Sí puedes lograr que una contraseña robada no sirva de nada. Un MFA fuerte, una lista corta de acciones protegidas y unas cuantas preguntas honestas a tus proveedores de software harán más que cualquier herramienta de monitoreo sofisticada. Si quieres ayuda para saber en qué punto estás, nuestras <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">soluciones de ciberseguridad para pequeñas empresas</a> y la <a href="https://incognitocybersecurity.com/end-point-protection/">protección de endpoints</a> cubren esto, y encontrarás más consejos en lenguaje sencillo en <a href="https://incognitocybersecurity.com/blog/">nuestro blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin:32px 0;color:#FFFFFF;">
<p style="margin:0 0 10px;font-size:20px;font-weight:700;color:#22D3EE;">¿No estás seguro de qué tan fuertes son tus accesos?</p>
<p style="margin:0 0 14px;color:#FFFFFF;">Revisaremos cómo inicia sesión tu equipo, encontraremos los puntos débiles y te daremos un plan sencillo para corregirlos. Sin presión, sin tecnicismos.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="background:#22D3EE;color:#0F1E34;padding:12px 22px;border-radius:6px;font-weight:700;text-decoration:none;display:inline-block;">Agenda una visita sin costo</a></p>
</div>
<h2>Envíanos un mensaje</h2>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_52_container">
			<label for="field_mjt0v" >
				If you are human, leave this field blank.			</label>
			<input  id="field_mjt0v" type="text" class="frm_form_field form-field frm_verify" name="item_meta[52]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCY5nF3/ND3YxHUoYI5fD7vIKqSkNI8AxMTBMDJ6pY2Bm" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>Fuente: <a href="https://www.forbes.com/sites/terdawn-deboe/2026/09/23/small-business-security-now-depends-on-what-happens-after-login/" target="_blank" rel="noopener nofollow">Forbes: Small Business Security Now Depends On What Happens After Login</a> (cifras de Mandiant y Verizon según se citan allí).</em></p>
<p>— Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<div style="font-size:12px;letter-spacing:1.5px;text-transform:uppercase;color:#F59E0B;font-weight:700;margin-bottom:6px;">Sobre el autor</div>
<div style="font-size:19px;font-weight:700;color:#0F1E34;margin-bottom:8px;">Nemuel Cruz</div>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="color:#334155;margin:0;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/acceso-robado-mfa-resistente-phishing-pequenas-empresas/">Un acceso robado pasa a otro hacker en 22 segundos: ¿tu MFA es lo bastante fuerte?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Stolen Login Gets Handed Off in 22 Seconds: Is Your MFA Strong Enough?</title>
		<link>https://incognitocybersecurity.com/blog/stolen-login-phishing-resistant-mfa-small-business/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=stolen-login-phishing-resistant-mfa-small-business</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 14:07:45 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/stolen-login-phishing-resistant-mfa-small-business/</guid>

					<description><![CDATA[<p>Hackers now hand off a stolen login in seconds. Here is what stronger MFA means for your small business, in plain English.</p>
The post <a href="https://incognitocybersecurity.com/blog/stolen-login-phishing-resistant-mfa-small-business/">A Stolen Login Gets Handed Off in 22 Seconds: Is Your MFA Strong Enough?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>A Stolen Login Gets Handed Off in 22 Seconds: Is Your MFA Strong Enough?</h1>
<p><a href="https://incognitocybersecurity.com/blog/acceso-robado-mfa-resistente-phishing-pequenas-empresas/" style="background:#22D3EE;color:#0F1E34;padding:10px 18px;border-radius:6px;font-weight:700;text-decoration:none;display:inline-block;">🇲🇽 Leer en Español →</a></p>
<p>Picture this: an employee&#8217;s password leaks on a Tuesday. By the time you finish your coffee, a different criminal gang already owns the keys to your email. Not days later. Seconds later. That is the world small businesses are working in right now, and October, Cybersecurity Awareness Month, is a good time to look at it honestly.</p>
<p><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/10/ics-mfa-infographic-en.png" alt="Infographic: three habits that shut the door on stolen logins - phishing-resistant MFA, guard five risky actions, audit your AI tools" width="1200" height="640" style="max-width:100%;height:auto;" /></p>
<h2>Hackers do not break in anymore. They log in.</h2>
<p>A recent <a href="https://www.forbes.com/sites/terdawn-deboe/2026/09/23/small-business-security-now-depends-on-what-happens-after-login/" target="_blank" rel="noopener nofollow">Forbes piece on small business security</a> pulled together some numbers that stuck with me. Google&#8217;s Mandiant team found that the time between an attacker getting initial access and handing it to a second criminal group dropped to just <strong>22 seconds in 2025</strong>. In 2022, that handoff took about eight hours. Think of it like a relay race where the baton is your stolen password, and the runners have gotten very, very fast.</p>
<p>The same article cites Verizon&#8217;s 2026 data: <strong>96% of ransomware victims are small and midsize businesses</strong>, and in <strong>38% of those cases</strong> the attackers had compromised credentials. In plain English, they did not smash a window. They used a key.</p>
<h3>Why your current MFA might not be enough</h3>
<p>You probably already use multi-factor authentication, or MFA: the text code or the &#8220;Approve this sign-in?&#8221; tap on your phone. Good. Keep it. The Forbes article notes that modern MFA cuts the risk of identity compromise by more than 99%. But &#8220;modern&#8221; is the key word. Criminals have learned to work around the weak versions:</p>
<ul>
<li><strong>Push bombing:</strong> they spam your employee with approval requests at 11 p.m. until one tired thumb taps &#8220;Approve.&#8221;</li>
<li><strong>Fake login pages:</strong> the employee types the password and the code into a convincing copy of the real site, and the criminal uses both instantly. I covered a version of this in my post on <a href="https://incognitocybersecurity.com/blog/device-code-phishing-microsoft-login/">device-code phishing</a>.</li>
<li><strong>Text-message codes:</strong> these can be tricked out of people or intercepted.</li>
</ul>
<p>The stronger option is called <strong>phishing-resistant MFA</strong>: passkeys or physical security keys. They only work on the real website, so there is nothing for a fake page to steal. It is the difference between a code someone can read over your shoulder and a key that only fits one lock.</p>
<h2>Protect the moments that matter most</h2>
<p>You cannot watch every click your team makes, and you should not try. Instead, the article suggests picking a short list of actions where a stranger doing them would cost you real money. For most small offices that list looks like this:</p>
<ul>
<li>Changing a password or recovery email</li>
<li>Adding a new administrator</li>
<li>Exporting your client list</li>
<li>Changing payment or bank details</li>
<li>Creating forwarding rules on a mailbox</li>
</ul>
<p>For those five, ask for an extra check, such as a fresh sign-in or a call-back to a known phone number, instead of nagging people about every little thing. Too many prompts and people learn to click through them all.</p>
<h3>Do not forget your AI tools</h3>
<p>Many businesses added AI assistants this year, and some of those tools act inside logged-in sessions: reading email, opening files, filling in forms. The article&#8217;s advice is blunt. Review every AI tool you have turned on, and ask each vendor what it can do inside a signed-in session and who else can reach it. If nobody can answer, that is your answer.</p>
<h2>What you can do this week</h2>
<ol>
<li><strong>Turn on MFA everywhere.</strong> Start with email, banking, payroll, and your accounting software.</li>
<li><strong>Switch your owner and admin accounts to passkeys or security keys.</strong> Those are the accounts criminals want most.</li>
<li><strong>Turn on number matching</strong> if your app offers it, so a blind &#8220;Approve&#8221; tap does not work.</li>
<li><strong>Write down your five risky actions</strong> and decide what extra check each one needs.</li>
<li><strong>List your AI tools</strong> and ask vendors who can see inside a signed-in session.</li>
<li><strong>Tighten your email defenses.</strong> Good <a href="https://incognitocybersecurity.com/spam-virus-filtering/">spam and virus filtering</a> stops many credential-stealing emails before anyone sees them.</li>
<li><strong>Train your team in 15 minutes.</strong> Our <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">cybersecurity awareness training</a> teaches people to report an odd approval request instead of tapping it.</li>
</ol>
<h2>The bottom line</h2>
