By Yiddy Lemmer, CEO – CompuConnect, Inc.

Small businesses in New York and New Jersey are facing increasingly sophisticated cyber threats, but the biggest risks are not always highly technical.

Ransomware, stolen credentials, business email compromise, phishing, unpatched systems, and third-party breaches continue to create serious problems for local businesses. What has changed is how quickly attackers can operate and how convincing their methods have become.

According to Verizon's 2025 Data Breach Investigations Report, ransomware appeared in 44% of the breaches analyzed and in 88% of breaches involving small and midsized businesses. Credential abuse was the leading initial access method at 22%, followed by exploitation of vulnerabilities at 20%.

For business owners and administrators, the goal is not to predict every possible attack. It is to build enough protection around the business that one stolen password, missed update, or convincing email does not become a major operational disruption.

Here are some of the most important cybersecurity threats New York and New Jersey businesses should be watching.

1. Ransomware Can Disrupt the Entire Business

Ransomware is more than a locked computer.

Attackers may steal information before encrypting systems, potentially exposing employee records, financial documents, customer information, tax records, passwords, and other sensitive business data.

The FBI received more than 3,600 ransomware complaints in 2025, with reported losses exceeding $32 million. The FBI also cautions that these numbers generally do not include many indirect costs, such as downtime, lost business, wages, equipment, or remediation expenses.

For a small business, those indirect costs may be just as damaging as the attack itself.

A New York Home Healthcare Example

A New York Attorney General case involving a Long Island-based home healthcare organization shows how significant the impact can become.

A ransomware attack compromised personal and medical information belonging to approximately 316,845 New Yorkers. The Attorney General determined that inadequate data-security practices contributed to the exposure and ultimately required financial penalties and cybersecurity improvements.

For home healthcare agencies, the lesson is particularly relevant to the office and administrative side of the organization.

Administrative systems may contain employee records, Social Security numbers, insurance information, payroll data, billing information, credentials, scheduling information, and other sensitive records.

If those systems are compromised, a home healthcare agency can face much more than an IT problem. The incident can create downtime, compliance obligations, administrative disruption, financial costs, and significant recovery work.

2. Business Email Compromise Can Turn One Message Into a Major Loss

Business Email Compromise, or BEC, often looks like an ordinary business request.

Attackers may impersonate an owner, executive, vendor, accountant, attorney, payroll provider, or customer. They then request a wire transfer, payment, direct-deposit change, or new banking instructions.

Sometimes the criminal has already compromised a legitimate email account and has been quietly monitoring conversations.

In April 2026, federal prosecutors in Brooklyn announced a guilty plea involving BEC and related schemes that caused more than $50 million in losses to individuals and small businesses in New York City and elsewhere.

New Jersey has seen similar fraud. In one federal case, a compromised business email account was used to send fraudulent instructions that resulted in an approximately $560,000 wire transfer.

The practical protection is simple:

Never approve unexpected changes to banking or wire instructions based on email alone.

Confirm the request using a previously known phone number or another trusted communication method.

3. Stolen Email Credentials Are a Major Entry Point

For many businesses, Microsoft 365 or Google Workspace is at the center of daily operations.

Email accounts can contain invoices, financial conversations, shared documents, password-reset messages, customer information, and years of business history.

That makes stolen credentials extremely valuable.

Attackers may obtain passwords through:

  • Fake login pages
  • Phishing emails
  • QR-code scams
  • Password reuse
  • Malware
  • Stolen browser sessions

Once inside an account, an attacker can study how the business operates, identify who approves payments, and potentially impersonate employees in highly convincing ways.

Verizon found that credential abuse accounted for 22% of known initial access methods in its 2025 breach analysis.

CISA recommends requiring multifactor authentication for business email, file storage, remote access, administrative accounts, and other critical systems. Stronger phishing-resistant authentication methods should be used where practical.

4. Phishing Is Becoming Harder to Recognize

The days when obvious spelling mistakes were enough to identify phishing are fading.

Modern phishing emails and fake login pages can look professional and closely imitate familiar business services.

Generative AI also makes it easier for criminals to create polished emails, convincing payment requests, realistic impersonation messages, and industry-specific language.

Employees therefore need to move beyond asking:

"Does this look legitimate?"

A better question is:

"Can I independently verify this request?"

That is especially important whenever someone is being asked to enter a password, provide sensitive information, approve a payment, or take an urgent action.

