January 16, 2026

The Silent Killer of Productivity in West Michigan: Slow Tech

This article has been written by Greg Johnson

It’s easy to spot a technology disaster. When a server crashes, everyone knows. When ransomware hits, it’s a five-alarm fire.


But there’s a different kind of threat quietly eating away at West Michigan businesses right now, and almost no one talks about it because it doesn’t come with an error message.


It’s the Silent Killer of Productivity.


It’s the desktop that takes 12 minutes to boot up while your office manager sips coffee.


It’s the spinning wheel of death every time your team tries to open a PDF. It’s the “workaround” your staff invented because the actual software is too painful to use.


And in 2026, when every good hire matters, you can’t afford to pay your team to wrestle with their tools.


Key takeaways


  • “Slow tech” is digital friction: laggy devices, slow apps, unstable Wi-Fi, and inconsistent updates that quietly drain payroll and morale.

  • The problem usually isn’t one computer… it’s lack of a lifecycle plan.

  • The fix is not a big scary overhaul. It’s a scheduled refresh rhythm so upgrades stop feeling like emergencies.


What “slow tech” means


Slow tech is technology that technically still works, but creates constant friction: slow logins, laggy apps, unreliable networks, and outdated systems with no scheduled plan for updating or replacing them.


This is where many businesses slide into “fine for now”… until it isn’t.


The cost of digital friction


You might think keeping an old computer for “one more year” is saving money. The data usually says the opposite.


One 2025 digital employee experience (DEX) report found employees are interrupted multiple times per month by tech problems and updates. Using a conservative assumption that each interruption takes ~15 minutes to resolve, that can translate to about 1.6 hours of lost productivity per employee per month.


The math (example)


Let’s say you have 10 employees at an average wage of $30/hour.

  • 1.6 hours/month × 12 months = 19.2 hours/year per employee

  • 19.2 hours × 10 employees = 192 hours/year

  • 192 hours × $30/hour = $5,760/year in paid time lost to friction

And that’s just the visible part: waiting, rebooting, retrying, calling “the tech person.”


The reality behind the number


The invisible cost is often bigger:

  • mistakes

  • delayed client responses

  • staff frustration


Why owners are afraid to upgrade


If the math is clear, why do so many owners hesitate?


In our experience supporting small businesses around Grand Rapids and West Michigan, it usually comes down to fear of disruption.


There’s a belief that “updating” means “breaking.”


What we hear from owners


  • “What if the new software doesn’t work with our old printer?”

  • “What if the migration takes three days and we can’t bill clients?”

  • “It’s slow, but at least we know how it works.”

This mindset creates technical debt. And just like financial debt, it accumulates interest.


Windows 10 is the easy example


Windows 10 support ended October 14, 2025.  Devices may still run, but the environment becomes harder to protect and maintain over time.


The “boiling frog” syndrome


Slow tech doesn’t happen overnight. It happens gradually. Your team gets used to it. They stop complaining because they assume, “This is just how it is.”


But here’s what’s happening quietly:


Morale drops


High performers hate being held back by bad tools. In a competitive hiring market, they don’t stay where everything is slow and clunky.


Security gaps widen


Older systems and outdated software are harder to keep patched and protected. And security issues are consistently cited as a leading cause of downtime in industry reporting.


Customer experience suffers


When your front desk says, “Sorry, my computer is slow,” your client hears: “We don’t have our act together.”


The “Digital Friction” self-audit: 10 questions to ask your team


Most business owners assume their tech is fine because nobody is actively complaining. But remember: silence doesn’t mean satisfaction… it often means resignation. Your team has likely stopped reporting the small glitches because they don’t want to be seen as “complainers.”


To find the truth, you have to ask specific questions. Don’t just ask, “Is the computer working?” (They’ll say yes.)


Instead, send out this anonymous 10-question survey to your staff next week. The answers might surprise you.


1. When you turn your computer on in the morning, how long until you can actually start typing?


What this reveals: If the answer is consistently more than ~60 seconds, you may be dealing with aging hardware, bloated startup processes, or outdated scripts. In 2026, most business-class machines should feel close to instant.


2. How many times a week do you restart your computer to make a glitch go away?


What this reveals: Frequent reboots can point to software conflicts, memory issues, or devices running at the edge of their capacity.


3. Is there any specific task (opening a large PDF, saving a file, running reports) that makes you feel like you have time to go get a coffee?