<p>You cannot stop every password from leaking. You can make a stolen password useless. Strong MFA, a short list of guarded actions, and a few honest questions to your software vendors will do more than any fancy monitoring tool. If you want help sorting out where you stand, our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">small business cyber security solutions</a> and <a href="https://incognitocybersecurity.com/end-point-protection/">endpoint protection</a> cover this, and you can find more plain-English tips on <a href="https://incognitocybersecurity.com/blog/">our blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin:32px 0;color:#FFFFFF;">
<p style="margin:0 0 10px;font-size:20px;font-weight:700;color:#22D3EE;">Not sure how strong your logins really are?</p>
<p style="margin:0 0 14px;color:#FFFFFF;">We will review how your team signs in, find the weak spots, and give you a simple plan to fix them. No pressure, no jargon.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="background:#22D3EE;color:#0F1E34;padding:12px 22px;border-radius:6px;font-weight:700;text-decoration:none;display:inline-block;">Book a complimentary visit</a></p>
</div>
<h2>Send us a message</h2>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_53_container">
			<label for="field_q1sr" >
				If you are human, leave this field blank.			</label>
			<input  id="field_q1sr" type="text" class="frm_form_field form-field frm_verify" name="item_meta[53]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCeKms10fvcAcmXChLCSf0ndWTbRBdTf+l1FcYuciLKot" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>Source: <a href="https://www.forbes.com/sites/terdawn-deboe/2026/09/23/small-business-security-now-depends-on-what-happens-after-login/" target="_blank" rel="noopener nofollow">Forbes: Small Business Security Now Depends On What Happens After Login</a> (Mandiant and Verizon figures as cited there).</em></p>
<p>— Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<div style="font-size:12px;letter-spacing:1.5px;text-transform:uppercase;color:#F59E0B;font-weight:700;margin-bottom:6px;">About the author</div>
<div style="font-size:19px;font-weight:700;color:#0F1E34;margin-bottom:8px;">Nemuel Cruz</div>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="color:#334155;margin:0;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/stolen-login-phishing-resistant-mfa-small-business/">A Stolen Login Gets Handed Off in 22 Seconds: Is Your MFA Strong Enough?</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>13 de octubre: la fecha límite de Microsoft que puede dejar tu negocio expuesto</title>
		<link>https://incognitocybersecurity.com/blog/fecha-limite-13-octubre-windows-10-office-2021/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=fecha-limite-13-octubre-windows-10-office-2021</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 14:07:10 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/fecha-limite-13-octubre-windows-10-office-2021/</guid>

					<description><![CDATA[<p>El 13 de octubre termina el primer año de ESU de Windows 10 y el soporte de Office 2021. Qué significa y qué hacer esta semana.</p>
The post <a href="https://incognitocybersecurity.com/blog/fecha-limite-13-octubre-windows-10-office-2021/">13 de octubre: la fecha límite de Microsoft que puede dejar tu negocio expuesto</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>13 de octubre: la fecha límite de Microsoft que puede dejar tu negocio expuesto</h1>
<p style="font-size:14px;"><a href="https://incognitocybersecurity.com/blog/windows-10-office-2021-deadline-october-13/">🇺🇸 Read this article in English</a></p>
<p>Una pregunta rápida: ¿cuántas computadoras de tu oficina siguen usando Windows 10? Si tuviste que detenerte a contarlas, sigue leyendo. El <strong>13 de octubre</strong> llega una segunda fecha límite de Microsoft, y afecta tanto a tus PCs como al Office que tu equipo usa todos los días.</p>
<p><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-win10-infographic-es.png" alt="Infografía: tres cosas que cambian el 13 de octubre — termina el año 1 de ESU, Office 2021 pierde soporte, el año 2 cuesta el doble" width="1200" height="640" style="max-width:100%;height:auto;" /></p>
<h2>Qué pasa exactamente el 13 de octubre</h2>
<p>Windows 10 perdió su soporte regular en octubre de 2025. Desde entonces, los negocios que querían seguir recibiendo parches de seguridad tuvieron que pagar por las Actualizaciones de Seguridad Extendidas, conocidas como ESU. Piensa en ESU como pagarle a un mecánico para mantener en la calle una camioneta vieja después de que el fabricante dejó de hacer refacciones. Funciona, pero solo mientras sigas pagando, y la cuenta sube cada año.</p>
<p>Según la <a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates" target="_blank" rel="noopener">propia documentación de Microsoft</a>, el primer año de cobertura ESU para negocios termina este octubre. El año uno costó $61 por equipo. El año dos cuesta $122 por equipo y el año tres, $244.</p>
<h3>La trampa: no puedes saltarte un año</h3>
<p>ESU es acumulativo. Si nunca te inscribiste y decides hacerlo ahora, Microsoft indica que también debes pagar el año uno. Son aproximadamente $183 por computadora antes de recibir un solo parche del año dos. Para una oficina con 15 PCs viejas, eso es cerca de $2,750, y seguirías usando equipos que ya están al límite.</p>
<h3>Office 2021 tiene su propia fecha</h3>
<p>Ese mismo día, <a href="https://learn.microsoft.com/en-us/lifecycle/announcements/office-ltsc-2021-end-of-support" target="_blank" rel="noopener">Microsoft termina el soporte de Office LTSC 2021</a>. No más correcciones, no más actualizaciones de seguridad. Si tu equipo usa la versión de pago único de Office 2021, Word, Excel y Outlook se vuelven un blanco fácil al día siguiente.</p>
<h2>Por qué importa más de lo que parece</h2>
<p>A los hackers les encanta el software sin soporte. Cada falla nueva que se descubre después de la fecha se queda abierta para siempre, y los criminales saben exactamente qué negocios siguen usando versiones viejas. No necesitan ser ingeniosos. Solo esperan a que aparezca un hueco nuevo y buscan en internet las oficinas que nunca lo parcharon.</p>
<p>Los riesgos para un pequeño negocio son muy prácticos:</p>
<ul>
<li><strong>Ransomware:</strong> las PCs sin parches son una entrada común. Si leíste mi artículo sobre <a href="https://incognitocybersecurity.com/blog/firewall-vpn-sin-actualizar-riesgo-pequenas-empresas/">por qué el equipo que &#8220;se instala y se olvida&#8221; atrae a los atacantes</a>, esta es la misma historia.</li>
<li><strong>Seguro cibernético:</strong> muchas aseguradoras preguntan si usas software sin soporte. Una respuesta equivocada, o un reclamo negado, puede costar mucho más que computadoras nuevas.</li>
<li><strong>Programas que dejan de funcionar:</strong> tu contabilidad, tus sistemas del negocio y tus herramientas de seguridad también dejarán de dar soporte a Windows viejo.</li>
</ul>
<h2>Qué puedes hacer esta semana</h2>
<ol>
<li><strong>Cuenta tus computadoras.</strong> Haz una lista de cada PC, incluida la de la oficina de atrás que nadie recuerda, y anota si usa Windows 10 o Windows 11.</li>
<li><strong>Revisa cuáles pueden actualizarse.</strong> La mayoría de las computadoras compradas en los últimos cuatro o cinco años pueden pasar a Windows 11 sin costo. Las más viejas quizá no califiquen.</li>
<li><strong>Encuentra tu versión de Office.</strong> Abre cualquier aplicación de Office, ve a Archivo y luego Cuenta. Si dice Office 2021 o LTSC 2021, ponla en tu lista de actualización.</li>
<li><strong>Decide: actualizar, reemplazar o pagar ESU.</strong> ESU es un puente corto, no un plan. Reemplazar una PC de cinco años suele costar menos que dos años más de parches.</li>
<li><strong>Protege lo que aún no puedes reemplazar.</strong> Las máquinas viejas que deban quedarse tienen que estar aísladas, contar con buena <a href="https://incognitocybersecurity.com/end-point-protection/">protección de endpoints</a> y nunca guardar la única copia de algo.</li>
<li><strong>Verifica tus respaldos.</strong> Antes de cualquier actualización, confirma que tus <a href="https://incognitocybersecurity.com/secure-data-backups/">respaldos de datos seguros</a> realmente se restauran.</li>
<li><strong>Avisa a tu equipo.</strong> Las actualizaciones cambian cómo se ven las pantallas, y a los estafadores les encanta eso. Un repaso rápido de <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">concientización</a> y un buen <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtro de spam y virus</a> ayudan a frenar correos falsos de &#8220;actualiza ahora&#8221;.</li>
</ol>
<h2>En resumen</h2>
<p>El 13 de octubre no es una fecha de desastre. Tus computadoras no dejarán de funcionar. Lo que cambia es que Microsoft deja de arreglar problemas nuevos y los atacantes siguen encontrándolos. Un pequeño negocio que planea esto ahora paga un costo predecible y único. Quien espera paga más, y a veces paga después de una brecha. Si quieres ver el panorama completo, nuestra página de <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">soluciones de ciberseguridad para pequeños negocios</a> muestra cómo lo manejamos con nuestros clientes, y puedes leer más consejos en lenguaje sencillo en <a href="https://incognitocybersecurity.com/blog/">nuestro blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin:32px 0;color:#FFFFFF;">
<p style="margin:0 0 10px;font-size:20px;font-weight:700;color:#22D3EE;">¿No sabes cuáles de tus PCs están en riesgo?</p>
