Medium

“Cyber Tax” Warning as Two-Fifths of SMBs Raise Prices After Breach

Infosecurity Magazine

Overview

A recent study by the Identity Theft Resource Center (ITRC) indicates that a staggering 81% of small businesses in the U.S. experienced a data or security breach in the past year. As a result, many of these businesses are feeling the financial strain and are responding by increasing their prices. Specifically, two-fifths of small and medium-sized businesses (SMBs) have raised their prices to offset the costs associated with these breaches. This trend not only impacts the businesses themselves but also affects consumers, who may face higher prices for goods and services. The findings emphasize the ongoing vulnerability of small businesses to cyber threats and the wider economic implications of such breaches.

Key Takeaways

  • Affected Systems: Small businesses in the U.S.
  • Action Required: Businesses should enhance their cybersecurity measures, conduct regular security audits, and consider investing in employee training to prevent future breaches.
  • Timeline: Newly disclosed

Original Article Summary

New ITRC research finds 81% of US small businesses suffered a data or security breach in the past year

Impact

Small businesses in the U.S.

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Businesses should enhance their cybersecurity measures, conduct regular security audits, and consider investing in employee training to prevent future breaches.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Vulnerability, Data Breach.

Related Coverage

Metabase zero-day exploited to access Framework customer data

Help Net Security

Framework, a company that specializes in repairable laptops, recently faced a data breach due to a zero-day vulnerability in Metabase, a business intelligence tool. Attackers exploited this vulnerability and gained unauthorized access to sensitive customer information, including names, email addresses, phone numbers, physical addresses, and login IP addresses. However, the breach did not compromise payment information or order records. Framework informed affected customers about the incident, emphasizing the importance of safeguarding personal data. This incident raises concerns about the security of business intelligence tools and the potential risks to customer data across various companies that utilize such services.

Aug 10, 2026

Member of The Com sent to prison for blackmail, sextortion

BleepingComputer

A member of an online cybercrime group known as 'The Com' has been sentenced to two years in prison for engaging in blackmail and sextortion against almost 120 victims globally. This individual targeted children and teenagers, exploiting their vulnerabilities for personal gain. The case sheds light on the growing issue of online exploitation and the dangers that young people face in digital spaces. Law enforcement agencies are increasingly focused on tackling such cybercrimes, and this conviction serves as a warning to others involved in similar activities. The incident raises significant concerns about the safety of minors online and underscores the need for improved protective measures.

Aug 10, 2026

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News

Recent research has shown vulnerabilities in passkey systems designed to enhance online security by replacing traditional passwords and resisting phishing attacks. Three separate studies demonstrated methods for bypassing these protections without breaking the underlying cryptography. For instance, attackers were able to exploit signed authentication data exposed by Windows, leverage a cloud-synced passkey system compromised by existing malware on a victim's device, and other techniques. This is concerning for users and organizations relying on passkeys for secure authentication, as it suggests that even advanced security measures can be undermined. As these attacks become more sophisticated, it raises questions about the reliability of passkeys and the need for ongoing vigilance in security practices.

Aug 10, 2026

LexisNexis shuts down services after suspicious activity on servers

BleepingComputer

LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline due to suspicious activity detected on servers managed by a third-party vendor. The company has not disclosed specific details about the nature of the unusual activity or the vendor involved. This action aims to protect user data and maintain the integrity of their services. Users of these platforms might experience interruptions as LexisNexis investigates the situation. It's crucial for companies that rely on third-party vendors to monitor their security practices closely, as this incident illustrates potential vulnerabilities in external partnerships.

Aug 10, 2026

Valve notifies Steam hardware customers of a data breach

BleepingComputer

Valve has informed its Steam hardware customers in Europe about a data breach that occurred due to a cyberattack on its shipping partner, CEVA Logistics. Hackers accessed sensitive customer information during the breach, although specific details about the type of data stolen have not been disclosed. This incident raises concerns about the security measures in place at third-party logistics providers, which play a crucial role in the supply chain for tech companies. Affected customers are advised to monitor their accounts for any suspicious activity. This breach also highlights the risks associated with outsourcing logistics and the potential vulnerabilities that can arise from relying on external partners for shipping and handling customer data.

Aug 10, 2026

New Jersey, Alabama Join States Targeted in Water Cyberattacks

SecurityWeek

Hackers believed to be linked to Iran have targeted industrial control systems (ICS) at water facilities across at least a dozen states in the U.S., including New Jersey and Alabama. This cyberattack raises serious concerns about the security of critical infrastructure, as these systems are essential for managing water supplies. While specific details on how the hackers gained access have not been disclosed, the incidents indicate a growing trend of cyber threats against vital public services. The implications of such attacks could be severe, potentially disrupting water services and endangering public safety. Authorities are urging water facilities to bolster their cybersecurity measures in response to these incidents.

Aug 10, 2026