🚨 July 18, 2026

July 2026 Threat Alert

What small businesses need to know this month: a new ransomware variant hitting NAS devices, a wave of fake e-commerce invoice scams, and multiple WordPress plugin vulnerabilities under active exploit.

πŸ”΄ High Severity

1. New LockBit Variant Targeting Small Business NAS Devices

A new variant of LockBit ransomware β€” internally tracked as LockBit-NG β€” has been observed in the wild since late June 2026, specifically targeting network-attached storage (NAS) devices used by small businesses for local backups and file sharing. This variant exploits default credentials and unpatched vulnerabilities in QNAP, Synology, and Western Digital NAS devices to encrypt both the NAS and any connected network shares.

Why this matters for small businesses: Many small businesses use NAS devices as their primary backup target, believing that local network storage is safer than the cloud. But if the NAS is on the same network as infected computers β€” or accessible from the internet with default credentials β€” it becomes the first thing encrypted. The result: both primary files and the backup are lost simultaneously.

πŸ›‘οΈ What to do right now:

  • β€’ Change default NAS admin passwords immediately. If your NAS username is "admin" and password is "admin" or "password," you are a target.
  • β€’ Update NAS firmware. QNAP, Synology, and WD have released security patches in the past 60 days. Install them.
  • β€’ Disable internet access to your NAS. Unless you specifically need remote access (and if so, use a VPN β€” never port-forward the admin interface directly).
  • β€’ Apply the 3-2-1 backup rule: 3 copies, 2 different media, 1 off-site. An on-site NAS backup is NOT an off-site backup if it sits in the same building.

2. Fake Shopify Invoice Phishing Campaign Targeting E-Commerce Sellers

A coordinated phishing campaign is targeting small e-commerce businesses with emails that appear to be order confirmations or invoice notifications from Shopify. The emails use Shopify's actual branding, reference real-looking order numbers, and contain a "View Order" button that leads to a credential-harvesting page.

Once the attacker captures the store owner's login, they typically: (1) export the customer list and order history, (2) change the payout bank account to their own, and (3) install a payment skimmer on the checkout page. The entire process can happen in under an hour.

🎣 Red flags to watch for:

  • β€’ "New order" emails when you have not had any sales that day
  • β€’ "Urgent: Your store has been suspended" β€” Shopify communicates through your admin dashboard, not email
  • β€’ "Invoice from Shopify" β€” Shopify does not send PDF invoices. Log into your admin to view billing.
  • β€’ Any email asking you to "verify your account" by clicking a link

3. Critical WooCommerce Plugin Vulnerabilities Under Active Exploit

Three high-severity vulnerabilities have been disclosed in popular WooCommerce add-ons this month. All three are under active exploitation β€” meaning attackers are already scanning for and attacking unpatched sites:

  • WooCommerce Dynamic Pricing & Discounts (CVE-2026-XXXXX) β€” Unauthenticated SQL injection allowing full database access. 200,000+ active installs.
  • WooCommerce Shipment Tracking (CVE-2026-XXXXX) β€” Stored XSS allowing attackers to inject malicious scripts visible to admin users. 80,000+ active installs.
  • WooCommerce PDF Invoices & Packing Slips β€” Authorization bypass allowing unauthenticated users to download any invoice, including customer addresses. 300,000+ active installs.

If you run any of these plugins, update immediately. If auto-updates are off, turn them on. If the plugin is no longer actively maintained by its developer, replace it.

πŸ”§ Action items for WooCommerce store owners:

  • β€’ Log into your WordPress admin β†’ Plugins β†’ check for available updates
  • β€’ Enable auto-updates for all plugins (Plugins β†’ click "Enable auto-updates" on each)
  • β€’ Remove any plugin you are not actively using β€” even deactivated plugins can be exploited in some cases
  • β€’ Install Wordfence or Sucuri (both free) for malware scanning and firewall protection

4. Seasonal Alert: Summer Vacation Phishing Targeting Small Business Owners

Every July-August, attackers exploit the fact that business owners and managers are on vacation. The pattern is consistent: "urgent" emails arrive when the decision-maker is away, and junior staff β€” afraid of looking unresponsive β€” act without verifying. This month's variant: fake vendor payment reminder emails claiming "your account is past due β€” service will be suspended."

Prevention: Before you go on vacation, brief your team: "If you receive an urgent payment demand, vendor suspension notice, or wire transfer request while I am away, do not act on it until you reach me or [designated backup person] on a known phone number." Put this in writing. The 30-second phone call verification prevents the $25,000 fraudulent wire transfer.

Summary: Your July 2026 Security To-Do List

  1. Update your NAS firmware and change default passwords
  2. Set up a 3-2-1 backup strategy if you rely solely on a NAS for backups
  3. Enable MFA on your Shopify/WooCommerce admin account
  4. Update all WooCommerce plugins and enable auto-updates
  5. Brief your team on vacation-time phishing scams
  6. Bookmark our Incident Response Center β€” just in case

Free Security Assessment

Check if your business is vulnerable to the threats in this alert. 20 questions, 3 minutes, instant results.

Start Free Assessment β†’