<p style="margin:0 0 14px;color:#FFFFFF;">Recorremos tu oficina, listamos cada equipo y versión de Office, y te damos un plan de actualización sencillo con costos reales. Sin presión y sin jerga.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="background:#22D3EE;color:#0F1E34;padding:12px 22px;border-radius:6px;font-weight:700;text-decoration:none;display:inline-block;">Agenda una visita sin costo</a></p>
</div>
<h2>Envíanos un mensaje</h2>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_54_container">
			<label for="field_jpyjs" >
				If you are human, leave this field blank.			</label>
			<input  id="field_jpyjs" type="text" class="frm_form_field form-field frm_verify" name="item_meta[54]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCQKIKKKz28Ut9edgfF5p6IekvscbyQ1Om6z9/3SUYmo6" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>Fuentes: <a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates" target="_blank" rel="noopener">Microsoft Learn: programa ESU de Windows 10</a>; <a href="https://learn.microsoft.com/en-us/lifecycle/announcements/office-ltsc-2021-end-of-support" target="_blank" rel="noopener">Microsoft Lifecycle: fin de soporte de Office LTSC 2021</a>.</em></p>
<p>— Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<div style="font-size:12px;letter-spacing:1.5px;text-transform:uppercase;color:#F59E0B;font-weight:700;margin-bottom:6px;">Sobre el autor</div>
<div style="font-size:19px;font-weight:700;color:#0F1E34;margin-bottom:8px;">Nemuel Cruz</div>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="color:#334155;margin:0;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/fecha-limite-13-octubre-windows-10-office-2021/">13 de octubre: la fecha límite de Microsoft que puede dejar tu negocio expuesto</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>October 13: The Microsoft Deadline That Could Leave Your Business Exposed</title>
		<link>https://incognitocybersecurity.com/blog/windows-10-office-2021-deadline-october-13/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=windows-10-office-2021-deadline-october-13</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 14:07:09 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/windows-10-office-2021-deadline-october-13/</guid>

					<description><![CDATA[<p>Windows 10 business ESU year one and Office 2021 support both end October 13. Here is what it means and what to do this week.</p>
The post <a href="https://incognitocybersecurity.com/blog/windows-10-office-2021-deadline-october-13/">October 13: The Microsoft Deadline That Could Leave Your Business Exposed</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>October 13: The Microsoft Deadline That Could Leave Your Business Exposed</h1>
<p><a href="https://incognitocybersecurity.com/blog/fecha-limite-13-octubre-windows-10-office-2021/" style="background:#22D3EE;color:#0F1E34;padding:10px 18px;border-radius:6px;font-weight:700;text-decoration:none;display:inline-block;">🇲🇽 Leer en Español →</a></p>
<p>Quick question: how many computers in your office are still running Windows 10? If you just paused to count, keep reading. A second Microsoft deadline lands on <strong>October 13</strong>, and it affects both your PCs and the Office software your team uses every day.</p>
<p><img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-win10-infographic-en.png" alt="Infographic: three things that change on October 13 — Windows 10 ESU year 1 ends, Office 2021 loses support, ESU year 2 costs double" width="1200" height="640" style="max-width:100%;height:auto;" /></p>
<h2>What actually happens on October 13</h2>
<p>Windows 10 officially lost regular support in October 2025. Since then, businesses that wanted to keep getting security patches had to pay for something called Extended Security Updates, or ESU. Think of ESU like paying a mechanic to keep an old truck on the road after the manufacturer stopped making parts. It works, but only as long as you keep paying, and the bill goes up every year.</p>
<p>According to <a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates" target="_blank" rel="noopener">Microsoft&#8217;s own documentation</a>, the first year of business ESU coverage ends this October. Year one cost $61 per device. Year two costs $122 per device, and year three costs $244.</p>
<h3>The catch: you cannot skip a year</h3>
<p>ESU is cumulative. If you never enrolled and decide to sign up now, Microsoft says you have to pay for year one too. That is roughly $183 per computer before you get a single year-two patch. For an office with 15 older PCs, that is close to $2,750, and you would still be running unsupported-by-default hardware.</p>
<h3>Office 2021 has its own deadline</h3>
<p>On the same day, <a href="https://learn.microsoft.com/en-us/lifecycle/announcements/office-ltsc-2021-end-of-support" target="_blank" rel="noopener">Microsoft ends support for Office LTSC 2021</a>. No more bug fixes, no more security updates. If your team uses the one-time-purchase version of Office 2021, Word, Excel, and Outlook become a soft target the day after.</p>
<h2>Why this matters more than it sounds</h2>
<p>Hackers love end-of-life software. Every new flaw found after the deadline stays open forever, and criminals know exactly which businesses are still running old versions. They do not need to be clever. They just wait for a newly discovered hole and scan the internet for offices that never patched it.</p>
<p>The risks for a small business are very practical:</p>
<ul>
<li><strong>Ransomware:</strong> unpatched PCs are a common way in. If you have read my post on <a href="https://incognitocybersecurity.com/blog/unpatched-firewall-vpn-small-business-risk/">why set-it-and-forget-it gear attracts attackers</a>, this is the same story.</li>
<li><strong>Cyber insurance:</strong> many carriers ask whether you run unsupported software. A wrong answer, or a denied claim, can cost far more than new computers.</li>
<li><strong>Software that stops working:</strong> your accounting, line-of-business, and security tools will eventually drop support for old Windows too.</li>
</ul>
<h2>What you can do this week</h2>
<ol>
<li><strong>Count your computers.</strong> List every PC, including the back-office one nobody thinks about, and note whether it runs Windows 10 or Windows 11.</li>
<li><strong>Check which PCs can upgrade.</strong> Most computers bought in the last four or five years can move to Windows 11 for free. Older ones may not qualify.</li>
<li><strong>Find your Office version.</strong> Open any Office app, go to File, then Account. If it says Office 2021 or LTSC 2021, put it on your upgrade list.</li>
<li><strong>Decide: upgrade, replace, or pay for ESU.</strong> ESU is a short bridge, not a plan. Replacing a five-year-old PC is usually cheaper than two more years of patches.</li>
<li><strong>Protect what you cannot replace yet.</strong> Old machines that must stay should be isolated, have good <a href="https://incognitocybersecurity.com/end-point-protection/">endpoint protection</a>, and never hold your only copy of anything.</li>
<li><strong>Verify your backups.</strong> Before any upgrade, confirm your <a href="https://incognitocybersecurity.com/secure-data-backups/">secure data backups</a> actually restore.</li>
<li><strong>Warn your team.</strong> Upgrades change how screens look, and scammers love that. A quick <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">awareness refresher</a> and solid <a href="https://incognitocybersecurity.com/spam-virus-filtering/">spam and virus filtering</a> help stop fake &#8220;update now&#8221; emails.</li>
</ol>
<h2>The bottom line</h2>
<p>October 13 is not a disaster date. Your computers will not stop working. What changes is that Microsoft stops fixing new problems, and attackers keep finding them. A small business that plans this now pays a predictable, one-time cost. One that waits pays more, and sometimes pays after a breach. If you want the bigger picture, our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">small business cyber security solutions</a> page shows how we handle this for clients, and you can always browse more plain-English tips on <a href="https://incognitocybersecurity.com/blog/">our blog</a>.</p>
<div style="background:#0F1E34;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin:32px 0;color:#FFFFFF;">
<p style="margin:0 0 10px;font-size:20px;font-weight:700;color:#22D3EE;">Not sure which of your PCs are at risk?</p>
<p style="margin:0 0 14px;color:#FFFFFF;">We will walk through your office, list every device and Office version, and give you a simple upgrade plan with real costs. No pressure, no jargon.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="background:#22D3EE;color:#0F1E34;padding:12px 22px;border-radius:6px;font-weight:700;text-decoration:none;display:inline-block;">Book a complimentary visit</a></p>
</div>
<h2>Send us a message</h2>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_55_container">
			<label for="field_22geq" >
				If you are human, leave this field blank.			</label>
