8776363957
Connect with us:
LinkedIn link
Facebook link
Twitter link
YouTube link
Gigabit Systems logo
Link to home
Who We AreManaged ServicesCybersecurityOur ProcessContact UsPartners
The Latest News in IT and Cybersecurity

News

A cloud made of diagonal linesA cloud made of diagonal lines
A pattern of hexagons to resemble a network.
Cybersecurity
Technology
Must-Read

Hackers are attacking America’s water supply

August 16, 2026
•
20 min read

Hackers Are Reaching Through the Internet and Touching America’s Water

This cyberattack didn’t steal data. It changed water pressure.

When most people hear “cyberattack,” they imagine stolen passwords, ransomware or leaked customer information.

This attack crossed a much more disturbing line.

Hackers have been targeting internet-connected industrial controllers used by American water and wastewater utilities—and in some cases, the consequences moved beyond computer screens and into the physical world.

Water pressure dropped.

Equipment stopped responding normally.

Flooding occurred.

Water and wastewater facilities in at least seven states reported attempted compromises, according to federal authorities.

More than 30 community water systems in Minnesota alone were reportedly targeted during one coordinated wave. (Anadolu Ajansı)

The attackers weren’t simply trying to steal files from an office computer.

They were targeting machines that help control the water itself.

Meet the Computer That Controls the Physical World

The devices at the center of the federal warning are called:

Programmable Logic Controllers—or PLCs.

Most people will never see one.

But PLCs are everywhere.

They’re specialized industrial computers used to control physical equipment.

A PLC might tell a pump:

Turn on.

Turn off.

Run faster.

Run slower.

Open a valve.

Close a valve.

Maintain a particular pressure.

At a water utility, these systems can be part of the infrastructure responsible for moving and managing enormous amounts of water.

And attackers were reportedly reaching some of them through the public internet.

The Hackers Changed the Passwords

According to the FBI and EPA, attackers targeted internet-facing Rockwell Automation/Allen-Bradley PLCs.

They remotely changed things including:

IP addresses.

Passwords.

Those changes could prevent legitimate operators from monitoring or controlling equipment normally. (Anadolu Ajansı)

Think about what that means.

You’re responsible for operating a municipal water system.

You open your control interface.

The password doesn’t work.

Or the controller isn’t where your network expects it to be anymore.

Meanwhile, the equipment that computer controls is still connected to actual pumps, valves and water infrastructure.

The attacker didn’t merely lock you out of a computer. They potentially interfered with your ability to control a physical process.

Some Attacks Had Physical Consequences

Federal authorities say some malicious activity degraded water operations.

Reported consequences included:

Loss of water pressure.

Flooding.

That distinction matters.

Cybersecurity has spent decades warning that attacks against operational technology could eventually produce real-world consequences.

This is what that transition looks like.

Bits become pressure.

Commands become pump behavior.

Network settings become physical disruption. (The Wall Street Journal)

Fortunately, operators in affected systems were able in some cases to switch to manual controls or other alternatives.

There have been no reports that the latest attacks contaminated drinking water. (The Wall Street Journal)

But that’s not a reason to dismiss what happened.

It’s a reason to understand how close digital infrastructure now sits to physical infrastructure.

Why Would Anyone Put a Water Controller on the Internet?

There’s a legitimate reason.

Remote access is incredibly useful.

A small municipal utility may have limited personnel covering facilities spread across a large geographic area.

Instead of driving to every pump station, tank or treatment facility, operators can remotely:

Monitor equipment.

Check alarms.

Review pressure.

Diagnose problems.

Change settings.

Restart systems.

That can save enormous amounts of time and money.

But remote access creates a dangerous equation:

If you can control it remotely, somebody else may try to control it remotely too.

The problem becomes especially serious when industrial equipment was designed primarily for reliability and availability—not for surviving attacks from adversaries scanning the entire internet.

The Internet Is Constantly Being Scanned

One misconception businesses have is:

“Nobody knows our system is there.”

That’s increasingly meaningless.

Attackers continuously scan the internet looking for exposed:

Firewalls.

VPN appliances.

Remote desktops.

Cameras.

Servers.

Routers.

Industrial controllers.

Human-machine interfaces.

They don’t necessarily need to target your municipality by name.

They can search for a type of vulnerable device and discover your municipality afterward.

EPA and CISA have specifically warned that internet-exposed industrial interfaces can be discovered using publicly available internet-scanning platforms. (CISA)

In other words:

The attacker doesn’t need to ask:

“How do I hack this water utility?”

They can ask:

“Show me exposed industrial controllers.”

Then start working down the list.

Small Town Doesn’t Mean Small Target

This is one of the most important lessons.

A tiny municipal water authority may think:

Why would a sophisticated attacker care about us?

Because the attacker may not care who you are.

They care that you’re vulnerable.

And smaller utilities can sometimes be attractive precisely because they have:

Smaller IT budgets.

Older equipment.

Limited cybersecurity staff.

Legacy industrial systems.

Remote-access requirements.

Few people available overnight.

EPA has acknowledged significant cybersecurity weaknesses throughout the water sector. In work conducted during 2025, the agency identified vulnerabilities at 277 water systems and helped address hundreds of issues. (US EPA)

Cybersecurity isn’t only a Fortune 500 problem anymore.

