CYBER FRI — Sept 25, 2026

Yasmine Johnston-Ison
This week, ransomware hit a commercial real estate brokerage — and the stolen data included deal files, property portfolios, and employee records. If you're acquiring a company, that's your data now.
- NAI Earle Furman — The secp0 ransomware group claimed access to a South Carolina brokerage's deal files, property management portfolios, broker commissions, and data from a previously absorbed firm: 1.36M file paths on one server. (DeXpose)
- Astrana Health — Attackers impersonated company staff to socially engineer employees into granting server access. Patient and employee data exposed; breach reported to the SEC. (SecurityWeek)
- Adobe Commerce “StyleSmuggler” — A CVSS 10.0 zero-day (CVE-2026-75650) in the e-commerce platform thousands of SMBs run on is under active exploitation. CISA added a related Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog Sept 24. (Sansec, CISA)
The deal lens: The NAI Earle Furman breach is the clearest illustration yet — when you acquire a company, you acquire its data exposure. That brokerage's stolen file server (deal terms, client lists, employee records) is exactly the kind of hidden liability that never appears on a balance sheet. A cyber posture assessment during diligence isn't a nice-to-have; it's how you avoid buying someone else's breach.
What's sitting on your target's file server? Legacy Forward Consulting builds cyber diligence into the deal process — let's talk.
#CyberSecurity #ThreatIntel #SMBAcquisition #DueDiligence
Sources
- DeXpose — Secp0 Ransomware Attack Targets NAI Earle Furman
- SOCRadar — NAI Earle Furman Data Breach | Secp0 Ransomware (2026)
- SecurityWeek — Astrana Health Data Breach Impacts Private, Confidential Information
- Sansec — StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
- Adobe — Critical Security Update for Adobe Commerce (APSB26-146)
- CISA — Known Exploited Vulnerabilities Catalog
Need Structured Guidance for Your Acquisition?
Book a 45-minute strategy call with our team to discuss your search progress, deal thesis, or transition plans.
Book an Appointment45 minutes to confirm fit and define next steps.
Related Insights
CYBER FRI (Analyst Edition) — Sept 18, 2026
Cisco ISE zero-day, Acronis backup flaw & record ransomware: IOCs & technical breakdown
The Cyber Liabilities You Inherit on Closing Day
Unpatched firewalls, exploited Windows flaws, and open SaaS guest access do not appear in the P&L—but buyers inherit them at close.