			<input  id="field_22geq" type="text" class="frm_form_field form-field frm_verify" name="item_meta[55]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCeSG9SNLgBo9WBGO9eVXxrQfmQ/BDTMKjD0VgUX/BsqO" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p><em>Sources: <a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates" target="_blank" rel="noopener">Microsoft Learn: Windows 10 ESU program</a>; <a href="https://learn.microsoft.com/en-us/lifecycle/announcements/office-ltsc-2021-end-of-support" target="_blank" rel="noopener">Microsoft Lifecycle: Office LTSC 2021 end of support</a>.</em></p>
<p>— Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<div style="font-size:12px;letter-spacing:1.5px;text-transform:uppercase;color:#F59E0B;font-weight:700;margin-bottom:6px;">About the author</div>
<div style="font-size:19px;font-weight:700;color:#0F1E34;margin-bottom:8px;">Nemuel Cruz</div>
<p style="color:#334155;margin:0 0 12px;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="color:#334155;margin:0;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/windows-10-office-2021-deadline-october-13/">October 13: The Microsoft Deadline That Could Leave Your Business Exposed</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Por Qué el Equipo de Seguridad que &#8220;Se Instala y se Olvida&#8221; Es Justo lo que Buscan los Hackers</title>
		<link>https://incognitocybersecurity.com/blog/firewall-vpn-sin-actualizar-riesgo-pequenas-empresas/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=firewall-vpn-sin-actualizar-riesgo-pequenas-empresas</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 14:20:41 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/firewall-vpn-sin-actualizar-riesgo-pequenas-empresas/</guid>

					<description><![CDATA[<p>Los hackers están explotando activamente firewalls y VPN sin actualizar de marcas importantes. Por qué la gestión de parches importa para toda pyme esta semana.</p>
The post <a href="https://incognitocybersecurity.com/blog/firewall-vpn-sin-actualizar-riesgo-pequenas-empresas/">Por Qué el Equipo de Seguridad que “Se Instala y se Olvida” Es Justo lo que Buscan los Hackers</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Por Qué el Equipo de Seguridad que &#8220;Se Instala y se Olvida&#8221; Es Justo lo que Buscan los Hackers</h1>
<p><a href="https://incognitocybersecurity.com/blog/unpatched-firewall-vpn-small-business-risk/">&#127482;&#127480; Read this article in English</a></p>
<p>El 22 de septiembre, CISA e investigadores de seguridad confirmaron que hackers estaban entrando activamente a firewalls y equipos de acceso remoto de dos de las marcas más grandes en seguridad empresarial &mdash; Check Point y F5 &mdash; usando fallas para las que los fabricantes ya habían publicado parches. Los atacantes no estaban forzando cerraduras. Estaban entrando por puertas que llevaban meses sin cerrarse con llave.</p>
<p>Probablemente usted no tenga equipo Check Point o F5. La mayoría de los negocios con los que trabajo en el sur de Arizona no lo tienen. Pero la historia detrás de este ataque es la misma que se repite en redes más pequeñas cada semana, y vale la pena tomarse cinco minutos para entender por qué.</p>
<h2>Qué Pasó Exactamente</h2>
<p>CISA agregó cuatro vulnerabilidades a su catálogo de Vulnerabilidades Explotadas Conocidas la semana pasada, incluyendo dos fallas de Check Point y una en el sistema de acceso BIG-IP de F5. Dos obtuvieron una puntuación perfecta de 10 sobre 10 en la escala de severidad de la industria &mdash; un atacante que encuentra un dispositivo sin actualizar puede tomar control total de él de forma remota, sin contraseña y sin que nadie dentro del negocio haga clic en nada. Desde ahí, tienen un camino directo hacia el resto de la red.</p>
<h3>Por Qué Esto Importa Aunque Nunca Haya Oído de Estos Productos</h3>
<p>La marca no es lo importante. El patrón sí: un fabricante descubre una falla, publica una solución y emite una advertencia &mdash; y días después ocurren ataques reales porque muchos negocios nunca instalaron la actualización. No importa si el dispositivo es un firewall empresarial de $40,000 dólares o un router de $150 comprado en una tienda grande. Si está conectado a internet y no está actualizado, es un blanco con el nombre de su negocio escrito encima.</p>
<h2>El Verdadero Problema No Es el Software &mdash; Es el Silencio</h2>
<p>Esto es lo que veo una y otra vez con los dueños de negocio: nadie decidió dejar de actualizar. Simplemente nunca hizo ruido. Su punto de venta, su router, la laptop de su contadora &mdash; ninguno suena una alarma cuando una actualización lleva meses de retraso. Todo parece funcionar bien, hasta que deja de funcionar. Los atacantes cuentan con que &#8220;sigue funcionando&#8221; y &#8220;sigue siendo seguro&#8221; se sientan como lo mismo, cuando en realidad no se parecen en nada.</p>
<h3>El Software Viejo Tiene una Fecha de Caducidad Silenciosa</h3>
<p>El software que llegó al final de su vida útil &mdash; una versión vieja de Windows, una plataforma de punto de venta antigua, un plugin que nadie ha tocado en años &mdash; deja de recibir parches de seguridad por completo. Se siguen descubriendo vulnerabilidades nuevas, pero el fabricante ya no envía la solución. Ese software no se vuelve más seguro por quedarse quieto; se vuelve más peligroso cada mes que se ignora, porque es la puerta que ya nadie vigila. Si alguna computadora de su oficina todavía usa un sistema operativo que su fabricante dejó de soportar, eso es lo primero que vale la pena revisar esta semana &mdash; nuestros <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">recursos de concientización en ciberseguridad</a> explican cómo detectarlo.</p>
<figure style="margin:32px 0;"><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-infographic-unpatched-firewall-es.png" alt="Infografia con 3 puntos clave sobre por que el equipo sin actualizar y el software obsoleto son un riesgo mayor para pequenas empresas" style="max-width:100%;height:auto;border-radius:8px;" /></figure>
<h2>Qué Buscan Realmente los Hackers</h2>
<p>Cuando una vulnerabilidad como estas se hace pública, herramientas de escaneo automatizado recorren internet buscando dispositivos sin actualizar en cuestión de horas, no semanas. No es un hacker eligiendo su negocio en particular &mdash; es un script revisando millones de direcciones, y no le importa qué tan grande sea usted. Un negocio pequeño con un firewall sin actualizar es tan visible como una empresa grande, y a menudo un blanco más fácil porque nadie revisa los registros.</p>
<p>Hablamos de los conceptos básicos de seguridad de router y firewall en una <a href="https://incognitocybersecurity.com/blog/router-firewall-security-small-business/">publicación reciente</a> en nuestro <a href="https://incognitocybersecurity.com/blog/">blog</a>, y esta noticia es un buen recordatorio de por qué importa: estos dispositivos están en la puerta de entrada de toda su red. Un firewall comprometido no solo expone una computadora &mdash; puede darle a un atacante un punto de apoyo hacia todo lo conectado detrás de él, incluyendo sus respaldos, los datos de sus clientes y su software de contabilidad.</p>
<h2>Cómo se Ve Esto en un Negocio Pequeño</h2>
<p>El patrón es el mismo si el blanco es un sistema hospitalario o un negocio de cinco personas: un atacante encuentra el dispositivo sin actualizar, entra en silencio y observa antes de hacer algo ruidoso &mdash; ransomware semanas después, o robo silencioso de datos de clientes e información bancaria. Para cuando usted nota que algo anda mal, a menudo ya tuvieron acceso por un tiempo. Por eso los <a href="https://incognitocybersecurity.com/secure-data-backups/">respaldos seguros y probados</a> y la <a href="https://incognitocybersecurity.com/end-point-protection/">protección de endpoints</a> en capas importan tanto como la puerta de entrada misma.</p>
<h2>Qué Puede Hacer Esta Semana</h2>
<ol>
<li><strong>Haga una lista de todo lo que está expuesto a internet.</strong> Firewall, router, VPN, herramientas de escritorio remoto, cualquier dispositivo con una página de acceso pública. Si no sabe qué hay en esa lista, ese es el primer vacío que hay que cerrar.</li>
<li><strong>Active las actualizaciones automáticas donde sea posible.</strong> Para los sistemas que no pueden actualizarse automáticamente sin riesgo, asigne a alguien &mdash; usted, su personal o su proveedor de TI &mdash; para revisarlos cada mes, no &#8220;eventualmente&#8221;.</li>
<li><strong>Retire todo lo que ya llegó al final de su vida útil.</strong> El software que ya no recibe actualizaciones de seguridad debe reemplazarse o aislarse de la red, no solo usarse con cuidado.</li>
<li><strong>Pida a quien administra su red un reporte del estado de las actualizaciones.</strong> Una simple respuesta de &#8220;cuándo se actualizó esto por última vez&#8221; para cada dispositivo le dice más que cualquier presentación de ventas.</li>
<li><strong>Agregue una revisión recurrente de 15 minutos a su calendario.</strong> Una vez al mes, alguien revisa si hay actualizaciones pendientes en sus sistemas clave. Es aburrido, y es una de las formas más económicas de evitar una semana muy cara.</li>
</ol>
<h2>En Resumen</h2>
