Breakglass Consulting · Threat Intelligence

The Florida Small-Business Threat Report

What is actually hitting Florida small businesses this quarter — and the specific exposures an attacker checks for before they pick a target.
Q3 2026 edition · Prepared for owners & operators of Florida SMBs · By a Breakglass analyst
The situation

Small businesses are now the primary target, not collateral

The comfortable myth is that criminals only chase large enterprises. The data says the opposite: attackers have industrialized, and small organizations — with real money, real customer data, and thin IT — are the efficient target. Florida sits squarely in the blast radius.

Top 3
Florida's standing among U.S. states for cybercrime victims & reported losses (FBI IC3)
BEC
Business Email Compromise remains the costliest category of cybercrime by dollars lost
<200
Employee count of the businesses hit hardest — they rarely have a dedicated security team

This report is deliberately non-technical. Each threat below is paired with the concrete, externally-visible weakness an attacker looks for — the same signals our free Exposure Grade and paid External Attack Surface Assessment check for from the outside, exactly as an adversary would.

The threats defining this quarter

What attackers are actually doing to Florida SMBs

1. Business Email Compromise & invoice fraud

Highest $ loss

A criminal spoofs an email from your domain — or a vendor's — and redirects a wire transfer, payroll, or a real estate closing. No malware, no "hack." It works because most small-business domains publish no enforcement policy telling the world's mail servers to reject forged mail.

The exposure we check: missing or weak SPF / DKIM / DMARC records. A domain without DMARC at p=reject is trivially spoofable — we can tell in seconds, and so can they.

2. Look-alike domain fraud

Rising fast

An attacker registers a domain that looks like yours — a dropped letter, an rn that reads as an m, or your name on .co instead of .com — and uses it to phish your customers and staff under your brand. If that look-alike also has mail records, it can hold real reply-to conversations, not just serve a fake login page.

The exposure we check: we generate the realistic typo/homoglyph variants of your domain and report the ones that are actually registered and resolving — the launch pads that already exist against your brand.

3. Leaked & reused employee credentials

Silent

Passwords harvested by info-stealer malware and prior breaches circulate on criminal forums for years. When an employee reused a password — and many do — an attacker simply logs in. Combined with any internet-facing login, this is the single most common intrusion path for small organizations, and it leaves no trace until it's used.

The exposure we check: we match your domain against breach and info-stealer datasets and report exposed accounts to you — with the passwords masked — so you can force resets before someone else uses them.

4. Ransomware via exposed remote access

Business-ending

Exposed Remote Desktop (RDP), a public database, or an unguarded VPN is the classic ransomware front door. For a small business, a successful encryption event — plus the data-theft extortion that now accompanies it — is frequently an extinction-level event, not an inconvenience.

The exposure we check: internet-facing management ports and admin panels (RDP/3389, databases, firewall/VPN consoles) that should never be reachable from any IP.

5. Exposed cloud storage & leaked secrets

Common & costly

A misconfigured storage bucket, a .git folder left on a web server, or a .env file containing API keys hands an attacker your data — or the credentials to everything — with no exploitation required. These are configuration mistakes, and they are everywhere.

The exposure we check: publicly readable cloud buckets, exposed source/config files, and secrets on your web-facing hosts.

By sector

Who's on the hook — and for which rules

Florida's SMB economy concentrates in exactly the sectors regulators watch. A breach isn't only an operational hit; for these businesses it triggers specific legal obligations.

SectorWhat attackers wantThe rule you answer to
Medical, dental & behavioral healthPatient records (PHI) for extortion & fraudHIPAA Security Rule — a Security Risk Analysis is mandatory
Tax preparers & accountantsSSNs, financials, refund fraudIRS Written Information Security Plan (WISP) — required to hold a PTIN
Property management & real estateWire-fraud at closing, tenant dataFTC Safeguards Rule
Auto, veterinary & other non-bank financeCustomer financial dataFTC Safeguards Rule
Anyone taking card paymentsCardholder dataPCI-DSS

Healthcare note: the HHS breach portal shows a steady stream of Florida provider breaches affecting 500+ individuals — the majority traced to email compromise and unpatched external exposure, the exact issues above.

Do this quarter

What cuts most of the risk

None of these require a big budget. In order of impact for a typical Florida SMB:

  • Publish DMARC at p=reject (with SPF + DKIM) so your domain can't be spoofed for invoice fraud.
  • Turn on multi-factor authentication everywhere — email, VPN, remote access, admin panels. This single step defeats most leaked-credential attacks.
  • Get RDP and databases off the public internet. Put remote access behind a VPN with MFA; never expose a database.
  • Check your domain against breach data and force resets on any exposed accounts.
  • Watch for look-alike domains impersonating your brand, and defensively register the highest-risk variants.
  • Lock down cloud storage — default buckets to private, and scan web servers for stray .git/.env/backup files.
  • Do the compliance risk assessment you already owe (HIPAA SRA / IRS WISP / FTC Safeguards). It's required, and it forces the six items above into a plan.

See your exposure the way an attacker does — free

The Breakglass Exposure Grade checks your domain from the outside and returns an A–F score across email spoofability, exposed services, look-alike domains, and leaked credentials — in minutes, no access required. A Breakglass analyst reviews every report.

Get your free Exposure Grade → Book a call

Ready for the full picture? Our External Attack Surface Assessment maps every internet-facing weakness, chains them into the real attack paths, and maps each finding to your compliance obligations — a report you can hand to your board, your insurer, or your auditor.