What this reveals: You’ll uncover exact bottlenecks.  Often insufficient RAM, storage performance issues, or slow network access to shared files.


4. Do you use any personal devices or apps to do your work because the company version is too difficult or too slow?


What this reveals: This is Shadow IT. It’s also a security problem. If your team is using personal email or unsanctioned tools to get work done, you’ve got risk and data sprawl.


5. Does the internet speed slow down at specific times of day?


What this reveals: This often points to bandwidth or scheduling problems (ex: backups or sync jobs running during business hours, guest Wi-Fi congestion, or aging network equipment).


6. How often does your VPN or remote connection drop when you work from home?


What this reveals: Remote stability matters here especially in West Michigan winters when weather and schedules force more remote work. Frequent drops may signal firewall/VPN limitations, licensing issues, or unstable configuration.


7. If you could wave a magic wand and fix ONE annoying thing about your computer, what would it be?


What this reveals: The golden nugget. This question almost always uncovers the real silent killer, like a line-of-business app that freezes every time someone prints.


8. Do you spend time searching for files because you can’t remember where they’re saved?


What this reveals: This is typically data governance, not hardware. If the folder structure is chaos, you’re paying staff to hunt instead of work.


9. Do you know who to call if your email looks suspicious, or do you just delete it and hope for the best?


What this reveals: A security training gap. If your team doesn’t have a clear “help button,” they’re guessing and guessing leads to breaches.


10. On a scale of 1–10, does your technology make you feel efficient (10) or frustrated (1)?


What this reveals: The “Net Promoter Score” of your IT. If your average is a 5 or 6, productivity and retention are already being impacted.


**Interpretation for owners**


If you get more than 3 red-flag answers, you don’t just have a computer problem… you likely have a profitability leak.


A user waiting just 5 minutes a day loses ~20 hours per year. Multiply that by 10 employees and you’ve essentially paid for five workweeks of staring at a loading screen.


The fix: a lifecycle schedule (not a surprise bill)


The healthiest businesses we support don’t treat IT updates as surprise events. They treat them like planned operational maintenance.


Recommended lifecycle replacement schedule


  • Workstations: Replace every  3 - 4 years
    (Rotate ~25% of devices each year so there’s never a massive capex hit.)

  • Servers / network gear: Replace every 5 - 6 years
    (Firewalls, switches, Wi-Fi… the stuff that causes “random issues” when it’s aging.)

  • Software + licenses: Audit annually
    (So you’re not paying for tools no one uses… or using tools that no longer fits the job.)

Why a schedule works


When you have a schedule, you remove the emotion. You stop asking, “Can we squeeze another month out of this laptop?” and start asking:


“Is this tool helping us run the business?”


Stop the bleeding


We get it… everyone’s watching the bottom line.


But cutting IT spend by keeping 7-year-old computers is a false economy. You aren’t saving cash. You’re quietly burning productivity.


Industry sources often cite the average cost of downtime as $5,600 per minute (with huge variance by business).


Don’t let the Silent Killer drain your 2026 profits.


Next step: a productivity + technology audit (Grand Rapids + West Michigan)


At IT Systems, LLC, we help businesses in Grand Rapids and across West Michigan build an upgrade plan that’s realistic, budget-friendly, and doesn’t disrupt your workday.


Schedule Your Productivity Audit with IT Systems, LLC



By Greg Johnson August 28, 2026
 When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top, marked "Sponsored," and most people click it without a second thought, because the top result is normally what you wanted. Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it's the official page. How the scam works The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right. When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after, and the download installs malware instead of the real program. Why these ads are so easy to fall for These ads are convincing. They sit above the real result, so they're the first thing you see. They use the real company's name and a web address that looks right. And they show up on a search you started yourself, so they don't feel as suspicious as a random email or text would. Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean, harmless page to the ad reviewers and the real, malicious page to everyone else, so the ad can pass review and still do damage. How common is this? Very. In its 2025 Ads Safety Report , Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster. Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip, and CCleaner, and even Google's own apps, with downloads that installed password-stealing malware. These show up on the everyday searches your team runs. What this means for your business For a business, the risk comes up in two everyday situations: downloading software, and logging in. When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser. When someone logs in, they search for "Microsoft 365 login" or their bank, click the ad rather than the official link, and type their username and password straight into a fake page. In both cases, the problem is info-stealing malware. Once it's on a machine, it can steal saved passwords, browser cookies, and session tokens, which can get an attacker into accounts even when multi-factor authentication is switched on. How to protect your team Scroll past the sponsored results. The ads sit at the top, marked "Sponsored" or "Ad." The real website is usually just below, in the normal results. Don't download software from an ad. Type the maker's web address yourself, or search and use the normal result, then download from the official site. Bookmark the sites you log into. For your bank, Microsoft 365, and other important accounts, use a saved bookmark instead of searching each time. Keep devices and browsers updated. Turn on automatic updates so a bad download is less likely to work. Tell your team this is a thing. Most people have no idea the top result can be a trap and, once they know, they stop clicking it. Frequently Asked Questions Aren't ads at the top of Google checked and safe? Google reviews ads and removes billions that break its rules, but scammers still slip through by showing reviewers a clean page and everyone else the malicious one. A "Sponsored" label doesn't mean the site is safe. What is malvertising? Malvertising is short for malicious advertising: scammers buy online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.

