24/7 SOC active — threats blocked today: 14,209
Threat Intelligence · INS-001
Every brief follows one rule: it does not stop at the company that got attacked. It follows the damage outward to the connected parties who were never targeted, yet still could not operate.
Threat Intelligence Briefs
The cascade library
Every brief here follows one rule: it does not stop at the company that got attacked. It follows the damage outward — to the suppliers, customers, clinics, dealers, stores and partners who were never targeted, never breached, and still could not operate.
Each brief is written to be read in five minutes by someone who does not work in security, and to survive scrutiny by someone who does.
How to read a cascade brief
Every entry answers the same five questions.
The incident, the entry point, the timeline
The organizations harmed who were never attacked
Not “systems” — payroll, deliveries, prescriptions, closings
How long the target was down vs. how long everyone downstream was
Concrete, affordable, and specific to being the connected party
TIER ONE — The defining cascades
BRIEF 01
Change Healthcare · February 2024 · Healthcare payments
Attackers signed in to a remote access portal using a stolen password on an account that had no multi-factor authentication, moved through the network for nine days, and deployed ransomware. The company processed roughly one in three US patient records.
The cascade. Nobody attacked the medical practices. They simply lost the pipe that turns care into cash. In a hospital association survey of around a thousand hospitals taken weeks after the attack — a self-selected member survey, not a random sample — 94% reported financial impact and roughly six in ten reported revenue impact of a million dollars a day or more. Two months later, a physician association survey of nearly six hundred practices found 90% still losing revenue, 62% covering expenses from personal funds, and 34% unable to make payroll. Both are self-selected member surveys, not random samples — these are reported figures, not measured ones.
Why it belongs first. This is the clearest demonstration on record that a single missing control at an organization you don’t own can put your own staff’s wages at risk. One account, no second factor — and two months later, ninety percent of surveyed practices were still losing revenue.
The transferable lesson. Know which single intermediary your revenue flows through, and contract a warm alternate before you need it. Two-thirds of surveyed hospitals said switching providers mid-crisis was difficult or very difficult — the lock-in was the damage multiplier.
BRIEF 02
CDK Global · June 2024 · Automotive retail
Ransomware hit the software platform that runs roughly 15,000 North American car dealerships. The vendor was restored in about two weeks. The dealerships were not.
The cascade. Dealerships are independent businesses. None of them were attacked. All of them stopped functioning — no financing, no titling, no warranty claims, no parts ordering, and in many cases no payroll. Dealers described single transactions, written by hand, taking six hours. An independent economic consultancy — not a security vendor — put direct dealer losses at $1.02 billion over three weeks, including roughly 56,200 lost new-vehicle sales, and explicitly excluded consumer, legal and manufacturer losses from that figure. It is a floor, not a total.
The detail that stays with people. Dealers discovered their entire customer history existed only inside a system they did not control.
The transferable lesson. Export your customer and open-order data on a schedule to somewhere your vendor cannot reach. Write down the manual version of how you take money, and rehearse it once a year. Then check whether your insurance covers business interruption caused by someone else’s outage — many dealer policies did not.
BRIEF 03
MOVEit / Progress Software · May 2023 · Everyone
A single flaw in a widely used file-transfer product was exploited at scale over a holiday weekend by a criminal group that had been researching it for two years.
The cascade. The overwhelming majority of the roughly 95.8 million individuals and 2,773 organizations affected had no relationship whatsoever with the software or its maker. They were customers, patients, students and pensioners of organizations that used a vendor that used a contractor that used this product. A single instance at one student-records non-profit cascaded to nearly nine hundred colleges. Education accounted for 39% of the affected organizations and healthcare for 20%.
The honest part. Almost no downstream victim could have patched their way out. They didn’t run the software. They didn’t know it existed.
The transferable lesson. You cannot patch someone else’s software, but you can control how much of your data sits inside it and for how long. The difference between a bad outcome and a catastrophic one was usually how much historical data the vendor was still holding. Data minimization is a supply chain control.
Note on a figure you will see elsewhere: the widely quoted multi-billion-dollar cost of this event is an extrapolation from average per-record breach costs, not a measured loss. We don’t use it.
BRIEF 04
United Natural Foods · June 2025 · Grocery distribution
North America’s largest publicly traded grocery wholesaler shut down its own network after detecting an intrusion. Ordering came back in eleven days; core systems in three weeks. The company estimated up to $425 million in impact and still raised its annual sales outlook.
The cascade — and the natural experiment. The independent grocers and co-ops it supplies had no such cushion. Reporting at the time captured four of them, and the outcomes track supplier concentration almost perfectly:
The transferable lesson. Know what percentage of your cost of goods sits with your largest supplier. That number is your risk assessment. A second supplier relationship costs you margin — and that margin is the price of continuity. Do the arithmetic explicitly instead of defaulting to sole source.
