Small businesses are now the primary target, not collateral
The comfortable myth is that criminals only chase large enterprises. The data says the opposite: attackers have industrialized, and small organizations — with real money, real customer data, and thin IT — are the efficient target. Florida sits squarely in the blast radius.
This report is deliberately non-technical. Each threat below is paired with the concrete, externally-visible weakness an attacker looks for — the same signals our free Exposure Grade and paid External Attack Surface Assessment check for from the outside, exactly as an adversary would.
What attackers are actually doing to Florida SMBs
1. Business Email Compromise & invoice fraud
Highest $ lossA criminal spoofs an email from your domain — or a vendor's — and redirects a wire transfer, payroll, or a real estate closing. No malware, no "hack." It works because most small-business domains publish no enforcement policy telling the world's mail servers to reject forged mail.
The exposure we check: missing or weak SPF / DKIM / DMARC records. A domain without DMARC at p=reject is trivially spoofable — we can tell in seconds, and so can they.
2. Look-alike domain fraud
Rising fastAn attacker registers a domain that looks like yours — a dropped letter, an rn that reads as an m, or your name on .co instead of .com — and uses it to phish your customers and staff under your brand. If that look-alike also has mail records, it can hold real reply-to conversations, not just serve a fake login page.
The exposure we check: we generate the realistic typo/homoglyph variants of your domain and report the ones that are actually registered and resolving — the launch pads that already exist against your brand.
3. Leaked & reused employee credentials
SilentPasswords harvested by info-stealer malware and prior breaches circulate on criminal forums for years. When an employee reused a password — and many do — an attacker simply logs in. Combined with any internet-facing login, this is the single most common intrusion path for small organizations, and it leaves no trace until it's used.
The exposure we check: we match your domain against breach and info-stealer datasets and report exposed accounts to you — with the passwords masked — so you can force resets before someone else uses them.
4. Ransomware via exposed remote access
Business-endingExposed Remote Desktop (RDP), a public database, or an unguarded VPN is the classic ransomware front door. For a small business, a successful encryption event — plus the data-theft extortion that now accompanies it — is frequently an extinction-level event, not an inconvenience.
The exposure we check: internet-facing management ports and admin panels (RDP/3389, databases, firewall/VPN consoles) that should never be reachable from any IP.
5. Exposed cloud storage & leaked secrets
Common & costlyA misconfigured storage bucket, a .git folder left on a web server, or a .env file containing API keys hands an attacker your data — or the credentials to everything — with no exploitation required. These are configuration mistakes, and they are everywhere.
The exposure we check: publicly readable cloud buckets, exposed source/config files, and secrets on your web-facing hosts.
Who's on the hook — and for which rules
Florida's SMB economy concentrates in exactly the sectors regulators watch. A breach isn't only an operational hit; for these businesses it triggers specific legal obligations.
| Sector | What attackers want | The rule you answer to |
|---|---|---|
| Medical, dental & behavioral health | Patient records (PHI) for extortion & fraud | HIPAA Security Rule — a Security Risk Analysis is mandatory |
| Tax preparers & accountants | SSNs, financials, refund fraud | IRS Written Information Security Plan (WISP) — required to hold a PTIN |
| Property management & real estate | Wire-fraud at closing, tenant data | FTC Safeguards Rule |
| Auto, veterinary & other non-bank finance | Customer financial data | FTC Safeguards Rule |
| Anyone taking card payments | Cardholder data | PCI-DSS |
Healthcare note: the HHS breach portal shows a steady stream of Florida provider breaches affecting 500+ individuals — the majority traced to email compromise and unpatched external exposure, the exact issues above.
What cuts most of the risk
None of these require a big budget. In order of impact for a typical Florida SMB:
- Publish DMARC at
p=reject(with SPF + DKIM) so your domain can't be spoofed for invoice fraud. - Turn on multi-factor authentication everywhere — email, VPN, remote access, admin panels. This single step defeats most leaked-credential attacks.
- Get RDP and databases off the public internet. Put remote access behind a VPN with MFA; never expose a database.
- Check your domain against breach data and force resets on any exposed accounts.
- Watch for look-alike domains impersonating your brand, and defensively register the highest-risk variants.
- Lock down cloud storage — default buckets to private, and scan web servers for stray
.git/.env/backup files. - Do the compliance risk assessment you already owe (HIPAA SRA / IRS WISP / FTC Safeguards). It's required, and it forces the six items above into a plan.
See your exposure the way an attacker does — free
The Breakglass Exposure Grade checks your domain from the outside and returns an A–F score across email spoofability, exposed services, look-alike domains, and leaked credentials — in minutes, no access required. A Breakglass analyst reviews every report.
Get your free Exposure Grade → Book a callReady for the full picture? Our External Attack Surface Assessment maps every internet-facing weakness, chains them into the real attack paths, and maps each finding to your compliance obligations — a report you can hand to your board, your insurer, or your auditor.