5. Unpatched Systems Can Become an Easy Way In

Attackers continuously scan the internet looking for vulnerable systems.

They do not necessarily need to target a company by name.

Firewalls, VPN appliances, servers, routers, remote-access tools, and business applications can all become entry points when known security updates are not installed.

Verizon reported a 34% increase in exploitation of vulnerabilities as an initial breach method in its 2025 research, with significant activity involving perimeter devices and VPNs.

For New York and New Jersey businesses, patching should be treated as routine business maintenance rather than something addressed only when a problem appears.

6. Third-Party Vendors Can Create Cybersecurity Risk

Businesses increasingly depend on outside vendors for payroll, cloud software, payment processing, accounting, healthcare administration, remote support, and other critical services.

Verizon found third parties were involved in 30% of breaches analyzed in its 2025 report, double the previous level.

This is especially important for home healthcare agencies, CPA firms, and other businesses that exchange sensitive information with multiple outside platforms and service providers.

Leadership teams should understand:

  • Which vendors have access to sensitive information
  • Which vendors are essential to daily operations
  • What security expectations are in place
  • What happens if a critical provider suddenly becomes unavailable

Third-party cybersecurity should be part of business continuity planning.

7. CPA and Tax Firms Remain Attractive Targets

CPA and accounting firms hold information that cybercriminals can monetize quickly.

That may include Social Security numbers, W-2s, tax returns, payroll information, banking details, and business financial records.

The New Jersey Division of Taxation specifically warns that cybercriminals increasingly target businesses and tax professionals to steal client information that may be used for fraudulent tax returns and identity crimes.

For CPA firms, cybersecurity is not simply about protecting office computers. It is about protecting the clients who have entrusted the firm with highly sensitive financial information.

What Should New York and New Jersey Businesses Do Now?

Cybersecurity works best when multiple protections are working together.

For most small businesses, priorities should include:

  • Require multifactor authentication.
  • Keep computers, servers, firewalls, VPNs, and applications patched.
  • Use professionally managed email and endpoint security.
  • Train employees regularly on phishing and BEC.
  • Maintain protected and tested backups.
  • Limit administrator access.
  • Verify financial changes outside of email.
  • Monitor systems for suspicious activity.
  • Maintain an incident-response and business continuity plan.

CISA identifies MFA, employee phishing awareness, software updates, system logging, and business data backups among its key cybersecurity practices for small and midsized businesses.

Cybersecurity Is a Business Responsibility

For New York businesses, cybersecurity can also carry legal responsibilities.

New York's SHIELD Act requires businesses maintaining private information belonging to New Yorkers to develop and maintain reasonable administrative, technical, and physical safeguards.

That includes areas such as employee training, risk assessment, service-provider oversight, attack prevention, monitoring, and response.

The bigger lesson for leadership teams is simple: cybersecurity is not just an IT issue.

It affects operations, productivity, compliance, financial stability, customer trust, and business continuity.

Build a Stronger IT Foundation Before an Attack

No cybersecurity strategy can guarantee that an attack will never happen.

The goal is to reduce unnecessary exposure, catch problems earlier, respond quickly, and prevent one incident from becoming a business-wide crisis.

CompuConnect helps businesses throughout Brooklyn, Manhattan, New York City, Brick, South Jersey, and the Tri-State Area strengthen their IT foundation through proactive managed IT services, cybersecurity, strategic planning, monitoring, backup and recovery, employee security awareness, and business continuity planning.

Clients also receive 100% live human support, so when something needs attention, they can reach real people who understand their business and can help move the issue forward.

If you are unsure where your company's biggest cybersecurity risks are, a proactive IT and cybersecurity assessment can help identify gaps and create a practical plan for improving security, stability, and business continuity.

Not Sure Where Your Biggest Cybersecurity Risks Are?

A discovery call with CompuConnect can help you take a closer look at your current IT environment, cybersecurity priorities, business continuity needs, and areas that may deserve more attention.

Schedule a discovery call with CompuConnect to start building a more secure, stable, and proactive IT strategy for your business.

About the Author
Yiddy LemmerYiddy Lemmer is the Founder and CEO of CompuConnect IT, a leading IT support and cybersecurity firm serving small and midsize businesses across New York and New Jersey. With over 18 years of hands-on experience, multiple Microsoft and CompTIA certifications, and deep roots in Brooklyn, Yiddy leads with a passion for technology, service excellence, and helping businesses thrive through secure and efficient IT systems.