How do I download software safely?

Go to the maker's official website by typing the address yourself, or search and use the normal (non-ad) result. Don't download from a sponsored ad, and don't trust a download that arrives through one. What should I do if someone clicked a scam ad? If they only visited the page, close it and don't enter anything. If they typed a password, change it and turn on MFA. If they downloaded and ran a file, disconnect the device and have your IT provider check it for info-stealing malware. Does an ad blocker help? It can. A reputable ad blocker hides many sponsored results, which takes the fake links off the page before anyone can click them. It isn't a complete fix, so keep the habits above too. Article used with permission from The Technology Press.
Text: QR Code Scams: What They Are and How to Protect Your Michigan Buisiness.
By Greg Johnson August 11, 2026
A QR code scam, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company's s
By Greg Johnson July 15, 2026
Article Summary: Most ransomware operations target small businesses at volume, running through dozens of prospects per month. A 22-person company can be researched in 40 minutes using public records, attacked using session-token theft after a single phishing click, and ransomed within a week. What follows is a step-by-step walkthrough of how that attack unfolds, written from the attacker's perspective, plus the five specific controls that would have stopped it. Each control is included in security tools small businesses already pay for. Small businesses are the most common ransomware target by volume of incidents, even though many small business owners assume hackers focus on larger organizations. A 22-person company has enough revenue to be worth attacking, no dedicated security team to defend it, and a publicly traceable footprint that takes about an hour to research. What follows is a step-by-step walkthrough of how a small business gets attacked, written from the attacker's side. The company in this account is composite, but the methods are accurate to current threat intelligence reporting. After the walkthrough, you'll see five specific points where the attack would have been stopped by controls that come bundled with security tools most small businesses already pay for. Monday: You Become the Target I work regular hours and run a small volume operation. My spreadsheet has about 40 prospects per month, and I prefer businesses between 10 and 50 staff. The reason for that range is economics. Large enterprises have security teams, incident response contracts, and lawyers who make recovery expensive on my end. At the other end of the scale, sole traders rarely have enough at stake to bother with. A 22-person commercial services company sits in the right zone: payroll, customer database, project files, supplier relationships, and an owner who will pay to get the lot back. The return per hour is better at this size than at either extreme. I did not find you through a breach or a tip. I found you on a public business records portal. State business registries, federal contract awards, and county-level licensing databases publish enough detail for me to identify your company, look up your name, estimate your revenue, and pick the most useful person inside the business. One search told me your company name, your registered agent, the contract value of a recent municipal job, and the named contact on the submission. The fact that nothing has gone wrong at your company yet is the strongest signal I get. It tells me your credentials are probably still valid, your staff has not been trained to spot anything, and nobody has had a reason to change a password. A clean record is the first indicator I look for. Tuesday: I Learn Your Org Chart I spend about 40 minutes researching your company today using only a browser. LinkedIn gives me eight of your current employees with their job titles listed. Your office manager has been there for six years and lists “accounts payable, payroll, and supplier invoicing” in her profile summary. Your second admin joined 14 months ago. You list yourself as director, with a sparse profile and a low connection count, which tells me you are unlikely to notice when someone unusual starts engaging with your profile or your company's social media. Public business filings confirm your registered business name and your full legal name. A “meet the team” post from two years ago on your Facebook page lists first names and photos, including someone described as helping out in the office a couple of days a week. One of the commenters shares your surname. I now know who handles your money, what their name is, how long they have been there, what software they probably use (I will check your job ads on Indeed for the phrase “experience with QuickBooks or Sage”), and who in your business has the authority to approve a payment without a second signature. That last person is my primary target. You are harder to reach and probably more cautious. Your office manager has system access, handles supplier payments, and is busy enough that one more email in her inbox does not get scrutinized the way it might if she had nothing else to do. I have not spent a dollar yet. Wednesday: I Buy Your Credentials for $14 Stealer logs are credential packages harvested by infostealer malware that infected someone's personal device, often months or years earlier. The malware records every username and password typed into the machine, then bundles the data for sale. Marketplaces on Telegram channels and forums let buyers search these logs by company email domain. I search for your company's email domain. Two results come back. One is your office manager's work email, with a password that looks like it was saved in her browser. The other is a personal Gmail address that appears to belong to a family member of yours, probably from a device that shared a home network. I pay $14 for the package. It takes four minutes. Your office manager's password follows a common pattern: a pet or child's name combined with a year and an exclamation mark. I check it against HaveIBeenPwned, which is the same free database security professionals use, and find that it appeared in a credential dump from a