BRIEF 05
PowerSchool · December 2024 · Education technology
Attackers used stolen credentials to reach a customer support portal and pull student information databases. The company paid a ransom on the stated belief it was in customers’ best interests. The perpetrator was later prosecuted and sentenced to four years.
The cascade, and the twist. Months after the payment, the attacker began extorting individual school districts directly, using the same data. Districts that had suffered no breach of their own, taken no action of their own, and been told the matter was resolved, received their own ransom demands — and had to run their own legal, notification and parent communication response.
The transferable lesson. A vendor’s ransom payment does not end your exposure, and their “resolved” is not your all-clear. Ask what data a vendor retains about your people and for how long — districts were exposed on students who had graduated years earlier. Keep a notification plan you can execute without the vendor, because you may be the one who gets contacted.
BRIEF 06
Salesloft Drift → Salesforce · August 2025 · SaaS integrations
Attackers reached a vendor’s source code repositories, pivoted into its cloud environment, and stole the authorization tokens connecting that vendor’s chat product to its customers’ CRM systems. Over ten days they queried hundreds of instances, deliberately hunting for credentials stored inside support tickets.
The cascade. More than 700 organizations were potentially affected. None were attacked. They had installed a chat widget. The victims who disclosed publicly were disproportionately cybersecurity companies — some of the most capable security teams in the world.
Why that matters for the framing. If firms whose entire business is security could not prevent this, the honest message is not you were careless. It is: this class of risk is not solved by being careful.
The transferable lesson. Authorization tokens bypass multi-factor authentication entirely — MFA on the CRM protected none of these companies. Audit the connected apps in your Microsoft, Google, Salesforce and HubSpot tenants and revoke everything nobody can name an owner for. Never paste credentials or API keys into a support ticket, and search your existing tickets for the ones already there.
BRIEF 07
Snowflake customer accounts · April–June 2024 · Cloud data platforms
Roughly 165 customer environments were accessed using credentials stolen years earlier by password-stealing malware — some dating back to 2020. Investigators found nearly 80% of the accounts used had prior known credential exposure, and stated explicitly that no breach of the platform provider was involved.
Why this brief is the inverse case. Every other entry in this library says your vendor’s failure became your problem. This one says the opposite: no compromise of the platform was involved — though it did not then require multi-factor authentication, and changed that afterwards — and it was still catastrophic. Three conditions made it possible, all of them on the customer side — accounts without multi-factor authentication, credentials never rotated, and no restriction on where logins could come from.
The lesson for anyone who is somebody else’s supplier. Many of the stolen credentials came from contractor and personal devices used for both work and browsing. A small agency’s infected laptop became a Fortune 500 data breach. Stolen credentials do not expire — “that was years ago” is not a defense.
TIER TWO — Supporting briefs
BRIEF 08
NCR Aloha POS · April 2023 · Restaurants and hospitality
A ransomware attack on a single data center serving hospitality point-of-sale systems. Card transactions in restaurants kept working. What broke was everything around them — back-office tools, loyalty and gift card handling, menu and price changes, and payroll processing.
Why it’s instructive. The failure mode was partial and counterintuitive. Independent operators could take money but could not pay staff. For a small restaurant that becomes existential within one pay cycle. Know which parts of your point-of-sale are local and which are cloud, and keep an offline export of hours and rates so payroll can run by hand.
BRIEF 09
Blue Yonder · November 2024 · Supply chain and workforce software
Ransomware in a hosted services environment disrupted employee scheduling and hour tracking at a major coffee chain — which reverted to pen and paper and still paid everyone — and degraded fresh-food warehouse management at two large grocers.
Why it’s here despite modest damage. Timing is a threat variable. This landed the day before Thanksgiving; the dealer, grocery and manufacturing cascades in this library all struck at operationally critical moments. Map which vendor outages would hurt most during your peak season, and rehearse those specifically.
We publish no downstream loss estimate for this event because none exists.
BRIEF 10
Clorox and its outsourced IT provider · August 2023 · Consumer goods
Attackers called an outsourced IT help desk and, according to allegations in ongoing litigation, had an employee’s password and multi-factor authentication reset without authenticating the caller. Production and shipping were disrupted for months.
Status note. The dollar claim and the password-reset account are allegations in an active lawsuit, not adjudicated findings. We present them as such.
The transferable lesson. If you use a managed service provider or outsourced help desk, their identity-verification procedure is your security control. Ask what they require before resetting a password or an authentication factor. Require callback to a known number plus manager approval for privileged resets — and get it in writing.
