The Breach That Did Not Need a Hacker

The Breach That Did Not Need a Hacker"The most dangerous person on your network is not a stranger. Most days, it is someone with a badge and a password." Josh Wilmoth, President and CEO, CTTS

I want to tell you about two headlines from the past month that made me sit up straight at my desk.

The first was CenterPoint Energy, right here in Texas, confirming in mid September that a hacker walked away with personal information tied to roughly 7.5 million customer accounts. The second was a campaign that hit McDonald's and Vodafone, where an attacker calling himself TheHatman pulled more than two million employee records out of their Microsoft systems, not by smashing through a firewall, but by using credentials that were simply lying around.

Here is what ties those two stories together, and it is the same thing I want every client of ours to hear this month. In 2026, the break-in rarely looks like a break-in. It looks like someone logging in like they belong there.

Why The Front Door Matters More Than The Walls

Security researchers tracking this trend reported something that stopped me cold. Password spraying attacks, where criminals quietly try common passwords across huge numbers of accounts, are up 155 times over compared to last year. One single campaign generated more than 81 million login attempts in a two week span.

What makes this worse is that most of the businesses hit in that study were not careless. They had multi-factor authentication turned on. They just had gaps in it. A forgotten application here. An older sign in method there. One excluded user group. Criminals do not need to break your security. They just need to find the one door you forgot to lock.

That is the real story behind both CenterPoint and the McDonald's incident. Somewhere in the chain, a login worked when it should not have.

Who Still Has a Key To Your Building

Think about your own business for a second. If someone left your company eight months ago, do they still have access to anything? If a vendor project wrapped up last spring, did anyone remember to close that door behind them?

I ask because this is the single most common gap I see when we do a security assessment for a new client. It is rarely the exotic stuff. It is a former employee's email still active, an administrator account nobody remembers creating, or a password that has been shared among three people since 2022. None of that requires a sophisticated hacker. It just requires someone finding it.

The Part That Costs You Nothing

Here is the good news, and it is genuinely good news. Almost everything that would have stopped the incidents above does not require a bigger budget. It requires discipline.

Turning on multi-factor authentication everywhere, not just where it is convenient, costs nothing extra on most Microsoft 365 and Google Workspace plans. Removing old accounts costs nothing but a checklist. Reducing how many people have administrator rights costs nothing but a conversation. These are not enterprise security investments. They are housekeeping. And housekeeping is exactly what gets skipped when everyone is busy running a business, which is precisely why criminals are counting on it.

Three Questions Worth Asking This Week

Before you set this newsletter down, I want you to think through three things with your team.

Do you know exactly who has administrator access to your systems right now, and could you name every one of them?

If an employee or contractor left tomorrow, is there a documented process that removes their access the same day, not the same month?

Is multi factor authentication turned on for every account that touches company data, with no exceptions carved out for convenience?

If you answered all three with confidence, you are in better shape than most of the businesses we assess. If you hesitated on any of them, you are not alone, and you are exactly who this is for.

Why This Matters To Me

I have spent 22 years building CTTS around one idea. Technology should make your business stronger, not be the thing that quietly takes it down. Healthcare practices, legal offices, construction firms, and manufacturers across Georgetown, Round Rock, Austin, and Cedar Park trust us because we don't wait for something to break. We go looking for the gaps first.

The businesses that get hurt worst by incidents like the ones above are rarely the ones without any security. They are the ones who assumed the basics were covered and never checked.

Do not let that be your business.

Schedule a free strategy session with CTTS. We will walk through exactly who has access to what in your systems, close the gaps that do not cost you a dime to fix, and give you a clear picture of where you actually stand.

Visit CTTSonline.com or call us at (512) 388-5559.

Josh Wilmoth President and CEO, CTTS

P.S. My wife asked why I was laughing at my laptop last week. I had just found a password on a sticky note in a prospect's server closet. The password was "Password1." The sticky note was labeled "Do Not Share." I have never seen an instruction followed so poorly in my life.


Contact CTTS today for IT support and managed services in Austin, TX. Let us handle your IT so you can focus on growing your business. Visit CTTSonline.com or call us at (512) 388-5559 to get started!