retail loyalty program breach three years earlier. The password has not been changed since. Your family member's credentials are more interesting than they look at first. The same password, with minor variations, shows up across a streaming service, a gaming account, and your company's Microsoft 365 login. The password works. The only thing standing between me and the inbox is the second factor. Total spend so far: $14. Thursday: I Get Past Your MFA Multi-factor authentication stops a lot of attacks, but the implementation matters more than the checkbox. Simple push-notification fatigue does not work against your office manager's account. Microsoft enabled number matching by default for all Microsoft Authenticator push notifications in May 2023, which means she would have to type a code from her login screen rather than just tap approve. Push bombing fails against that configuration. What still works is adversary-in-the-middle (AiTM) phishing. I send your office manager an email designed to look like a routine Microsoft 365 password reset notification, citing the breach that her password appeared in (the same breach I found her credentials in earlier in the week). The link in the email takes her to a page that mirrors the real Microsoft sign-in screen. That page is a proxy I control. When she enters her password and approves her MFA prompt, my proxy forwards both to the real Microsoft login server. Microsoft validates the credentials, completes the MFA challenge, and issues a session token back to my proxy. I capture the token. She sees a normal login experience on what she thinks is the real Microsoft site, then a “password updated successfully” message. I am now signed in as her. The MFA prompt succeeded, and the session token sits in my browser instead of hers. Microsoft sees a valid authenticated session and treats my activity as legitimate. I had a backup plan in case the email did not get clicked. Earlier in the day, I called your office posing as your IT support company, using a name I found in a Google review you had left 18 months earlier. I told your receptionist that we were seeing unusual login activity on the office manager's account and that I would need her to approve a verification push in the next few minutes. She said the office manager was not at her desk. I said no problem, I would try again later. The call cost me nothing. By Thursday night, I am inside your office manager's Microsoft 365 account. I set up an inbox forwarding rule so her emails copy to an address I control without notifying her, then I wait. Friday 2:47pm: Time to Encrypt I spend 36 hours reading email before I encrypt anything. That dwell time is how I size the ransom correctly. In those 36 hours, I find your cyber insurance policy attached to an email from your broker, with a cyber liability sub-limit of $250,000. A bank reconciliation your office manager sent you two weeks ago shows your business account at around $180,000 at month end. Your customer list sits in a quote template she emailed to herself, and a message thread with a municipal project manager mentions a job starting in three weeks with a hard deadline you cannot afford to miss. I set my ransom at $65,000 in cryptocurrency. That figure is low enough that you will pay rather than fight it, high enough that it is worth my time, and well within what I know you can access. Ransoms set above 10 percent of visible liquid assets tend to get contested. The figure I picked sits below that line. I deploy the encryption payload at 2:47pm on Friday. The timing is deliberate. Your bookkeeper finishes at 3pm on Fridays, which I know from an out-of-office reply I saw in the forwarded emails. You are on a job site, with your calendar synced to the shared inbox. The person most likely to notice something wrong and call for help is already gone, and the person with the authority to make decisions is unreachable. By the time anyone understands what has happened, it is a Friday evening, every file on your shared drive is encrypted, and a ransom note sits on every screen in your office. Total cost to me: $14 for credentials and about six hours of work spread across the week. Five Places This Attack Would Have Died The attack on your business worked because five ordinary things were not in place. None of them were expensive. Most were already bundled into security tools you already pay for. 1. The credential purchase on Wednesday. HaveIBeenPwned is free. Microsoft Entra password protection can detect and block reused or commonly-compromised passwords across your accounts. Enforcing unique passwords per account, through a password manager and through Entra's policies, makes a stolen credential purchase useless for me. 2. The MFA bypass on Thursday night. Microsoft already blocks the simpler push-bombing attack, because number matching has been enabled by default for all Microsoft Authenticator push notifications since May 2023. The current dominant credential-based bypass is adversary-in-the-middle phishing. Defenses include phishing-resistant MFA (FIDO2 hardware keys, passkeys, or Windows Hello for Business), Conditional Access policies that require a compliant or hybrid-joined device, and anti-phishing protection in Microsoft Defender for Office 365. Any one of these would have either prevented the session token capture or made the captured token unusable from my IP address. 3. The inbox forwarding rule. Microsoft 365 allows admins to block external email forwarding rules at the tenant level. With that block in place, the inbox forwarding rule I used to read 36 hours of email would not have worked. I might have encrypted anyway, but I would have been guessing on the ransom size. 4. The 36-hour dwell time. Microsoft Defender for Business, included in Microsoft 365 Business Premium, generates an alert when a new inbox forwarding rule is created. If anyone had been watching those alerts, or if the alerts had been routed somewhere visible, it would have been detected on Thursday night. The most impactful change for a business your size is rarely a new product purchase. The improvement comes from someone reviewing the security alerts that the tools you already pay for are already generating. 