<p>Los hackers no están innovando con ataques como estos &mdash; están aprovechando que actualizar el software es trabajo invisible sin recompensa inmediata, así que siempre se pospone para la próxima semana. Los negocios más afectados casi nunca son los que tienen las defensas más débiles en el papel; son aquellos donde nadie tenía claramente la responsabilidad de mantener esas defensas al día. Ese es un vacío que puede cerrar esta semana sin gastar un centavo en equipo nuevo.</p>
<div style="background:#0B1524;border:1px solid #1E3A5F;border-left:6px solid #22D3EE;border-radius:8px;padding:28px 32px;margin:36px 0;">
<p style="margin:0 0 12px 0;color:#F59E0B;font-weight:700;text-transform:uppercase;font-size:13px;letter-spacing:0.06em;">¿No está seguro de qué está actualizado y qué no?</p>
<p style="margin:0 0 18px 0;color:#E5EDF5;">Administramos las actualizaciones, los firewalls y la protección de endpoints para negocios pequeños en todo el sur de Arizona &mdash; en silencio, de fondo. Si ha pasado tiempo desde la última revisión, veámoslo juntos.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#07131F;font-weight:700;padding:12px 24px;border-radius:6px;text-decoration:none;">Agende una Visita Sin Costo &rarr;</a></p>
</div>
<p>Conozca nuestras <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">soluciones de ciberseguridad para pequeñas empresas</a>, incluyendo el <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtrado de spam y virus</a> que detiene muchos de estos ataques antes de que lleguen a un dispositivo que necesite actualización.</p>
<h2>Envíenos un Mensaje</h2>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_56_container">
			<label for="field_w5lnz" >
				If you are human, leave this field blank.			</label>
			<input  id="field_w5lnz" type="text" class="frm_form_field form-field frm_verify" name="item_meta[56]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCZuoezAgDGucGzAHteL9vuaslxTMff7CFbU03rwP1Mwo" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p>&mdash; Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 8px 0;color:#F59E0B;font-weight:700;text-transform:uppercase;font-size:12px;letter-spacing:0.06em;">Sobre el autor</p>
<p style="margin:0 0 10px 0;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 12px 0;color:#334155;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="margin:0;color:#334155;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/firewall-vpn-sin-actualizar-riesgo-pequenas-empresas/">Por Qué el Equipo de Seguridad que “Se Instala y se Olvida” Es Justo lo que Buscan los Hackers</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why &#8220;Set It and Forget It&#8221; Security Gear Is Exactly What Hackers Are Counting On</title>
		<link>https://incognitocybersecurity.com/blog/unpatched-firewall-vpn-small-business-risk/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=unpatched-firewall-vpn-small-business-risk</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 14:20:30 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/unpatched-firewall-vpn-small-business-risk/</guid>

					<description><![CDATA[<p>Hackers are actively exploiting unpatched firewalls and VPN gear from major vendors. Here's why patch management matters for every small business this week.</p>
The post <a href="https://incognitocybersecurity.com/blog/unpatched-firewall-vpn-small-business-risk/">Why “Set It and Forget It” Security Gear Is Exactly What Hackers Are Counting On</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Why &#8220;Set It and Forget It&#8221; Security Gear Is Exactly What Hackers Are Counting On</h1>
<p><a href="https://incognitocybersecurity.com/blog/firewall-vpn-sin-actualizar-riesgo-pequenas-empresas/" style="display:inline-block;background:#22D3EE;color:#07131F;font-weight:700;padding:10px 20px;border-radius:6px;text-decoration:none;margin:8px 0 20px 0;">&#127474;&#127485; Leer en Espa&ntilde;ol &rarr;</a></p>
<p>On September 22, CISA and security researchers confirmed hackers were actively breaking into firewalls and remote-access equipment from two of the biggest names in business security &mdash; Check Point and F5 &mdash; using flaws the vendors had already published patches for. Attackers weren&#8217;t picking locks. They were walking through doors left unlocked for months.</p>
<p>You probably don&#8217;t run Check Point or F5 gear. Most businesses I work with in Southern Arizona don&#8217;t. But the story behind this attack is the same one that plays out on smaller networks every week, and it&#8217;s worth five minutes to understand why.</p>
<h2>What Actually Happened</h2>
<p>CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog last week, including two Check Point flaws and one in F5&#8217;s BIG-IP access system. Two scored a perfect 10 out of 10 on the industry&#8217;s severity scale &mdash; an attacker who finds an unpatched device can take total remote control of it, no password and no click required from anyone inside the business. From there, they have a direct path into the rest of the network.</p>
<h3>Why This Matters Even If You&#8217;ve Never Heard of These Products</h3>
<p>The brand isn&#8217;t the point. The pattern is: a vendor discovers a flaw, releases a fix, and publishes a warning &mdash; and real-world attacks follow within days because so many businesses never applied the update. It doesn&#8217;t matter whether the device is a $40,000 enterprise firewall or a $150 router from a big-box store. If it&#8217;s connected to the internet and unpatched, it&#8217;s a target with your business&#8217;s name on it.</p>
<h2>The Real Problem Isn&#8217;t the Software &mdash; It&#8217;s the Silence</h2>
<p>Here&#8217;s what I see over and over with business owners: nobody decided to skip patching. It just never made noise. Your point-of-sale system, your router, your bookkeeper&#8217;s laptop &mdash; none of them ring a bell when an update is overdue. Everything looks fine, right up until it isn&#8217;t. Attackers count on the fact that &#8220;still running&#8221; and &#8220;still safe&#8221; feel like the same thing, when they&#8217;re not even close.</p>
<h3>Old Software Has a Quiet Expiration Date</h3>
<p>Software that&#8217;s reached end-of-life &mdash; an old Windows version, a legacy point-of-sale platform, a plugin nobody&#8217;s touched in years &mdash; stops receiving security fixes entirely. New vulnerabilities keep getting discovered, but the vendor is no longer sending fixes. That software doesn&#8217;t get safer by sitting still; it gets more dangerous every month it&#8217;s ignored, because it&#8217;s the one door nobody&#8217;s watching. If any office machine is still running an operating system your vendor has stopped supporting, that&#8217;s the first thing worth checking this week &mdash; our <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">cybersecurity awareness resources</a> walk through how to spot it.</p>
<figure style="margin:32px 0;"><img decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-infographic-unpatched-firewall-en.png" alt="Infographic with 3 key points on why unpatched firewalls and end-of-life software are a bigger security risk than small business owners think" style="max-width:100%;height:auto;border-radius:8px;" /></figure>
<h2>What Hackers Are Actually Looking For</h2>
<p>When a vulnerability like these goes public, automated scanners sweep the internet for unpatched devices within hours, not weeks. It&#8217;s not a hacker picking your business specifically &mdash; it&#8217;s a script checking millions of addresses, and it doesn&#8217;t care how big you are. A small business with an unpatched firewall is just as visible as a Fortune 500 company, and often an easier target because nobody&#8217;s watching the logs.</p>
<p>We covered basic router and firewall hygiene in a <a href="https://incognitocybersecurity.com/blog/router-firewall-security-small-business/">recent post</a> on our <a href="https://incognitocybersecurity.com/blog/">blog</a>, and this news is a good reminder why it matters: these devices sit at the front door of your entire network. A compromised firewall doesn&#8217;t just expose one computer &mdash; it can give an attacker a foothold into everything behind it, including your backups, customer records, and accounting software.</p>
<h2>How This Plays Out for a Small Business</h2>
<p>The pattern holds whether the target is a hospital or a five-person shop: an attacker finds the unpatched device, gets in quietly, and looks around before doing anything noisy &mdash; ransomware weeks later, or quietly siphoned customer and banking data. By the time you notice, they&#8217;ve often had access for a while. That&#8217;s why <a href="https://incognitocybersecurity.com/secure-data-backups/">secure, tested backups</a> and layered <a href="https://incognitocybersecurity.com/end-point-protection/">endpoint protection</a> matter as much as the front door itself.</p>
<h2>What You Can Do This Week</h2>
<ol>
<li><strong>List everything facing the internet.</strong> Firewall, router, VPN, remote desktop tools, any device with a public login page. If you don&#8217;t know what&#8217;s on that list, that&#8217;s the first gap to close.</li>
<li><strong>Turn on automatic updates wherever you can.</strong> For systems that can&#8217;t auto-update safely, put someone &mdash; you, staff, or your IT provider &mdash; in charge of checking monthly, not &#8220;eventually.&#8221;</li>
