The past seven days delivered a clear message to small and mid-size businesses across North America: your exposure is rarely just your own. A wave of incidents disclosed between September 4 and September 11 traced back not to sophisticated exploits, but to single stolen credentials, misconfigured cloud storage, and forgotten vendor tokens — each one cascading into dozens or hundreds of downstream organizations. For business owners, the lesson is less about any one breach and more about the pattern: identity is now the perimeter, and vendors are the weakest link in it.

The Vendor Cascade: One Stale Credential, 200 Companies Affected

The clearest illustration of supply-chain risk this year continues to widen its blast radius. A four-year-old, unrotated Salesforce credential at a company called Klue gave threat actors a foothold that spread into the Salesforce and Gong environments of nearly 200 companies, several of them cybersecurity vendors themselves. Datadog Security Labs has traced the extortion crew, which calls itself Icarus, to activity dating back to at least April 28, 2026, before it began harvesting Salesforce and Gong OAuth tokens through a dormant credential on June 11, 2026, opening a path into the Salesforce environments of close to 200 companies. LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium and Huntress all confirmed they lost business data in the incident. The takeaway for SMBs: your vendor's forgotten API token is now your breach notification obligation. Expect renewal questionnaires to ask more directly about credential age and OAuth grant review cadence, not just whether a vendor risk program exists.

A Single Employee Credential Brought Down a State Database

On the individual-employee side, Florida's motor vehicle agency confirmed a breach that started with exactly one person's login. FLHSMV learned of a data breach conducted by an international cybercriminal organization after a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device. A criminal-targeting extortion group known as ShinyHunters has claimed responsibility, and Mathspace, an online math learning platform, separately disclosed that attackers stole data from more than 1 million students, staff, and parents after breaching its internal reporting system. Both incidents underline the same operational failure businesses keep repeating: credentials stored outside approved, monitored systems remain the single most common entry point for identity-based intrusions.

Breach Databases Are Growing Faster Than Detection Can Keep Up

The scale of exposed credentials sitting in breach databases continues to outpace enterprise defenses. None of the increased spending on infostealer detection stopped a 24-billion-record database from sitting exposed for days. Commercial real estate services firm Berkadia also joined the list of confirmed victims this week, with a data breach involving Berkadia, a commercial real estate services company, with 10 million records leaked, posted by ShinyHunters on BreachForums. For any business handling client financial or property records, this is a direct reminder that breach notification laws apply regardless of company size, and regulators are increasingly unforgiving of delayed disclosure.

What Individuals Should Do This Week

  • Check your work and personal email addresses against breach databases and rotate any password reused across more than one account.
  • Enable multi-factor authentication on all financial, email, and cloud storage accounts — session-token theft is now bypassing passwords entirely in active phishing kits.
  • Avoid storing work credentials on personal devices, exactly the failure point that triggered the FLHSMV breach.

What Businesses Should Do This Week

  • Audit vendor OAuth tokens and API keys for age — a credential left unrotated for years was the entry point for the 200-company Klue cascade.
  • Require breach notification clauses and credential-rotation cadence commitments in every vendor contract renewal.
  • Monitor your company domain against breach databases and criminal-targeting sources continuously, not just after a public disclosure — by the time a breach makes headlines, employee credentials may have circulated for weeks.
  • Review where employee and customer data lives across third-party SaaS tools; as this week showed, your compliance exposure often runs through a vendor's misconfigured system, not your own.