The short version: most cyber hacks aren’t personal — criminals hunt for easy openings, not specific victims. Here are three types of hacks most businesses don’t expect: supply chain attacks through trusted software, Internet of Things (IoT) device attacks exploiting weak passwords, and voice phishing (“vishing”) scam calls. Here’s how each works, and how to help prevent them reaching your business.
You, as a specific company, are rarely a specific target for cybercriminals. In the same way a petty burglar tries car doors down the block to find the one left unlocked, hackers commit crimes of opportunity. They exploit the vulnerabilities they can see, and they don’t much care who’s behind the desk.
This doesn’t mean you’re safe. It means there’s probably nothing special about you compared to the next potential victim — and most attacks are automated, because cybercrime runs like a business, scanning the internet at industrial scale for an open door.
What’s more, you’re constantly bombarded with instructions to “protect your business,” but you often don’t have enough clear information about what hackers are doing and how your business might get caught up in it.
So let’s fix that. Here are three common but unexpected ways businesses end up in a hacker’s crosshairs. And the good news is, none of them require you to be a security genius to avoid.
1. Supply Chain Attacks
A supply chain attack targets your business by compromising one of the suppliers you already trust. Instead of breaking into your network directly, the attacker poisons a trusted link — a vendor, a service provider, or a piece of software — and rides that trust straight through your front door.

Here’s what it looks like in practice. Malicious code gets slipped into software your company relies on, such as accounting tools like QuickBooks, design tools like Adobe, anything that pushes regular updates. The update arrives, you install it like always, and the malware comes along for the ride. You did everything right. The weak link was upstream.
The fix is to use vetted software providers with strict security policies. This is one of the quieter jobs a managed IT partner who vets your software handles in the background. We can also help you create a supply-chain risk management program.
2. Smart Device Attacks
The Internet of Things — IoT for short — is the catch-all term for everyday objects that connect to the internet: smart thermostats, security cameras, the multifunction copier down the hall, even the office fridge. These tools make life easier. They also make excellent ways for hackers to access your platforms, because their security is usually an afterthought.

Hackers don’t care how many steps your smartwatch logged. What thrills them is the idea that you reused the same password on that device and on your work accounts — because one weak gadget can become the foothold they use to reach everything else on the network. Here’s where the risk tends to cluster:
| Connected Device | Why Hackers Want It | How to Lock It Down |
|---|---|---|
| Smart cameras, thermostats, smart locks | Widely used, rarely reconfigured | Change the default password; update firmware |
| Routers and network gear | One router can open the whole network | Strong admin password; separate networks |
| Connected medical devices | Patient data and unauthorized access | Vendor security review; segmentation |
| Industrial and building systems | Disrupting operations | Isolate from the business network |
| Wearables | Data over unsecured Bluetooth | Turn off Bluetooth when unused; update apps |
And we make it easy for them. The most common way people get hacked through smart devices is the simplest one imaginable, weak or default passwords like “admin” or “password1” that nobody ever changes. So set strong, unique passwords on every device, add multi-factor authentication where you can, and when shopping for new gear, look for a U.S. Cyber Trust Mark (better yet, ask us first!).
3. Voice Phishing (“Vishing”): The Scam That Calls You
Vishing, short for “voice phishing,” is a phone-based con. The caller impersonates someone you’d trust: your bank, a government agency, your own tech support. Then they manufacture a sense of urgency to rush you into handing over a password, a credit card number, or remote access to your computer.

It works for the same reason email scams do: it’s the same social engineering trick behind phishing emails, just delivered through a voice. And it’s getting more convincing: generative AI voice tools can now clone a familiar voice from a short clip, so the “boss” asking you to wire money in a hurry might sound exactly like your boss.
The defense is simple, if a little awkward at first. Verify before you trust. Don’t share sensitive information with anyone who called you; hang up and call the organization back on a number you look up yourself. Use call screening, and keep your phone secure while you’re at it. And skip the cheerful “Hi, this is [your name]” when you pick up an unknown number — you’re handing the caller a free piece of information. If a call smells like a scam, report it to the FTC.
The Three Attacks at a Glance
| Attack | How It Sneaks In | Your Move |
|---|---|---|
| Supply chain attack | Malware hidden in a trusted software update | Use vetted vendors; let IT screen software |
| Smart device attack | Weak or default passwords on gadgets | Unique passwords, updates, MFA |
| Voice phishing (vishing) | An urgent call impersonating someone you trust | Verify independently; share nothing with inbound callers |
What to Do: Closing the Easy Openings
None of this requires a server room or a security degree. A handful of habits closes the doors most opportunistic attacks rely on:
- Use vetted software and patch promptly. Stick to reputable vendors, and install updates quickly.
- Change every default password. Each device and account gets its own strong, unique password. Then use a password manager such as LastPass with a single master password.
- Turn on multi-factor authentication. The single highest-leverage thing you can do.
- Separate your networks. Keep smart devices and guest Wi-Fi off your business network.
- Verify unexpected calls. Hang up and call back on a number you look up.
- Train your team. Train your team to spot the patterns and they’ll catch what filters miss.
Knowing you’re rarely a direct target should take some of the edge off — while still keeping you alert to the openings worth closing.
For tips tailored to your business, get in touch with the Stratti team, or call us in Chico at (530) 342-8999 or Roseville at (916) 290-4511.
Frequently Asked Questions
What does it actually mean to “get hacked”?
Getting hacked means someone gains unauthorized access to your accounts, devices, or network. Most of the time it isn’t targeted; it’s an automated attack finding an opening you left exposed, like a weak password or an out-of-date system.
Am I really a target if my business is small?
Yes, but not personally. Hackers commit crimes of opportunity, scanning for any business with a weak spot. Small-to-medium businesses are often hit precisely because they assume they’re too small to bother with.
What is a supply chain attack in simple terms?
A supply chain attack hits you through a supplier you trust. Rather than breaking in directly, attackers compromise a vendor or piece of software. When you run an update, the malware reaches your computers that way.
How do hackers get in through smart devices?
Usually through weak or unchanged default passwords. A connected camera, router, or thermostat with credentials like “admin” is an easy entry point. Once inside, attackers see what else they might be able to access with that password.
What is vishing?
Vishing is “voice phishing” — a scam phone call. The caller pretends to be your bank, a government agency, tech support, even your mom, then uses urgency to pressure you into sharing passwords, payment details, or computer access.
Can hackers really fake someone’s voice?
Yes. Generative AI voice tools can clone a familiar voice from a short audio clip, which makes vishing calls more convincing than ever. If a caller you “recognize” pressures you to act fast, verify through a separate channel before doing anything.
What should I do if I think I’ve already been hacked?
Act fast. Disconnect the affected device from the network, change your passwords starting with email and financial accounts, and contact your IT team right away. The sooner you respond, the more you limit the damage.
|
BL
|
Written by Brent Largent
Managed IT Services Expert · Stratti
Brent and the Stratti team have spent over a decade helping small and mid-sized businesses across Chico, Roseville, and the greater Sacramento area handle cybersecurity threats, managed IT, and technology strategy. When IT works, you don’t notice it—and that’s exactly how they like it. Last reviewed: August 16, 2026
|