<li><strong>Retire anything past end-of-life.</strong> Software that no longer gets security updates needs to be replaced or isolated from the network, not just used carefully.</li>
<li><strong>Ask whoever manages your network for a patch status report.</strong> A simple &#8220;when was this last updated&#8221; answer for every device tells you more than any sales pitch.</li>
<li><strong>Put a recurring 15-minute review on your calendar.</strong> Once a month, someone checks for pending updates on your key systems. It&#8217;s boring, and it&#8217;s one of the cheapest ways to avoid a very expensive week.</li>
</ol>
<h2>Bottom Line</h2>
<p>Hackers aren&#8217;t breaking new ground with attacks like these &mdash; they&#8217;re exploiting the fact that patching is invisible work with no immediate reward, so it keeps getting pushed to next week. The businesses hit hardest usually aren&#8217;t the ones with the weakest defenses on paper; they&#8217;re the ones where nobody was clearly responsible for keeping those defenses current. That&#8217;s a gap you can close this week without spending a dime on new equipment.</p>
<div style="background:#0B1524;border:1px solid #1E3A5F;border-left:6px solid #22D3EE;border-radius:8px;padding:28px 32px;margin:36px 0;">
<p style="margin:0 0 12px 0;color:#F59E0B;font-weight:700;text-transform:uppercase;font-size:13px;letter-spacing:0.06em;">Not sure what&#8217;s patched and what isn&#8217;t?</p>
<p style="margin:0 0 18px 0;color:#E5EDF5;">We manage patching, firewall updates, and endpoint protection for small businesses across Southern Arizona &mdash; quietly, in the background. If it&#8217;s been a while since anyone checked, let&#8217;s take a look together.</p>
<p style="margin:0;"><a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#07131F;font-weight:700;padding:12px 24px;border-radius:6px;text-decoration:none;">Book a Complimentary Visit &rarr;</a></p>
</div>
<p>Take a look at our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">small business cybersecurity solutions</a>, including <a href="https://incognitocybersecurity.com/spam-virus-filtering/">spam and virus filtering</a> that catches a lot of these attacks before they ever reach a device that needs patching.</p>
<h2>Send us a message</h2>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_57_container">
			<label for="field_2z2a" >
				If you are human, leave this field blank.			</label>
			<input  id="field_2z2a" type="text" class="frm_form_field form-field frm_verify" name="item_meta[57]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCZTrvizMN1yayQdtxpdoJmp7ZgBbMy9czh0GepRnhhe9" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p>&mdash; Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="margin:0 0 8px 0;color:#F59E0B;font-weight:700;text-transform:uppercase;font-size:12px;letter-spacing:0.06em;">About the author</p>
<p style="margin:0 0 10px 0;font-size:19px;font-weight:700;color:#0F1E34;">Nemuel Cruz</p>
<p style="margin:0 0 12px 0;color:#334155;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="margin:0;color:#334155;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/unpatched-firewall-vpn-small-business-risk/">Why “Set It and Forget It” Security Gear Is Exactly What Hackers Are Counting On</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cuando la IA te da el Número de un Estafador en Vez de Soporte Real</title>
		<link>https://incognitocybersecurity.com/blog/estafa-envenenamiento-ia-soporte-falso/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=estafa-envenenamiento-ia-soporte-falso</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 14:17:33 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/estafa-envenenamiento-ia-soporte-falso/</guid>

					<description><![CDATA[<p>Los estafadores optimizan paginas falsas de soporte para que los chatbots de IA las recomienden como respuestas reales. Asi funciona y que hacer esta semana.</p>
The post <a href="https://incognitocybersecurity.com/blog/estafa-envenenamiento-ia-soporte-falso/">Cuando la IA te da el Número de un Estafador en Vez de Soporte Real</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>Cuando la IA te da el Número de un Estafador en Vez de Soporte Real</h1>
<p style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/ai-search-poisoning-fake-support-scam/" style="color:#22D3EE;text-decoration:none;font-weight:600;">🇺🇸 Read this article in English</a></p>
<p>La semana pasada vi a un cliente escribir &#8220;cómo contacto al departamento de fraude de mi banco&#8221; en una herramienta de búsqueda con IA. La respuesta que recibió se veía perfecta: un resumen limpio, un número de teléfono, hasta el formato del número de caso que debía tener a la mano. Solo que el número no era del banco. Era de un estafador que había pasado meses asegurándose de que las herramientas de IA lo encontraran primero.</p>
<p>Esto no es una hipótesis. Investigadores de seguridad acaban de documentar una campaña activa en la que los atacantes inundan internet con páginas falsas de soporte, reseñas y PDFs diseñados específicamente para que ChatGPT, Google AI Overviews, Gemini y Perplexity los tomen como respuesta. Aerolíneas, bancos y sitios de viaje como Delta, Chase, Bank of America y Airbnb ya han tenido números falsos de soporte aparecer en respuestas de IA. Todavía nadie ha probado que los pequeños negocios estén siendo el blanco de la misma forma, pero la técnica no distingue el tamaño de la empresa que está suplantando, y tus clientes usan las mismas herramientas de IA que los clientes de tu banco.</p>
<h2>Cómo funciona realmente el &#8220;envenenamiento de búsquedas con IA&#8221;</h2>
<p>Los buscadores tradicionales clasificaban páginas según enlaces y reputación, lo que hacía difícil manipularlos de la noche a la mañana. Los chatbots de IA funcionan distinto: resumen el contenido que parece más relevante y confiable en el momento, tomado de un grupo de fuentes mucho más amplio y que cambia más rápido.</p>
<h3>La estrategia del atacante</h3>
<p>Los investigadores llaman a esta técnica GEO — Generative Engine Optimization, o optimización para motores generativos — el primo, en la era de la IA, del viejo spam de SEO. En lugar de perseguir el ranking de Google, los atacantes escriben contenido pensado específicamente para cómo lo &#8220;lee&#8221; la IA: la frase exacta que escribiría un cliente (&#8220;número de servicio al cliente de Delta&#8221;), formato de preguntas y respuestas, y el número falso repetido varias veces para reforzarlo. Lo publican en todos lados a la vez — reseñas de Yelp, páginas de Google Sites, GitHub Pages, Blogger, descripciones de YouTube, incluso sitios comprometidos de universidades y gobiernos — para que al menos algunas copias queden indexadas y aparezcan en las respuestas.</p>
<h3>Por qué funciona tan bien</h3>
<p>Cuando una herramienta de IA te da una respuesta segura y bien formateada, no viene con un enlace que puedas pasar el cursor por encima ni una URL que puedas revisar en busca de errores, como sí pasa con un resultado normal de Google. Estás confiando en el resumen de la IA tal cual. Eso es exactamente la confianza que este engaño busca explotar — y es la misma razón por la que hemos estado advirtiendo a nuestros clientes sobre <a href="https://incognitocybersecurity.com/blog/phishing-codigo-dispositivo-microsoft/">páginas de inicio de sesión falsas que parecen reales</a>.</p>
<h2>Por qué esto te importa aunque no seas Chase ni Delta</h2>
<p>Aquí se juntan dos riesgos para el dueño de un pequeño negocio. Primero, tu propio personal busca constantemente números de soporte de proveedores y bancos: la empresa de nómina, la aseguradora, el proveedor de software, el procesador de pagos. Si alguna de esas búsquedas alguna vez termina en un número falso, alguien de tu equipo podría entregar credenciales de una cuenta o un código de un solo uso pensando que habla con una línea de soporte legítima. Así es como en realidad empieza gran parte del <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">robo de credenciales</a> — no con un hackeo dramático, sino con una llamada telefónica que se siente completamente normal.</p>
<p>Segundo, si alguna vez suplantan el nombre y el contacto de soporte de tu propio negocio de esta manera, un cliente podría terminar dando su tarjeta o los datos de su cuenta a alguien que se hace pasar por ti. Eso es un problema de reputación que no verás venir hasta que un cliente te llame confundido por un cargo que tú nunca hiciste.</p>
<figure style="margin:32px 0;text-align:center;">
<img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-ai-search-poisoning-infographic-es.png" alt="Tres cosas que las pequeñas empresas pueden hacer sobre el envenenamiento de búsquedas con IA: reconocer ataques GEO, verificar los números de contacto antes de llamar y avisar a tu equipo" style="max-width:100%;height:auto;border-radius:8px;" width="1200" height="640" /><br />
</figure>
<h2>Qué puedes hacer esta semana</h2>
<ol>
<li><strong>Deja de confiar en números de teléfono que te da la IA para cualquier tema financiero.</strong> Consigue el número en el reverso de tu tarjeta, en la factura del proveedor, o escribiendo tú mismo la URL real de la empresa en el navegador — nunca del resumen de un chatbot.</li>