5. The public business records. You cannot unpublish a state contracting registry or a federal contract award. That data will stay public. What you can control is what your team chooses to post about their specific responsibilities. Your office manager's LinkedIn profile listed her financial responsibilities in enough detail to make her the obvious target. That detail is worth a conversation with your team, framed as practical security awareness rather than a rule about what people can post. Three Questions to Send Your IT Provider These three questions cover most of where the example attack failed. Each one corresponds to a control that comes bundled with security tools you most likely already pay for. Are we using phishing-resistant MFA (FIDO2 keys, passkeys, or Windows Hello for Business) for finance, admin, and executive logins? Is external email forwarding blocked at the tenant level? Are our security alerts going somewhere, and is someone reviewing them? Article FAQs Do hackers target small businesses? Yes. Most ransomware operations target small and mid-sized businesses because the ratio of payout potential to defensive resources is higher than at either extreme of company size. The volume sweet spot is roughly 10 to 50 staff, where there are assets worth encrypting but no dedicated security team to defend them. What is adversary-in-the-middle (AiTM) phishing? AiTM phishing is a technique where the attacker hosts a proxy page that mirrors a real login screen, such as Microsoft 365 or Google Workspace. When the user enters credentials and approves the MFA prompt, the proxy captures the resulting session token. The legitimate service treats the login as successful, but the session token ends up in the attacker's browser. AiTM has become the dominant credential-based attack vector against Microsoft 365 tenants after the default rollout of number matching ended simpler push-bombing attacks. What is a stealer log? A stealer log is a package of credentials harvested by infostealer malware from an infected personal device. The logs include browser-saved passwords, session cookies, and stored authentication tokens, and they are sold on underground markets for $10 to $20 per package. The malware that creates them typically infects personal computers through pirated software or malicious browser extensions. How much does it cost an attacker to compromise a small business? In the example walkthrough above, the total spend was $14 for stolen credentials and about six hours of work. Costs vary, but the threshold to attempt the kind of attack described in this post sits well below $100. Are there free tools that would have stopped this attack? Several of the controls referenced in the walkthrough come bundled with Microsoft 365 Business Premium licenses that businesses in this size range typically already hold. External forwarding restrictions and Defender for Business alerts are configuration changes rather than new purchases. HaveIBeenPwned is a free check available to anyone. Phishing-resistant MFA hardware keys are a small per-user cost compared with the cost of a successful ransomware incident. Article used with permission from The Technology Press .
Show More
By Greg Johnson August 28, 2026
 When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top, marked "Sponsored," and most people click it without a second thought, because the top result is normally what you wanted. Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it's the official page. How the scam works The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right. When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after, and the download installs malware instead of the real program. Why these ads are so easy to fall for These ads are convincing. They sit above the real result, so they're the first thing you see. They use the real company's name and a web address that looks right. And they show up on a search you started yourself, so they don't feel as suspicious as a random email or text would. Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean, harmless page to the ad reviewers and the real, malicious page to everyone else, so the ad can pass review and still do damage. How common is this? Very. In its 2025 Ads Safety Report , Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster. Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip, and CCleaner, and even Google's own apps, with downloads that installed password-stealing malware. These show up on the everyday searches your team runs. What this means for your business For a business, the risk comes up in two everyday situations: downloading software, and logging in. When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser. When someone logs in, they search for "Microsoft 365 login" or their bank, click the ad rather than the official link, and type their username and password straight into a fake page. In both cases, the problem is info-stealing malware. Once it's on a machine, it can steal saved passwords, browser cookies, and session tokens, which can get an attacker into accounts even when multi-factor authentication is switched on. How to protect your team Scroll past the sponsored results. The ads sit at the top, marked "Sponsored" or "Ad." The real website is usually just below, in the normal results. Don't download software from an ad. Type the maker's web address yourself, or search and use the normal result, then download from the official site. Bookmark the sites you log into. For your bank, Microsoft 365, and other important accounts, use a saved bookmark instead of searching each time. Keep devices and browsers updated. Turn on automatic updates so a bad download is less likely to work. Tell your team this is a thing. Most people have no idea the top result can be a trap and, once they know, they stop clicking it. Frequently Asked Questions Aren't ads at the top of Google checked and safe? Google reviews ads and removes billions that break its rules, but scammers still slip through by showing reviewers a clean page and everyone else the malicious one. A "Sponsored" label doesn't mean the site is safe. What is malvertising? Malvertising is short for malicious advertising: scammers buy online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.