A town with 2,000 residents can sit on the same hostile internet as a multinational bank.

There Is an Important Difference Between IT and OT

Businesses protect IT.

Email.

Microsoft 365.

Laptops.

Servers.

Customer databases.

Water facilities also operate OT—Operational Technology.

OT controls physical processes.

And securing OT requires a different mindset.

If an employee’s laptop crashes, that’s inconvenient.

If a water-treatment control system stops functioning, operators may have to maintain a public utility manually.

If an industrial process is incorrectly manipulated, equipment can potentially be damaged.

Availability and safety become just as important as confidentiality.

You aren’t only protecting information. You’re protecting physics.

Why “Just Patch It” Isn’t Always Easy

Industrial environments can contain equipment expected to operate for decades.

Some systems cannot simply be rebooted Tuesday afternoon because a software update became available.

Updates may need testing.

Maintenance windows may be limited.

Specialized vendors may be involved.

Old equipment may no longer support modern security controls.

And shutting down the system itself can disrupt operations.

That’s why protecting operational technology requires layers around the equipment—not simply antivirus installed on everything.

Federal Agencies Are Giving Water Utilities Very Basic Advice

And that’s perhaps the most concerning part.

Many of the recommendations aren’t futuristic cybersecurity technologies.

EPA, FBI and CISA have repeatedly emphasized fundamentals:

Remove operational technology from direct public internet exposure whenever possible.

Use strong authentication.

Change default passwords.

Strictly control remote access.

Maintain accurate inventories of IT and OT equipment.

Back up critical systems.

Monitor configuration changes.

Develop and practice incident-response procedures.

And maintain the ability to operate manually when digital systems become unavailable. (US EPA)

That last recommendation deserves attention.

Manual Control May Be the Ultimate Backup

We usually think about backups as copies of data.

Operational technology needs another kind of backup:

A way to operate without the computer.

Can employees run the system if remote access disappears?

Do they know how?

Are procedures documented?

When was the last time anybody actually practiced it?

EPA’s 2026 national cybersecurity exercise specifically challenged water utilities to operate when internet connectivity, telecommunications, SCADA remote access, cloud services and other digital systems became unavailable. (US EPA)

That’s excellent cybersecurity thinking.

Don’t merely ask:

“How do we prevent an attack?”

Ask:

“How do we keep operating after prevention fails?”

Every Business Should Ask the Same Question

You probably don’t operate a water-treatment plant.

But your business may have its own version of an exposed PLC.

A firewall with remote administration enabled.

An old server reachable from the internet.

A forgotten remote desktop connection.

A security camera with default credentials.

A building-access controller.

An HVAC system.

A vendor-maintained appliance.

A copier.

An IoT device nobody remembers installing.

Your MSP should know every internet-facing asset your organization owns and why it needs to be exposed.

If nobody can explain why something needs direct internet access:

It probably shouldn’t have it.

Healthcare, Law Firms and Schools Have Physical Dependencies Too

This matters beyond utilities.

Hospitals depend on building controls, medical infrastructure and network-connected equipment.

Schools operate cameras, door-access systems, HVAC equipment and other connected technology.

Law firms and SMBs increasingly occupy “smart” buildings containing network-connected access, environmental and security systems.

The traditional boundary between cybersecurity and physical security is disappearing.

A compromised account can open a file.

A compromised controller can open a valve.

Both are cybersecurity problems.

The Water Coming From Your Faucet Depends on Computers

That’s the uncomfortable lesson.

Modern civilization quietly depends on thousands of computers most people never see.

They move water.

Manage electricity.

Control manufacturing.

Coordinate transportation.

Operate buildings.

Run telecommunications.

And increasingly, some of those systems are connected—directly or indirectly—to the same global internet containing criminals, hacktivists and nation-state operators.

The latest water-system attacks didn’t create a national public-health disaster.

Operators contained the damage.

Manual systems worked.

Water continued flowing.

That’s good news.

But pressure loss and flooding should be treated for what they are:

A warning shot.

Because ransomware stealing files is expensive.

A cyberattack manipulating the physical systems keeping a city alive is something entirely different.

The next critical infrastructure breach may not appear on your screen.

You may notice it when you turn on the faucet.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #CriticalInfrastructure #DataProtection #ManagedIT #CyberSecurityAwareness


Travel
Cybersecurity

Hackers Hijacked the Wi-Fi on a Delta Flight

August 13, 2026
•
20 min read

Hackers Hijacked the Wi-Fi on a Delta Flight

The plane was real. The Wi-Fi network wasn’t.

A bizarre cybersecurity incident reportedly unfolded aboard Delta Flight 591 from Las Vegas to Atlanta after passengers returning from DEF CON 34, one of the world’s largest cybersecurity conferences, created a rogue Wi-Fi network while the aircraft was in flight.

According to reports, passengers aboard the flight suddenly lost access to Delta’s normal in-flight Wi-Fi.

Then another network appeared:

“DELTA WIFI FAST.”

It wasn’t Delta.

The situation became serious enough that the pilots contacted Delta’s operations center through ACARS, the aircraft’s text-based communications system, and asked that corporate security be alerted.