<li><strong>Dile a tu equipo, en palabras simples, esta misma semana.</strong> Dos minutos en tu próxima reunión hacen más que una política que nadie lee. Si esto te suena nuevo, nuestra <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">capacitación de concientización en ciberseguridad</a> cubre exactamente este tipo de engaño en un lenguaje que tu personal sí va a recordar.</li>
<li><strong>Busca el nombre de tu propio negocio junto con &#8220;número de teléfono&#8221; o &#8220;servicio al cliente&#8221; en ChatGPT, Gemini y un par más.</strong> Si algo se ve raro, mejor que lo sepas tú antes que un cliente.</li>
<li><strong>Guarda en favoritos las páginas reales de soporte de tus proveedores</strong> — banco, nómina, aseguradora, software clave — para que nadie en tu equipo tenga que buscarlas bajo presión.</li>
<li><strong>Asegúrate de que tu protección de endpoints realmente esté vigilando el siguiente paso de este engaño</strong> — herramientas de acceso remoto y malware para robar credenciales que un &#8220;agente de soporte&#8221; convence a la víctima de instalar. Para eso existe la <a href="https://incognitocybersecurity.com/end-point-protection/">protección de endpoints</a>.</li>
</ol>
<h2>Lo esencial</h2>
<p>Las herramientas de IA son genuinamente útiles, y no te estoy diciendo a ti ni a tu equipo que dejen de usarlas. Pero trata un número de teléfono o enlace de contacto generado por IA como tratarías un nombre desconocido en el identificador de llamadas: útil como punto de partida, no algo para actuar sin verificarlo primero. Los negocios que caen en esto no son descuidados — simplemente están ocupados, y ocupado es justo con lo que cuenta este engaño.</p>
<p>Si quieres una segunda opinión sobre cómo tu equipo manejaría algo así — o si tu <a href="https://incognitocybersecurity.com/spam-virus-filtering/">filtrado de spam y phishing</a> y tu <a href="https://incognitocybersecurity.com/secure-data-backups/">protección de respaldo de datos</a> actuales detectarían lo que viene después de un engaño como este — para eso están nuestras <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">soluciones de ciberseguridad para pequeños negocios</a>. Trabajamos con dueños de pequeños negocios en todo el sur de Arizona en este tipo de situaciones todos los días.</p>
<p>Puedes encontrar más artículos como este, explicados en lenguaje sencillo, en nuestro <a href="https://incognitocybersecurity.com/blog/">blog</a>.</p>
<div style="background:#0F1E34;background:linear-gradient(135deg,#0a0f1c,#101e34);border-radius:10px;padding:28px 24px;margin:32px 0;text-align:center;">
<p style="color:#ffffff;font-size:19px;font-weight:bold;margin:0 0 8px;">¿No estás seguro de que tu equipo detectaría un engaño como este?</p>
<p style="color:#9FB3C8;margin:0 0 18px;">Obtén una revisión gratuita y sin compromiso de tu configuración actual — protección de endpoints, respaldos, filtrado de spam, y cómo tu equipo maneja la llamada inesperada.</p>
<p>  <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:bold;padding:12px 28px;border-radius:6px;text-decoration:none;">Agenda una Visita sin Costo</a>
</div>
<h2>Envíanos un mensaje</h2>
<p>¿Preguntas sobre esto o sobre cualquier otro tema de seguridad en tu negocio? Escríbenos y te responderemos.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_58_container">
			<label for="field_e3g83" >
				If you are human, leave this field blank.			</label>
			<input  id="field_e3g83" type="text" class="frm_form_field form-field frm_verify" name="item_meta[58]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCZ03VQR74p7+eFHpjYAIKYOHHcZHI6EfsPqgJ9b9am1C" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p>&mdash; Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="text-transform:uppercase;color:#F59E0B;font-size:12px;font-weight:bold;letter-spacing:0.05em;margin:0 0 8px;">Sobre el autor</p>
<p style="font-size:19px;font-weight:bold;color:#0F1E34;margin:0 0 10px;">Nemuel Cruz</p>
<p style="color:#334155;margin:0 0 12px;line-height:1.6;">Nemuel Cruz es el fundador y propietario de Incognito Cyber Security, un proveedor de servicios administrados de TI y ciberseguridad con sede en Tucson, Arizona. Desde 2011 ha ayudado a pequeñas empresas de todo el sur de Arizona a proteger sus sistemas, dar soporte a su personal y seguir operando con respuesta de emergencia 24/7. Escribe sobre seguridad en lenguaje sencillo para dueños que tienen un negocio que atender.</p>
<p style="color:#334155;margin:0;">¿Preguntas sobre este artículo? Escríbeme a <a href="mailto:nemuel@incognitocybersecurity.com" style="color:#0F1E34;font-weight:600;">nemuel@incognitocybersecurity.com</a> o <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="color:#0F1E34;font-weight:600;">agenda una visita sin costo</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/estafa-envenenamiento-ia-soporte-falso/">Cuando la IA te da el Número de un Estafador en Vez de Soporte Real</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When AI Gives You a Scammer&#8217;s Phone Number Instead of Real Support</title>
		<link>https://incognitocybersecurity.com/blog/ai-search-poisoning-fake-support-scam/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ai-search-poisoning-fake-support-scam</link>
		
		<dc:creator><![CDATA[Nemuel Cruz]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 14:17:00 +0000</pubDate>
				<category><![CDATA[Incognito CyberSecurity]]></category>
		<guid isPermaLink="false">https://incognitocybersecurity.com/blog/ai-search-poisoning-fake-support-scam/</guid>

					<description><![CDATA[<p>Scammers are optimizing fake support pages so AI chatbots recommend them as real answers. Here's how it works and what to do this week.</p>
The post <a href="https://incognitocybersecurity.com/blog/ai-search-poisoning-fake-support-scam/">When AI Gives You a Scammer’s Phone Number Instead of Real Support</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></description>
										<content:encoded><![CDATA[<h1>When AI Gives You a Scammer&#8217;s Phone Number Instead of Real Support</h1>
<p class="ics-es-link-button" style="margin:0 0 24px;"><a href="https://incognitocybersecurity.com/blog/estafa-envenenamiento-ia-soporte-falso/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:bold;padding:10px 20px;border-radius:6px;text-decoration:none;font-size:15px;">🇲🇽 Leer en Español →</a></p>
<p>Last week I watched a client type &#8220;how do I contact my bank&#8217;s fraud department&#8221; into an AI search tool. The answer that came back looked perfect — a clean summary, a phone number, a case number format to have ready. Only the number wasn&#8217;t the bank&#8217;s. It belonged to a scammer who had spent months making sure AI tools would find it first.</p>
<p>This isn&#8217;t a hypothetical. Security researchers just documented an active campaign where attackers flood the web with fake support pages, reviews, and PDFs built specifically to get picked up by ChatGPT, Google AI Overviews, Gemini, and Perplexity. Airlines, banks, and travel sites like Delta, Chase, Bank of America, and Airbnb have all had fake support numbers surface in AI answers. Nobody&#8217;s proven small businesses are being targeted the same way yet — but the technique doesn&#8217;t care what size company it&#8217;s impersonating, and your customers are using the same AI tools your bank&#8217;s customers are.</p>
<h2>How &#8220;AI search poisoning&#8221; actually works</h2>
<p>Search engines used to rank pages based on links and reputation, which made them hard to game overnight. AI chatbots work differently — they summarize whatever content looks most relevant and authoritative in the moment, pulled from a much wider, faster-moving pool of sources.</p>
<h3>The attacker&#8217;s playbook</h3>
<p>Researchers call this technique GEO — Generative Engine Optimization — the AI-era cousin of old-school SEO spam. Instead of chasing Google rankings, attackers write content specifically for how AI reads it: exact phrasing a customer would type (&#8220;Delta customer service phone number&#8221;), question-and-answer formatting, and the fake number repeated several times for emphasis. They post it everywhere at once — Yelp reviews, Google Sites pages, GitHub Pages, Blogger, YouTube descriptions, even compromised university and government websites — so at least a few copies get indexed and surfaced.</p>
<h3>Why it works so well</h3>
<p>When an AI tool gives you a confident, well-formatted answer, it doesn&#8217;t come with a link you can hover over or a URL you can eyeball for typos, the way a Google search result does. You&#8217;re trusting the AI&#8217;s summary at face value. That&#8217;s exactly the trust the scam is built to exploit — and it&#8217;s the same reason we&#8217;ve been warning clients about <a href="https://incognitocybersecurity.com/blog/device-code-phishing-microsoft-login/">fake login pages that look real</a>.</p>
<h2>Why this matters even if you&#8217;re not Chase or Delta</h2>