How do I download software safely?

Go to the maker's official website by typing the address yourself, or search and use the normal (non-ad) result. Don't download from a sponsored ad, and don't trust a download that arrives through one. What should I do if someone clicked a scam ad? If they only visited the page, close it and don't enter anything. If they typed a password, change it and turn on MFA. If they downloaded and ran a file, disconnect the device and have your IT provider check it for info-stealing malware. Does an ad blocker help? It can. A reputable ad blocker hides many sponsored results, which takes the fake links off the page before anyone can click them. It isn't a complete fix, so keep the habits above too. Article used with permission from The Technology Press.
Text: QR Code Scams: What They Are and How to Protect Your Michigan Buisiness.
By Greg Johnson August 11, 2026
A QR code scam, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company's s
By Greg Johnson July 15, 2026
Article Summary: Most ransomware operations target small businesses at volume, running through dozens of prospects per month. A 22-person company can be researched in 40 minutes using public records, attacked using session-token theft after a single phishing click, and ransomed within a week. What follows is a step-by-step walkthrough of how that attack unfolds, written from the attacker's perspective, plus the five specific controls that would have stopped it. Each control is included in security tools small businesses already pay for. Small businesses are the most common ransomware target by volume of incidents, even though many small business owners assume hackers focus on larger organizations. A 22-person company has enough revenue to be worth attacking, no dedicated security team to defend it, and a publicly traceable footprint that takes about an hour to research. What follows is a step-by-step walkthrough of how a small business gets attacked, written from the attacker's side. The company in this account is composite, but the methods are accurate to current threat intelligence reporting. After the walkthrough, you'll see five specific points where the attack would have been stopped by controls that come bundled with security tools most small businesses already pay for. Monday: You Become the Target I work regular hours and run a small volume operation. My spreadsheet has about 40 prospects per month, and I prefer businesses between 10 and 50 staff. The reason for that range is economics. Large enterprises have security teams, incident response contracts, and lawyers who make recovery expensive on my end. At the other end of the scale, sole traders rarely have enough at stake to bother with. A 22-person commercial services company sits in the right zone: payroll, customer database, project files, supplier relationships, and an owner who will pay to get the lot back. The return per hour is better at this size than at either extreme. I did not find you through a breach or a tip. I found you on a public business records portal. State business registries, federal contract awards, and county-level licensing databases publish enough detail for me to identify your company, look up your name, estimate your revenue, and pick the most useful person inside the business. One search told me your company name, your registered agent, the contract value of a recent municipal job, and the named contact on the submission. The fact that nothing has gone wrong at your company yet is the strongest signal I get. It tells me your credentials are probably still valid, your staff has not been trained to spot anything, and nobody has had a reason to change a password. A clean record is the first indicator I look for. Tuesday: I Learn Your Org Chart I spend about 40 minutes researching your company today using only a browser. LinkedIn gives me eight of your current employees with their job titles listed. Your office manager has been there for six years and lists “accounts payable, payroll, and supplier invoicing” in her profile summary. Your second admin joined 14 months ago. You list yourself as director, with a sparse profile and a low connection count, which tells me you are unlikely to notice when someone unusual starts engaging with your profile or your company's social media. Public business filings confirm your registered business name and your full legal name. A “meet the team” post from two years ago on your Facebook page lists first names and photos, including someone described as helping out in the office a couple of days a week. One of the commenters shares your surname. I now know who handles your money, what their name is, how long they have been there, what software they probably use (I will check your job ads on Indeed for the phrase “experience with QuickBooks or Sage”), and who in your business has the authority to approve a payment without a second signature. That last person is my primary target. You are harder to reach and probably more cautious. Your office manager has system access, handles supplier payments, and is busy enough that one more email in her inbox does not get scrutinized the way it might if she had nothing else to do. I have not spent a dollar