BRIEF 11
SonicWall cloud backup · September 2025 · Network security
An unauthorized party accessed firewall configuration backup files held in a vendor cloud service. The disclosure was initially scoped at under five percent of devices and later revised to all customers who had used the backup feature.
Why it belongs in a library for smaller organizations. This product line is heavily used by smaller businesses and the providers that serve them. The stolen files are snapshots of network topology, VPN configuration and rule sets — an attacker holding yours knows where your walls are thin. The affected organizations did nothing wrong; they used a vendor-recommended feature.
The transferable lesson. Vendor cloud convenience features create a copy of your secrets outside your control. Before enabling cloud backup, config sync or key escrow anywhere, ask what is inside the file and what happens if the vendor loses it. And act on the worst-case scope, not the first disclosure — “under five percent” became “everyone.”
BRIEF 12
Ingram Micro · July 2025 · IT distribution
Ransomware took down ordering platforms at one of the world’s largest technology distributors over a holiday weekend. Resellers and managed service providers could not place orders; ordering was restored by phone and email over several days.
The three-layer cascade. The immediate victims were the providers — themselves small businesses — and behind them their customers, who could not get hardware or license renewals provisioned. One provider executive publicly described removing third-party privileged access to client environments out of concern the compromise could reach further down the chain.
The transferable lesson. Ask your IT provider what standing privileged access they hold into your Microsoft or Google tenant, and whether it is permanent or granted just in time. Permanent delegated administration means their bad week is automatically your bad week.
BRIEF 13
Salt Typhoon · 2023–2025 · Telecommunications
A state-linked campaign compromised telecommunications providers, with government agencies reporting targeting across more than eighty countries and later expanding the known target set well beyond telecom.
The mobile asset angle. Every customer of a compromised carrier — including every small business and every employee handset on that network — had communications metadata exposed without any compromise of their own devices. National cyber authorities responded with specific mobile communications guidance.
The transferable lesson. Use end-to-end encrypted messaging and calling for anything sensitive. Stop using text messages as your second authentication factor: carrier-level compromise and SIM swapping both defeat it. Move to an authenticator app or a hardware key.
BRIEF 14
Jaguar Land Rover · August–October 2025 · Automotive manufacturing
A cyberattack halted production for roughly five weeks. An independent monitoring body assessed it as a systemic event affecting more than five thousand organizations, with a central estimate near £1.9 billion — the vast majority from lost manufacturing output at the manufacturer and its suppliers.
Status note. That estimate is explicitly scenario-based modelling by an independent body, not measured operational data. We label it accordingly.
The detail that lands. The same analysis documented suppliers facing severe cash flow strain, including at least one owner taking out a personally backed loan to keep the business alive — because of an attack on someone else’s network.
The transferable lesson. If more than about thirty percent of your revenue or receivables sits with one customer, that is a named risk. Arrange a credit line before you need it; you cannot arrange one in week three of someone else’s crisis. And check whether contingent business interruption cover is available to you — most standard policies require your systems to be affected, which in these cascades they never are. That gap is the most expensive line on this page.
The pattern across all fourteen
Set the briefs side by side and one finding repeats without exception.
The attacked company’s recovery is a systems problem, measured in weeks. The connected company’s recovery is a cash flow problem, measured in months — and it begins roughly where the attacked company’s ends. Backlog, delayed receivables and departed customers only materialize once service resumes.
~2 weeks
Dealer backlogs described in the trade press as months, if not years
Weeks to months
90% of surveyed practices still losing revenue two months later
~3 weeks
Independent grocers absorbed lost sales and emergency supply premiums, uncompensated
~5 weeks to limited output
Suppliers in severe cash flow strain, personally guaranteed borrowing
Resolved
Districts extorted after the vendor declared it closed
The education case is the extreme: downstream harm arrived entirely after the vendor’s recovery was complete.
We present this as an observed pattern across documented incidents, not as a statistic — because no rigorous general dataset comparing downstream to primary recovery time exists.
What we don’t publish
No aggregate estimate exists of losses to independent grocers, small pharmacies or dental practices in the incidents above. Those businesses were harmed, and nobody counted.
No documented case meets our evidence bar for a fleet or logistics telematics compromise cascading to small carriers. The claims exist; the sourcing doesn’t. We will publish when it does.
Several widely circulated figures attached to these events — a ransom amount here, a total cost there — trace to unnamed sources or to extrapolation. Where we’ve used them at all, we’ve labeled them.
Briefs in preparation
Defending small & mid-sized businesses across the USA and U.S. territories. Eleven walls. One way through.
Healthcare
Legal
Manufacturing
Retail
Credit Unions
Gov Contractors
© 2026 way11.io · All rights reserved · Serving the USA & U.S. Territories
Privacy · Terms · Accessibility · Responsible Disclosure