Let’s talk about IT

5 Ways Hackers Break In and How to Slam the Door

The five most common ways attackers break in — and how to shut them down.

Most breaches don’t start with a Hollywood-style hack — they start with a single click, a reused password, or a missed patch. In Macro Technology Group’s second-ever webinar, technical account manager Nicholas Frangopoulos and CTO Ken Widmer go inside the mind of a malicious actor to show exactly how attackers get into your environment — and how your organization can slam the door on them.

You’ll watch a phishing email and a live credential-theft demo dissected step by step, then walk through the layered, proactive defenses — from phishing-resistant MFA to 24/7 SOC monitoring and immutable backups — that stop each attack before it becomes a breach. Everything is kept high-level, so it’s useful whatever your technical background.

In this webinar, you’ll discover:

  • The five most common attack vectors — phishing, compromised credentials, exploited vulnerabilities, malware & ransomware, and insider threats
  • Live walkthroughs: a spoofed phishing email pulled apart clue by clue, and an attacker remotely browsing a workstation and stealing files in real time
  • The layered defense stack Macro runs — phishing-resistant MFA, EDR, 24/7 SOC monitoring, patch & vulnerability management, DLP, and immutable backups
Read the transcript

The full conversation from the webinar above, lightly edited for readability. Timestamps mark each section.

0:00 · Welcome & Introduction

Nick: Welcome, everyone. My name is Nicholas Frangopoulos, one of the technical account managers here at Macro Technology Group, and joining me again is Ken Widmer, CTO of the company. Today we’re proud to host our second-ever webinar, focused on cybersecurity — specifically, five ways hackers can get into your environment and how you, as an organization, can slam the door on them. We’ll go inside the mind of a malicious actor, and cover what you and your business can do to keep them out.

Nick: Here’s a brief overview of what we’ll cover: phishing, compromised credentials, exploited vulnerabilities, malware and ransomware, and insider threats — then layered security in action, what to do next, and a short Q&A at the end, like last time.

Nick: One quick note before we start: we’ll keep everything at a fairly high level so everyone can follow along regardless of technical background. Feel free to ask more detailed questions in the Q&A if there’s something specific you’d like us to go over.

1:36 · Why Layered Security Matters: A Cautionary Tale

Nick: As you saw, there are a wide variety of ways an attack can happen, and because of that it’s critical that organizations take a multi-layered approach to protecting themselves. To hammer home why, I want to share a quick story.

Nick: Back in 2020, I personally worked with a fairly large organization — roughly 300 users — to perform a cybersecurity assessment and offer recommendations. During that assessment, multiple suggestions were made about a number of security gaps we identified; they were particularly susceptible to ransomware with the measures they had in place. Ultimately, for one reason or another, the organization chose to pass on the suggestions, believing that what they already had was enough with a few minor tweaks.

Nick: We reiterated that their stack left a number of holes open and strongly recommended taking further measures, but they went with the more consolidated approach. Unfortunately, it wouldn’t take long to bite them: roughly four months later, they were hit with a ransomware attack — one they ultimately decided to pay. Once they were back up and running, they implemented the measures we’d originally suggested.

Nick: It’s a cautionary tale about why a proactive, multi-layered approach matters. All of this could have been avoided at best, or minimized at worst, had the proper steps been taken beforehand. As technology grows, our dependency on it expands — and so does the number of ways attackers can try to compromise your organization and your data. Staying one step ahead, identifying your current gaps, and locking all your doors is always your best bet. With that, I’ll hand it to Ken.

4:08 · Attack #1 — