LeadingIT breaks down new phishing and breach data for Chicagoland SMBs
LeadingIT is using new Verizon and Microsoft threat reports to show Chicagoland small businesses why patching, multifactor authentication and phishing training all matter now. The Naperville managed IT firm says attackers are shifting tactics, but email scams and unpatched systems remain a dangerous mix for companies without dedicated security staff.
Why it matters: - Chicagoland small and midsize businesses face a two-front cyber risk: stolen credentials are still a major breach factor, while unpatched vulnerabilities are rising fast. - Microsoft’s email threat data shows phishing volume remains high enough that one missed scam can still lead to a breach. - For businesses without a dedicated security team, patching, employee training and multifactor authentication now need to move together.
What happened: - LeadingIT said it is helping Chicagoland business owners interpret Verizon’s 2026 Data Breach Investigations Report and Microsoft’s Q1-Q2 2026 email threat intelligence. - Stephen Taylor, LeadingIT founder and CEO, said national breach data matches what the company sees with local businesses. - LeadingIT is a managed IT services and cybersecurity provider based in Naperville, Illinois, serving businesses across Chicagoland.
The details: - Verizon’s 2026 DBIR said stolen credentials fell from 22% of breaches in the 2025 report to 13% this year as the initial access vector. - Verizon also reported exploitation of unpatched vulnerabilities jumped to 31%, a 55% increase. - Credential misuse still appeared in 39% of breaches when tracked at any stage, according to Verizon. - Microsoft’s Q1 2026 email threat report logged roughly 8.3 billion email-based phishing threats in three months. - Microsoft’s report included about 2.9 billion phishing threats in January alone. - Microsoft’s Q2 2026 report recorded 7.6 billion more email-based phishing threats. - QR-code phishing grew 146% in Q1 as attackers looked for ways around URL filters. - LeadingIT said it has spent more than a decade pairing IT support and IT outsourcing with 24/7 monitoring. - LeadingIT said it is built for businesses with 25 to 250 end users and operates as a full managed service provider with an IT help desk and network security monitoring. - LeadingIT said business owners can schedule a consultation at its Naperville office to review their setup against this year’s threat data. - LeadingIT said its recommended actions for this quarter are to confirm patching is current, confirm multifactor authentication is enforced where possible and run a phishing simulation before the next attack arrives.
Between the lines: - The shift in Verizon’s data suggests attackers are diversifying, not abandoning old tactics. - That makes basic security hygiene more important, not less, because a company can be exposed by either weak patching or weak user awareness. - LeadingIT is positioning itself as a translator of national threat data into practical steps for smaller businesses that may not have in-house security expertise.
What’s next: - Chicagoland business owners can use the current threat reports as a checklist for the rest of the year. - LeadingIT said it wants owners to review patching, multifactor authentication and phishing readiness before the next wave of attacks lands. - More information is available through LeadingIT’s website and its social channels, including LinkedIn, Instagram, Facebook, YouTube and X.
The bottom line: - The message for small businesses is simple: cyber defense now depends on both fast patching and constant phishing awareness.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Small Business Online Network
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.