<p>Two risks stack up here for a small business owner. First, your own staff searches for vendor and bank support numbers constantly — payroll processor, insurance carrier, software vendor, merchant services. If any of those searches ever routes through a scam number, someone on your team could hand over account credentials or a one-time passcode believing they&#8217;re talking to a legitimate support line. That&#8217;s how a lot of <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">credential theft actually starts</a> — not a dramatic hack, but a normal-feeling phone call.</p>
<p>Second, if your own business&#8217;s name and support contact ever get impersonated this way, a customer could end up giving their card or account information to someone pretending to be you. That&#8217;s a reputation problem you won&#8217;t see coming until a customer calls you confused about a charge you never made.</p>
<figure style="margin:32px 0;text-align:center;">
<img loading="lazy" loading="lazy" decoding="async" src="https://incognitocybersecurity.com/wp-content/uploads/2026/09/ics-ai-search-poisoning-infographic-en.png" alt="Three things small businesses can do about AI search poisoning: recognize GEO attacks, verify contact numbers before calling, and brief your team" style="max-width:100%;height:auto;border-radius:8px;" width="1200" height="640" /><br />
</figure>
<h2>What you can do this week</h2>
<ol>
<li><strong>Stop trusting AI-provided phone numbers for anything financial.</strong> Get the number from the back of your card, the vendor&#8217;s invoice, or by typing the company&#8217;s actual URL into your browser — not from a chatbot summary.</li>
<li><strong>Tell your team, in plain language, this week.</strong> A two-minute heads-up in your next huddle does more than a policy nobody reads. If it sounds unfamiliar, our <a href="https://incognitocybersecurity.com/cybersecurity-awareness-for-business/">cybersecurity awareness training</a> covers exactly this kind of scam in language your staff will actually remember.</li>
<li><strong>Search your own business name plus &#8220;phone number&#8221; or &#8220;customer service&#8221; in ChatGPT, Gemini, and a couple of others.</strong> If anything looks off, you want to know before a customer does.</li>
<li><strong>Bookmark your real vendor support pages</strong> — bank, payroll, insurance, key software — so nobody on your team has to search for them under pressure.</li>
<li><strong>Make sure endpoint protection is actually watching for the next step of this scam</strong> — remote-access tools and credential-stealing malware that a &#8220;support agent&#8221; talks a victim into installing. That&#8217;s exactly what <a href="https://incognitocybersecurity.com/end-point-protection/">endpoint protection</a> is built to catch.</li>
</ol>
<h2>The bottom line</h2>
<p>AI tools are genuinely useful, and I&#8217;m not telling you or your team to stop using them. But treat an AI-generated phone number or contact link the way you&#8217;d treat an unfamiliar name on caller ID: helpful as a starting point, not something to act on without a second check. The businesses that get burned by this aren&#8217;t careless — they&#8217;re just busy, and busy is exactly what this scam is counting on.</p>
<p>If you want a second set of eyes on how your team handles this kind of thing — or whether your current <a href="https://incognitocybersecurity.com/spam-virus-filtering/">spam and phishing filtering</a> and <a href="https://incognitocybersecurity.com/secure-data-backups/">backup protection</a> would catch what comes after a scam like this succeeds — that&#8217;s exactly what our <a href="https://incognitocybersecurity.com/small-business-cyber-security-solutions/">small business cybersecurity solutions</a> are built for. We work with small business owners across Southern Arizona on exactly this kind of thing every day.</p>
<p>You can find more plain-English breakdowns like this one on our <a href="https://incognitocybersecurity.com/blog/">blog</a>.</p>
<div style="background:#0F1E34;background:linear-gradient(135deg,#0a0f1c,#101e34);border-radius:10px;padding:28px 24px;margin:32px 0;text-align:center;">
<p style="color:#ffffff;font-size:19px;font-weight:bold;margin:0 0 8px;">Not sure if your team would catch a scam like this?</p>
<p style="color:#9FB3C8;margin:0 0 18px;">Get a free, no-pressure look at your current setup — endpoint protection, backups, spam filtering, and how your team handles the unexpected call.</p>
<p>  <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="display:inline-block;background:#22D3EE;color:#0F1E34;font-weight:bold;padding:12px 28px;border-radius:6px;text-decoration:none;">Book a Complimentary Visit</a>
</div>
<h2>Send us a message</h2>
<p>Questions about this or anything else in your security setup? Send us a note and we&#8217;ll get back to you.</p>
<div class="frm_forms  with_frm_style frm_style_modern-dark-background" id="frm_form_4_container" data-token="866e1ba86d5b6087cfe59018265ce284">
<form enctype="multipart/form-data" method="post" class="frm-show-form  frm_pro_form " id="form_main-form" data-token="866e1ba86d5b6087cfe59018265ce284">
<div class="frm_form_fields ">
<fieldset>
<legend class="frm_screen_reader">ICS Form</legend>

<div class="frm_fields_container">
<input type="hidden" name="frm_action" value="create" />
<input type="hidden" name="form_id" value="4" />
<input type="hidden" name="frm_hide_fields_4" id="frm_hide_fields_4" value="" />
<input type="hidden" name="form_key" value="main-form" />
<input type="hidden" name="item_meta[0]" value="" />
<input type="hidden" id="frm_submit_entry_4" name="frm_submit_entry_4" value="a6c0e2ab5b" /><input type="hidden" name="_wp_http_referer" value="/feed/" /><div id="frm_field_22_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_qh4icy3" id="field_qh4icy3_label" class="frm_primary_label">Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_qh4icy3" name="item_meta[22]" value=""  data-reqmsg="Name cannot be blank." aria-required="true" data-invmsg="Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_24_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6">
	<label for="field_29yf4d3" id="field_29yf4d3_label" class="frm_primary_label">Email
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input type="email" id="field_29yf4d3" name="item_meta[24]" value=""  data-reqmsg="Email cannot be blank." aria-required="true" data-invmsg="Please enter a valid email address" aria-invalid="false"  />
	
	
</div>
<div id="frm_field_29_container" class="frm_form_field form-field  frm_required_field frm_top_container frm6 frm_first">
	<label for="field_uoc7p" id="field_uoc7p_label" class="frm_primary_label">Business Name
		<span class="frm_required" aria-hidden="true">*</span>
	</label>
	<input  type="text" id="field_uoc7p" name="item_meta[29]" value=""  data-reqmsg="Business Name cannot be blank." aria-required="true" data-invmsg="Business Name is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_38_container" class="frm_form_field form-field  frm_top_container frm6">
	<label for="field_3z78d" id="field_3z78d_label" class="frm_primary_label">Phone Number
		<span class="frm_required" aria-hidden="true"></span>
	</label>
	<input  type="text" id="field_3z78d" name="item_meta[38]" value=""  data-invmsg="Phone Number is invalid" aria-invalid="false"   />
	
	
</div>
<div id="frm_field_27_container" class="frm_form_field form-field ">
	<div class="frm_submit frm_flex">
<button class="frm_button_submit frm_final_submit" type="submit"   formnovalidate="formnovalidate">Submit</button>



</div>
</div>
	<input type="hidden" name="item_key" value="" />
			<div id="frm_field_59_container">
			<label for="field_hsw5b" >
				If you are human, leave this field blank.			</label>
			<input  id="field_hsw5b" type="text" class="frm_form_field form-field frm_verify" name="item_meta[59]" value=""  />
		</div>
		<input name="frm_state" type="hidden" value="aFjyV5PjKl+R0fI2YcAcCVugvCvcs5aXn2He78JvN3+QN6Qelr8IiAUi+AyIELi1" /><p class="frm_description" style="margin-top:12px;font-size:13px;opacity:0.8;">🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.</p></div>
</fieldset>
</div>

</form>
</div>

<p>&mdash; Nemuel Cruz, Incognito Cyber Security</p>
<div class="ics-author-bio" style="background:#F8FAFC;border:1px solid #E2E8F0;border-left:6px solid #22D3EE;border-radius:6px;padding:24px 28px;margin-top:44px;">
<p style="text-transform:uppercase;color:#F59E0B;font-size:12px;font-weight:bold;letter-spacing:0.05em;margin:0 0 8px;">About the author</p>
<p style="font-size:19px;font-weight:bold;color:#0F1E34;margin:0 0 10px;">Nemuel Cruz</p>
<p style="color:#334155;margin:0 0 12px;line-height:1.6;">Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.</p>
<p style="color:#334155;margin:0;">Questions about this article? Email <a href="mailto:nemuel@incognitocybersecurity.com" style="color:#0F1E34;font-weight:600;">nemuel@incognitocybersecurity.com</a> or <a href="https://incognitocybersecurity.com/book-a-complimentary-visit/" style="color:#0F1E34;font-weight:600;">book a complimentary visit</a>.</p>
</div>The post <a href="https://incognitocybersecurity.com/blog/ai-search-poisoning-fake-support-scam/">When AI Gives You a Scammer’s Phone Number Instead of Real Support</a> first appeared on <a href="https://incognitocybersecurity.com">Incognito CyberSecurity</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