One cockpit message reportedly warned that passengers returning from a cybersecurity conference had been able to interfere with the Wi-Fi and broadcast their own signal.

A second was even more explicit:

“WE HAVE A PAX ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST.”

The crew ultimately shut down passenger Wi-Fi for approximately 30 minutes while the situation was investigated.

When Flight 591 landed in Atlanta, law enforcement reportedly boarded the aircraft and questioned several passengers.

Welcome home from DEF CON.

What May Have Happened at 35,000 Feet

The reported attack resembles what’s known as an evil twin attack.

Instead of breaking into the legitimate network, an attacker creates another wireless network designed to look like it.

Imagine opening your phone’s Wi-Fi menu aboard a Delta aircraft and seeing:

DeltaWiFi

and

DELTA WIFI FAST

Which one do you choose?

To an exhausted traveler trying to get online, the second one might even sound better.

Connect to the attacker’s network and you can potentially be redirected to a fake captive portal designed to resemble the legitimate airline internet page.

From there, the attacker could attempt to collect information users voluntarily enter—such as email addresses, passwords or other credentials.

That’s why evil-twin attacks are so effective.

The attacker doesn’t necessarily hack your device. They convince you to connect to theirs.

Reports Suggest Something Even More Aggressive

Some accounts of the incident allege the passengers didn’t simply broadcast a competing hotspot.

They may have used portable wireless security-testing equipment—devices in the same general category as tools used by legitimate penetration testers—to interfere with connections to the legitimate network.

One technique capable of disrupting Wi-Fi clients is commonly called a deauthentication attack.

Conceptually, the attack repeatedly tells connected devices:

“You’ve been disconnected.”

The victim’s phone or laptop begins searching for Wi-Fi again.

And conveniently, another convincing network is waiting nearby.

DELTA WIFI FAST.

That combination would make an evil-twin attack substantially more effective: disrupt the legitimate connection, then offer the victim an attractive replacement.

However, the currently available reporting does not conclusively establish the specific equipment or exact wireless technique used, so those details should be treated as allegations rather than confirmed forensic findings.

The Airplane Was Never Hacked

This distinction is extremely important.

Despite how frightening “hackers jam Wi-Fi aboard an airplane” sounds, Delta says:

No aircraft operating systems were affected.

Delta also says there wasn’t an actual compromise of its in-flight Wi-Fi system itself.

The aircraft remained safe.

The alleged attack concerned the passenger internet environment, not flight controls, navigation or avionics.

That’s reassuring.

But from a cybersecurity perspective, the passenger threat remains very real.

You Don’t Need to Hack Delta

This incident demonstrates something cybersecurity professionals have understood for years.

Sometimes attacking the trusted organization is unnecessarily difficult.

It’s easier to attack the customer’s trust in the organization.

Don’t hack Delta.

Create something that looks like Delta.

Don’t hack Microsoft.

Create a Microsoft login page.

Don’t hack the hotel.

Create the hotel’s Wi-Fi portal.

Don’t hack Google.

Send someone to a page that looks like Google.

The victim completes the attack for you.

Your VPN Doesn’t Solve This

This is where travelers frequently misunderstand VPNs.

A VPN can provide valuable protection when you’re using an untrusted network.

But a VPN cannot protect you from voluntarily entering your password into a phishing page.

If “DELTA WIFI FAST” presents you with a fake login page and you willingly enter your credentials, the encrypted tunnel isn’t the problem.

You handed the attacker the password.

HTTPS doesn’t automatically save you either.

A phishing website can have a valid HTTPS certificate.

The padlock means your connection to that website is encrypted.

It does not mean the website belongs to Delta, Google, Microsoft or your employer.

How to Protect Yourself From Evil-Twin Wi-Fi

Before connecting to Wi-Fi on an airplane, hotel, airport or conference center, verify the official network name.

If you’re unsure aboard an aircraft, ask a flight attendant.

If you’re at a hotel, check the instructions provided by the hotel rather than simply selecting the strongest network.

Be particularly suspicious if public Wi-Fi asks you to:

  • Install software

  • Download a certificate

  • Install a browser update

  • Enter corporate Microsoft 365 credentials

  • Enter Google credentials unexpectedly

  • Disable security software

  • Download a “network repair” utility

Whenever practical, use cellular data or your personal hotspot instead.

And enable strong MFA—preferably phishing-resistant passkeys—on important accounts.

Businesses Should Be Paying Attention

Now imagine the person connecting isn’t simply watching Netflix.

It’s your CFO.

Your attorney.

Your physician.

Your school administrator.

Your employee traveling with a laptop containing access to:

Microsoft 365.

SharePoint.

OneDrive.

QuickBooks.

Customer records.

Patient information.

Legal documents.

Corporate VPNs.

Suddenly an airplane Wi-Fi prank becomes a serious SMB cybersecurity incident.

Businesses should train employees to treat public Wi-Fi as hostile infrastructure.

Managed IT environments should also use MFA, EDR/XDR, conditional-access policies, DNS protection, least privilege and strong identity monitoring so one stolen credential doesn’t immediately become a company-wide breach.

This Technique Has Already Put Someone in Prison

The uploaded report points to a remarkably similar Australian case from 2024.

Authorities accused a man of using a portable wireless access device aboard a commercial flight to mimic legitimate onboard Wi-Fi.

A flight attendant became suspicious.

Police investigated.

And authorities ultimately uncovered what was described as a much larger criminal operation.

The man was eventually sentenced to seven years in prison.

So while the Delta incident may sound like hackers fooling around after DEF CON, the underlying technique isn’t a harmless party trick.

Evil-twin networks can be credential-stealing infrastructure.

The Most Dangerous Part Is How Normal It Looks

No ransomware screen.

No flashing warning.

No hacker wearing a hoodie.

Your phone simply says:

Wi-Fi available.

You tap it.

A familiar-looking page appears.

You sign in.

And you continue your flight.

That’s why this attack is so effective.

We’re conditioned to trust network names because they’re familiar.

But your phone can’t tell you that the Wi-Fi network called “Delta” actually belongs to Delta.

The same applies to your hotel tomorrow night.

And the airport the next morning.

The name appearing under the Wi-Fi icon is ultimately just a name someone configured.

The airplane might be real.

The hotel might be real.

The airport might be real.

The Wi-Fi might not be.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #WiFiSecurity #Phishing #DataProtection #ManagedIT


Technology
Cybersecurity
Tips
AI

The most dangerous scam may start with someone being helpful.

August 10, 2026
•
20 min read

The Scam Call That Doesn’t Sound Like a Scam

The most dangerous scam may start with someone being helpful.

Imagine your phone rings.

“Hi, this is going to sound strange, but I think I found something that belongs to you.”

The caller mentions a jacket. A bag. A watch. Maybe another personal item.

They aren’t threatening you.

They aren’t claiming to be the IRS.

They aren’t asking you to buy gift cards.

They sound like a normal person trying to do something nice.

And that is precisely why you should be suspicious.

Scammers Are Learning That Fear Isn’t Always the Best Weapon

For years, scam calls were relatively predictable.

“Your Social Security number has been suspended.”

“Your grandson has been arrested.”

“Your computer has a virus.”

“Your bank account has been compromised.”

Those scams still exist, but people have become better at recognizing them.

So social engineering is evolving.

Instead of immediately frightening you, a sophisticated scammer can begin by creating curiosity and trust.

A strange caller claiming to have found something belonging to you is an excellent example.

The natural response is:

“What did you find?”

“Where did you find it?”

“How did you know it was mine?”

Those questions begin a conversation — and the conversation itself can become the attack.

The First Goal May Not Be Money

This is something people misunderstand about modern scams.

The first phone call doesn’t necessarily need to steal anything.

It may simply need to learn something.

Suppose someone says:

“I found a watch with your information connected to it. Did you lose a watch recently?”

You might respond:

“No, but my son has an Apple Watch.”

Now the caller knows you have a son.

They might continue:

“Interesting. Could it belong to him?”

You might reveal his name.

A few innocent questions later, the stranger potentially knows family relationships, possessions, locations, travel habits or other details that can make the next attack far more believable.

Cybersecurity professionals call this social engineering.

The attacker isn’t hacking the computer.

They’re hacking the conversation.

AI Makes These Conversations Far More Dangerous

Artificial intelligence changes the economics of scams.

Scammers can increasingly combine information from data breaches, social media, public records and other sources with automated systems capable of conducting convincing conversations.

AI voice technology adds another problem.

The Federal Trade Commission has specifically warned that modern voice-cloning technology can reproduce someone’s voice from relatively small samples of recorded audio, creating opportunities for convincing impersonation scams. (Consumer Advice⁠)

And detecting these voices by ear is becoming unreliable.

A 2026 study examining AI-generated voices in simulated vishing attacks found participants struggled badly to distinguish synthetic voices from real ones. In the experiment, 75% of AI-generated samples were judged by a majority of participants to be human. (arXiv⁠)

That changes an important cybersecurity assumption:

A familiar voice is no longer proof of a familiar person.

The Innocent Conversation Can Become Reconnaissance

Consider how easily an unusual lost-item conversation could develop.

“Is this Michael?”

“Yes.”

“I found a watch that might belong to someone in your family.”

“Where?”

“Near the airport.”

“Oh, we were there last week.”

“Were you traveling with your family?”

“Yes.”

“Maybe one of your kids dropped it.”

Suddenly the caller has confirmed your identity, recent travel and family information.

None of those questions individually feels particularly dangerous.

Together, they’re intelligence.

That information could later make a phishing email, text message or impersonation attempt significantly more convincing.

The person who calls tomorrow doesn’t necessarily need to be the person who called today.

The Second Call Is Where Things Can Get Ugly

Imagine another call several weeks later.

Someone sounds like your child.

There’s panic in their voice.

They mention the airport.

They know about the trip.

They know your name.

They know details about your family.

And they need money immediately.

The FTC warns that scammers already use AI voice cloning in family-emergency scams and deliberately create urgency so victims act before independently verifying what happened. (Consumer Advice⁠)

Suddenly the harmless conversation about a missing watch looks very different.

This doesn’t mean every unusual call is part of an elaborate AI operation.

It means we need to change how we evaluate strangers who unexpectedly know something about us.

Stop Judging Calls by How Friendly They Sound

People often look for the wrong warning signs.

They listen for foreign accents.

Robotic voices.

Aggressive sales tactics.

Bad grammar.

Strange pauses.

Those signals are becoming increasingly useless.

The better question is:

Why does this stranger need information from me?

If someone legitimately found your property, you shouldn’t need to provide a biography to retrieve it.

Ask the caller to describe the item.

Don’t describe it for them.

Ask where it was found.

Don’t tell them where you’ve recently traveled.

Ask how they obtained your telephone number.

Don’t provide additional identifying information to help them “confirm” your identity.

Most importantly, don’t allow curiosity to override skepticism.

Use the Reverse Verification Rule

This is one of the simplest cybersecurity habits you can teach employees and family members:

The person initiating the contact does not get to establish their own identity.

If your bank calls, hang up and call the number printed on your card.

If someone claims to represent your child’s school, call the school directly.

If someone claims to be a coworker, contact that coworker through your normal communication channel.

If someone claims to have found something belonging to you, make them describe it first.

Never verify an unexpected caller using telephone numbers, links or information that the caller provides.

You independently find the trusted contact method.

The FTC recommends essentially the same principle for impersonation scams: stop and independently verify the story before taking action. (Federal Trade Commission⁠)

Businesses Need to Teach This Too

This isn’t merely a consumer problem.

The same psychology works extraordinarily well against businesses.

An employee receives a friendly call:

“I’m trying to return something one of your employees left at our office.”

“I’m trying to reach whoever handles your insurance.”

“Someone from your accounting department asked me to call.”

“I’m returning a laptop that belongs to your company.”

The employee wants to help.

So they provide a name.

A department.

An email address.

A manager.

A vendor.

A travel schedule.

Attackers can then use those details to construct much more convincing phishing and business-email-compromise attacks.

For an SMB, healthcare organization, law firm or school, that seemingly harmless information can become the reconnaissance stage of a cybersecurity incident.

A good Managed IT or cybersecurity program therefore shouldn’t only teach employees:

Don’t click suspicious links.

It should teach:

Don’t help strangers build the story they’ll eventually use against you.

Five Rules for Strange Phone Calls

  1. Make the caller provide information first.
    If they supposedly found your watch, ask them to describe it. Don’t tell them what yours looks like.

  2. Never authenticate yourself to an unexpected caller.
    Avoid confirming birthdays, addresses, family members, account information or travel details.

  3. Break the communication channel.
    Hang up and independently contact the organization or person supposedly involved.

  4. Ignore caller ID as proof of identity.
    The FTC warns that scammers can manipulate the name or number displayed on caller ID. (Consumer Advice⁠)

  5. Teach your family and employees one sentence:
    “I don’t verify information on incoming calls.”

That sentence can stop an extraordinary number of social-engineering attacks.

AI Didn’t Invent Scamming. It Industrialized It.


The broader threat is very real: the FTC says Americans reported $3.5 billion in losses to impersonation scams in 2025, nearly triple the losses reported in 2020.

Scammers have manipulated people for centuries.

What AI changes is scale.

It can help attackers research targets, personalize conversations, generate convincing messages and reproduce voices at a speed that previously required significant human effort.

That means cybersecurity can no longer focus exclusively on protecting computers.

We also have to protect conversations.

The next sophisticated cyberattack against you might not begin with malware.

It might begin with a friendly stranger saying:

“I think I found something that belongs to you.”

And your safest response may be to reveal absolutely nothing.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ArtificialIntelligence #CyberSecurityAwareness #DataProtection #SmallBusiness


Technology
Crypto
Tips
Cybersecurity

One Tiny Bug Just Broke Bitcoin’s Biggest Promise

August 11, 2026
•
20 min read

One Tiny Bug Just Broke Bitcoin’s Biggest Promise

For years, Bitcoin holders have repeated one phrase:

“Not your keys, not your coins.”

This week, that advice proved to be only part of the story.

A firmware flaw in COLDCARD hardware wallets allowed some devices to generate predictable seed phrases instead of truly random ones. Those seed phrases are the foundation of Bitcoin security. If the randomness is weak enough, attackers can eventually derive the wallet’s private keys and steal the funds. Reports indicate that coordinated thefts are still occurring as attackers continue identifying vulnerable wallets.

Why This Is So Serious

Every cryptocurrency wallet starts with a seed phrase—typically 12 or 24 words.

Those words aren’t supposed to follow any predictable pattern. They must be generated with extremely high-quality randomness (entropy).

Think of it like a lottery.

If every ticket is completely random, your odds of guessing the winning numbers are effectively zero.

But if the machine secretly only uses a tiny fraction of all possible combinations, suddenly the lottery becomes solvable.

That’s essentially what happened.

The hardware wallet itself wasn’t remotely hacked.

The keys it created were fundamentally weaker than users believed.

Why a Firmware Update Isn’t Enough

Many security vulnerabilities disappear after installing an update.

Not this one.

Once a vulnerable seed phrase has been generated, that weakness stays with the seed forever.

Installing updated firmware doesn’t magically make the existing recovery phrase random.

The only effective fix is:

  • Update the wallet firmware.

  • Generate an entirely new seed phrase using the fixed firmware.

  • Move every Bitcoin balance to addresses protected by the new seed.

Simply importing the old seed into another wallet does not solve the problem because the vulnerability is tied to the seed itself, not the hardware.

Lessons Beyond Cryptocurrency

This incident highlights an important cybersecurity principle that extends far beyond Bitcoin.

Security isn’t just about using the right product.

It’s about trusting the entire process that creates and protects your secrets.

Whether it’s:

  • Password generators

  • Encryption keys

  • Hardware security modules

  • Multi-factor authentication

  • Cryptographic certificates

…the strength of the system depends on the quality of the randomness behind it.

If randomness fails, even mathematically strong encryption can be undermined.

If You Own a COLDCARD

If your wallet may have generated a seed using affected firmware:

  • Determine whether your model and firmware version are affected.

  • Install the latest firmware.

  • Generate a completely new seed phrase using the patched firmware.

  • Transfer all Bitcoin to addresses derived from the new seed.

  • Never continue using an older, affected seed phrase, even on a different wallet.

The Bigger Lesson

Technology often fails in unexpected places.

Sometimes it isn’t encryption that breaks.

It isn’t the blockchain.

It isn’t the hardware.

It’s a single software bug that quietly weakens the randomness everything else depends on.

Trust—but always verify.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #Bitcoin #Cryptocurrency #DataProtection #ManagedIT

Must-Read
Tips
Cybersecurity

A Lost Wallet Can Cost More Than Your Cash

August 5, 2026
•
20 min read

A Lost Wallet Can Cost More Than Your Cash

Most people panic about the money.

Cybercriminals are thinking about everything else.

Losing your wallet isn’t just an inconvenience anymore—it’s often the beginning of an identity theft attack. Modern thieves don’t need your cash. They want your driver’s license, debit card, health insurance card, and anything else that helps them impersonate you.

By the time fraudulent accounts appear, your information may already have been sold or used multiple times.

Why Your Debit Card Is the Biggest Immediate Risk

Many people rush to cancel their credit cards first.

That’s backwards.

A stolen debit card provides direct access to your checking account. Unlike credit cards, which generally have stronger fraud protections, fraudulent debit card transactions can remove your own money immediately.

Time matters.

The sooner you lock or report the card, the less likely you’ll suffer financial loss.

The First 30 Minutes Matter Most

If your wallet is lost or stolen:

1. Lock Every Payment Card Immediately

Most banking apps allow you to temporarily lock a card while you determine whether it’s truly lost. If recovery seems unlikely, cancel it and request replacements with new numbers.

2. Freeze Your Credit

A thief with your driver’s license may have enough information to apply for loans or open new credit accounts.

Place a credit freeze with all three major credit bureaus:

  • Experian

  • Equifax

  • TransUnion

A freeze is free and significantly reduces the chances of someone opening accounts in your name.

3. File an Identity Theft Report

Visit IdentityTheft.gov to receive a customized recovery plan if your identity has been compromised or you suspect fraud.

4. File a Police Report

Even if police never recover your wallet, the report creates an official record that may help dispute fraudulent accounts or transactions later.

5. Turn On Account Alerts

Enable real-time notifications for:

  • Credit cards

  • Bank accounts

  • Debit cards

  • Mobile payment apps

Small unauthorized purchases often serve as “test transactions” before larger theft occurs.

6. Monitor Every Financial Account

Identity thieves frequently wait weeks or even months before using stolen information.

Watch for:

  • Small charges

  • New accounts

  • Address changes

  • Unknown logins

  • Unexpected credit inquiries

7. Replace Sensitive Documents

Request replacements for:

  • Driver’s license

  • Health insurance cards

  • Medicare card (if applicable)

If your Social Security card was in your wallet, contact the IRS about obtaining an Identity Protection PIN (IP PIN) to help prevent fraudulent tax returns.

Better Yet—Prepare Before It Happens

Most people carry far more than they need.

Consider these simple precautions:

  • Carry only essential cards.

  • Photograph the front and back of important cards and store the images securely in an encrypted password manager or secure digital vault—not in your regular photo gallery.

  • Keep customer service numbers for your financial institutions readily available.

  • Add a Bluetooth tracker such as an AirTag or similar device to your wallet.

  • Leave your Social Security card at home unless you specifically need it.

Preparation turns a potential disaster into a manageable inconvenience.

The Bigger Lesson

Identity theft doesn’t always begin with a sophisticated cyberattack.

Sometimes it starts with a wallet left on a restaurant table, dropped in a parking lot, or stolen from a shopping cart.

The faster you respond, the less valuable your information becomes to criminals.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #IdentityTheft #DataProtection #SmallBusiness #ManagedIT

Crypto
Cybersecurity
Technology

Bitcoin’s Greatest Mystery Still Has No Answer.

August 6, 2026
•
20 min read

Bitcoin’s Greatest Mystery Still Has No Answer.

More than fifteen years later, we still don’t know who created Bitcoin.

The pseudonym Satoshi Nakamoto published the Bitcoin whitepaper in 2008, launched the network in 2009, gradually stepped away from the project, and disappeared from public communication in 2011.

The coins widely attributed to Satoshi—estimated at roughly 1.1 million bitcoin—have never been spent.

That mystery has fueled countless theories.

But one thing is often overlooked:

Bitcoin wasn’t built in isolation.

The People Who Helped Shape Bitcoin’s Earliest Days

Several developers and cryptographers played critical roles during Bitcoin’s infancy.

Among them were:

  • Hal Finney – The recipient of the first Bitcoin transaction and one of the earliest contributors. He remains one of the most frequently discussed Satoshi candidates.

  • Gavin Andresen – Entrusted with maintaining Bitcoin’s codebase after Satoshi stepped away from the project.

  • Martti Malmi – One of Bitcoin’s earliest developers who helped build Bitcoin.org and expand the young community.

  • Jeff Garzik – An early developer who contributed to Bitcoin’s growth during its formative years.

  • Ray Dillinger – Reviewed and discussed Bitcoin’s design during its earliest stages within the cypherpunk community.

  • Adam Back – Creator of Hashcash, whose proof-of-work system became a foundational concept behind Bitcoin.

Each helped transform an academic idea into a functioning decentralized network.

Why Satoshi’s Identity Still Matters

Bitcoin isn’t remarkable because someone invented digital money.

It’s remarkable because its creator disappeared.

There was no CEO.

No marketing department.

No venture capital launch.

No company controlling the protocol.

Instead, Bitcoin survived because an open-source community continued building it.

That may be Satoshi’s greatest contribution of all.

The Bigger Lesson

The internet has produced many revolutionary technologies.

Few have become more influential than Bitcoin.

Yet one of the most important innovations of the 21st century remains tied to a mystery that has never been solved.

Whether Satoshi Nakamoto was one person or several working together may never be known.

Ironically, the technology built to eliminate the need for trust still asks us to trust one unanswered question.

What do you think?

Was Satoshi Nakamoto a single individual… or a group working under one name?

70% of all cyber attacks target small businesses, I can help protect yours.

#Bitcoin #Blockchain #Cryptography #Technology #Innovation

Technology
Cybersecurity
Travel

Your Car May Have A Hidden Computer You Never Knew Existed

August 12, 2026
•
20 min read

Your Car May Have A Hidden Computer You Never Knew Existed.

When people think about vehicle cybersecurity, they usually think about the manufacturer.

Ford.

Toyota.

Honda.

Tesla.

But one of the biggest risks may have been installed after the vehicle left the factory.

Security researchers recently disclosed a vulnerability affecting certain Bluetooth-enabled dealer-installed vehicle security systems, including some KARR Security products. These aftermarket devices are commonly installed by dealerships for inventory tracking, theft recovery, or alarm functionality—and many owners don’t even realize they’re there.

The Hidden Technology Inside Your Vehicle

Many dealerships install aftermarket security or tracking equipment before a vehicle is sold.

In some cases, the system remains installed even if the buyer never activates, subscribes to, or even knows about it.

Because these devices are wired into critical vehicle systems, they can become another potential point of attack.

According to the researchers, an attacker within Bluetooth range could potentially issue unauthorized commands to affected systems, including actions such as:

  • Unlocking vehicle doors.

  • Activating lights or the horn.

  • Disabling the alarm.

  • Tracking the vehicle.

  • Preventing the engine from starting.

The exact risk depends on the installed device and whether available security updates have been applied.

The Bigger Cybersecurity Lesson

Modern vehicles are no longer just mechanical machines.

They’re rolling computer networks.

Every connected component represents another potential attack surface.

Factory software.

Infotainment systems.

Mobile apps.

Bluetooth devices.

Dealer-installed hardware.

Third-party accessories.

Cybersecurity is only as strong as the weakest connected component.

What Drivers Should Do

If you purchased a vehicle from a dealership:

  • Ask whether any aftermarket security or tracking devices were installed.

  • Determine whether your vehicle includes a Bluetooth-enabled dealer-installed security system.

  • Check whether firmware updates are available through the vendor or dealership.

  • Never remove aftermarket wiring yourself unless performed by a qualified professional.

Many owners have no idea these systems exist until something goes wrong.

The Future Of Automotive Security

For decades, vehicle safety focused on seatbelts, airbags, and crash testing.

Today’s vehicles require something else:

Cybersecurity.

Manufacturers, dealerships, suppliers, and technology vendors all share responsibility for securing the increasingly connected systems that modern drivers depend on every day.

Because the next vehicle recall may not be caused by a mechanical defect.

It may begin with software.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #AutomotiveSecurity #ConnectedCars #Technology #DataProtection

Cybersecurity
Technology
Tips

That free Wi-Fi can cost you everything

August 4, 2026
•
20 min read

One Hotel Login Can Cost You Everything

Business travelers connect to hotel Wi-Fi every day without a second thought. Unfortunately, cybercriminals know it.

Microsoft has issued a warning about an active campaign by a Russian state-sponsored threat group that is compromising hotel and hospitality Wi-Fi networks to steal credentials, install malware, and gain long-term access to victims’ devices. The attacks have reportedly been observed across hotels, conference centers, and other hospitality venues worldwide.

This isn’t just another phishing email. It’s an attack that begins the moment you connect to what appears to be a legitimate hotel network.

How the Attack Works

Many hotels use a captive portal—the webpage that appears before you can access the internet.

Attackers are compromising these portals and presenting convincing fake prompts that appear to be legitimate Windows or browser updates. Victims believe they are fixing a connectivity issue or completing a required update, but instead they are installing malware.

Once installed, the malware can:

  • Steal saved passwords

  • Capture browser cookies

  • Access confidential documents

  • Record keystrokes

  • Take screenshots

  • Capture audio and video

  • Monitor clipboard contents

  • Give attackers remote control of the computer

Even more concerning, some victims are redirected to fake Microsoft 365 login pages, allowing attackers to steal email credentials and gain access to OneDrive, SharePoint, Teams, and other Microsoft services.

For businesses that rely on Microsoft 365, one compromised employee can become the entry point for a much larger attack.

Why Small Businesses Should Care

Cybercriminals don’t have to breach your firewall anymore.

Sometimes they simply wait until your employees leave the office.

Sales representatives, executives, attorneys, healthcare professionals, consultants, and remote workers frequently connect from hotels while traveling. One successful compromise can expose:

  • Customer information

  • Legal documents

  • Medical records

  • Financial data

  • Internal communications

  • Cloud storage

A single infected laptop can bypass months of cybersecurity investments when it reconnects to the corporate network.

Red Flags Every Traveler Should Recognize

If you’re connected to hotel Wi-Fi and suddenly see prompts asking you to install software before browsing, stop immediately.

Be suspicious of unexpected requests to install:

  • Windows Updates

  • Browser updates

  • Security scans

  • PDF viewers

  • Network repair tools

  • Certificates

  • Microsoft Visual C++ packages

  • Runtime installers

Legitimate hotel Wi-Fi almost never requires software installation simply to access the internet.

How to Protect Yourself

Simple precautions dramatically reduce your risk:

  • Use your phone’s hotspot whenever possible instead of public Wi-Fi.

  • Never install software or updates from a hotel login page.

  • Verify Microsoft 365 login pages before entering credentials.

  • Enable Multi-Factor Authentication (MFA) on every business account.

  • Keep devices updated before traveling—not after connecting to public Wi-Fi.

  • Use Endpoint Detection and Response (EDR) to identify suspicious behavior.

  • Train employees to recognize captive portal scams before they travel.

  • Consider using a trusted VPN, understanding that it protects traffic after a secure connection is established but cannot stop you from voluntarily entering credentials into a fake login page or installing malicious software.

The Bigger Picture

This campaign is a reminder that modern cyberattacks aren’t always launched through sophisticated exploits—they often succeed because attackers exploit trust.

When a fake login page appears on what seems to be a legitimate hotel network, many people assume it’s safe.

That’s exactly what these attackers are counting on.

Businesses must assume employees will work from airports, hotels, and conference centers. Security strategies need to protect users wherever they connect—not just inside the office.

70% of all cyber attacks target small businesses, I can help protect yours.

#CyberSecurity #ManagedIT #Microsoft365 #BusinessSecurity #SmallBusiness

Technology
AI

AI companies are purchasing massive collections of used books and then destroying them

August 2, 2026
•
20 min read

Can We Teach AI Without Destroying History?

Artificial intelligence is transforming the way we learn.

But it has also sparked an uncomfortable question.

What should we be willing to sacrifice to build it?

Reports have emerged that once they’ve been digitized.

From a logistical standpoint, it makes sense.

From a historical standpoint, it feels different.

A Book Is More Than Data

Every book represents thousands of hours of someone’s life.

Years of research.

Countless revisions.

Late nights.

Creative breakthroughs.

For many authors, that book becomes their life’s work.

Some copies carry even more than the printed words.

Handwritten notes.

Personal inscriptions.

Bookmarks.

Coffee stains.

The quiet evidence that the book was read, shared, and valued by real people.

Once those copies are destroyed, something disappears that no digital scan can fully replace.

Information Isn’t The Same As History

Digitizing knowledge is incredibly valuable.

It makes ideas searchable.

Accessible.

Preserved against physical decay.

That’s a remarkable achievement.

But preserving information isn’t always the same as preserving history.

The physical object has value beyond the words printed on its pages.

It tells its own story.

Innovation And Preservation Can Coexist

Artificial intelligence doesn’t have to come at the expense of our cultural record.

Libraries, archives, museums, and private collections exist because society has long recognized that some things deserve to outlive their immediate usefulness.

Perhaps books that contribute to training the next generation of AI should also be considered worthy of preservation.

Progress doesn’t require erasing the artifacts that made progress possible.

The Bigger Lesson

AI will almost certainly help humanity solve problems that once seemed impossible.

It will accelerate scientific discovery.

Improve medicine.

Transform education.

Expand creativity.

Those are extraordinary opportunities.

But as we build the future, we should be careful not to treat the past as disposable.

Because a book is more than information.

It’s evidence that a human being once had an idea worth preserving—and that another human being thought it was worth reading.

70% of all cyber attacks target small businesses, I can help protect yours.

#ArtificialIntelligence #Books #Innovation #DigitalPreservation #Technology

Previous
Next
About
Managed ServicesCybersecurityOur ProcessWho We AreNewsPrivacy PolicyTerms & Conditions
Help
FAQsContact UsSubmit a Support Ticket
Social
LinkedIn link
Twitter link
Facebook link
Have a Question?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Copyright © {auto update year} Gigabit Systems All Rights Reserved.
Website by Klarity
Gigabit Systems Inc. BBB Business Review