yet. Wednesday: I Buy Your Credentials for $14 Stealer logs are credential packages harvested by infostealer malware that infected someone's personal device, often months or years earlier. The malware records every username and password typed into the machine, then bundles the data for sale. Marketplaces on Telegram channels and forums let buyers search these logs by company email domain. I search for your company's email domain. Two results come back. One is your office manager's work email, with a password that looks like it was saved in her browser. The other is a personal Gmail address that appears to belong to a family member of yours, probably from a device that shared a home network. I pay $14 for the package. It takes four minutes. Your office manager's password follows a common pattern: a pet or child's name combined with a year and an exclamation mark. I check it against HaveIBeenPwned, which is the same free database security professionals use, and find that it appeared in a credential dump from a retail loyalty program breach three years earlier. The password has not been changed since. Your family member's credentials are more interesting than they look at first. The same password, with minor variations, shows up across a streaming service, a gaming account, and your company's Microsoft 365 login. The password works. The only thing standing between me and the inbox is the second factor. Total spend so far: $14. Thursday: I Get Past Your MFA Multi-factor authentication stops a lot of attacks, but the implementation matters more than the checkbox. Simple push-notification fatigue does not work against your office manager's account. Microsoft enabled number matching by default for all Microsoft Authenticator push notifications in May 2023, which means she would have to type a code from her login screen rather than just tap approve. Push bombing fails against that configuration. What still works is adversary-in-the-middle (AiTM) phishing. I send your office manager an email designed to look like a routine Microsoft 365 password reset notification, citing the breach that her password appeared in (the same breach I found her credentials in earlier in the week). The link in the email takes her to a page that mirrors the real Microsoft sign-in screen. That page is a proxy I control. When she enters her password and approves her MFA prompt, my proxy forwards both to the real Microsoft login server. Microsoft validates the credentials, completes the MFA challenge, and issues a session token back to my proxy. I capture the token. She sees a normal login experience on what she thinks is the real Microsoft site, then a “password updated successfully” message. I am now signed in as her. The MFA prompt succeeded, and the session token sits in my browser instead of hers. Microsoft sees a valid authenticated session and treats my activity as legitimate. I had a backup plan in case the email did not get clicked. Earlier in the day, I called your office posing as your IT support company, using a name I found in a Google review you had left 18 months earlier. I told your receptionist that we were seeing unusual login activity on the office manager's account and that I would need her to approve a verification push in the next few minutes. She said the office manager was not at her desk. I said no problem, I would try again later. The call cost me nothing. By Thursday night, I am inside your office manager's Microsoft 365 account. I set up an inbox forwarding rule so her emails copy to an address I control without notifying her, then I wait. Friday 2:47pm: Time to Encrypt I spend 36 hours reading email before I encrypt anything. That dwell time is how I size the ransom correctly. In those 36 hours, I find your cyber insurance policy attached to an email from your broker, with a cyber liability sub-limit of $250,000. A bank reconciliation your office manager sent you two weeks ago shows your business account at around $180,000 at month end. Your customer list sits in a quote template she emailed to herself, and a message thread with a municipal project manager mentions a job starting in three weeks with a hard deadline you cannot afford to miss. I set my ransom at $65,000 in cryptocurrency. That figure is low enough that you will pay rather than fight it, high enough that it is worth my time, and well within what I know you can access. Ransoms set above 10 percent of visible liquid assets tend to get contested. The figure I picked sits below that line. I deploy the encryption payload at 2:47pm on Friday. The timing is deliberate. Your bookkeeper finishes at 3pm on Fridays, which I know from an out-of-office reply I saw in the forwarded emails. You are on a job site, with your calendar synced to the shared inbox. The person most likely to notice something wrong and call for help is already gone, and the person with the authority to make decisions is unreachable. By the time anyone understands what has happened, it is a Friday evening, every file on your shared drive is encrypted, and a ransom note sits on every screen in your office. Total cost to me: $14 for credentials and about six hours of work spread across the week. Five Places This Attack Would Have Died The attack on your business worked because five ordinary things were not in place. None of them were expensive. Most were already bundled into security tools you already pay for. 1. The credential purchase on Wednesday. HaveIBeenPwned is free. Microsoft Entra password protection can detect and block reused or commonly-compromised passwords across your accounts. Enforcing unique passwords per account, through a password manager and through Entra's policies, makes a stolen credential purchase useless for me. 2. The MFA bypass on Thursday night. Microsoft already blocks the simpler push-bombing attack, because number matching has been enabled by default for all Microsoft Authenticator push notifications since May 2023. The current dominant credential-based bypass is adversary-in-the-middle phishing. Defenses include phishing-resistant MFA (FIDO2 hardware keys, passkeys, or Windows Hello for Business), Conditional Access policies that require a compliant or hybrid-joined device, and anti-phishing protection in Microsoft Defender for Office 365. Any one of these would have either prevented the session token capture or made the captured token unusable from my IP address. 3. The inbox forwarding rule. Microsoft 365 allows admins to block external email forwarding rules at the tenant level. With that block in place, the inbox forwarding rule I used to read 36 hours of email would not have worked. I might have encrypted anyway, but I would have been guessing on the ransom size. 4. The 36-hour dwell time. Microsoft Defender for Business, included in Microsoft 365 Business Premium, generates an alert when a new inbox forwarding rule is created. If anyone had been watching those alerts, or if the alerts had been routed somewhere visible, it would have been detected on Thursday night. The most impactful change for a business your size is rarely a new product purchase. The improvement comes from someone reviewing the security alerts that the tools you already pay for are already generating. 5. The public business records. You cannot unpublish a state contracting registry or a federal contract award. That data will stay public. What you can control is what your team chooses to post about their specific responsibilities. Your office manager's LinkedIn profile listed her financial responsibilities in enough detail to make her the obvious target. That detail is worth a conversation with your team, framed as practical security awareness rather than a rule about what people can post. Three Questions to Send Your IT Provider These three questions cover most of where the example attack failed. Each one corresponds to a control that comes bundled with security tools you most likely already pay for. Are we using phishing-resistant MFA (FIDO2 keys, passkeys, or Windows Hello for Business) for finance, admin, and executive logins? Is external email forwarding blocked at the tenant level? Are our security alerts going somewhere, and is someone reviewing them? Article FAQs Do hackers target small businesses? Yes. Most ransomware operations target small and mid-sized businesses because the ratio of payout potential to defensive resources is higher than at either extreme of company size. The volume sweet spot is roughly 10 to 50 staff, where there are assets worth encrypting but no dedicated security team to defend them. What is adversary-in-the-middle (AiTM) phishing? AiTM phishing is a technique where the attacker hosts a proxy page that mirrors a real login screen, such as Microsoft 365 or Google Workspace. When the user enters credentials and approves the MFA prompt, the proxy captures the resulting session token. The legitimate service treats the login as successful, but the session token ends up in the attacker's browser. AiTM has become the dominant credential-based attack vector against Microsoft 365 tenants after the default rollout of number matching ended simpler push-bombing attacks. What is a stealer log? A stealer log is a package of credentials harvested by infostealer malware from an infected personal device. The logs include browser-saved passwords, session cookies, and stored authentication tokens, and they are sold on underground markets for $10 to $20 per package. The malware that creates them typically infects personal computers through pirated software or malicious browser extensions. How much does it cost an attacker to compromise a small business? In the example walkthrough above, the total spend was $14 for stolen credentials and about six hours of work. Costs vary, but the threshold to attempt the kind of attack described in this post sits well below $100. Are there free tools that would have stopped this attack? Several of the controls referenced in the walkthrough come bundled with Microsoft 365 Business Premium licenses that businesses in this size range typically already hold. External forwarding restrictions and Defender for Business alerts are configuration changes rather than new purchases. HaveIBeenPwned is a free check available to anyone. Phishing-resistant MFA hardware keys are a small per-user cost compared with the cost of a successful ransomware incident. Article used with permission from The Technology Press .
Show More

Share this article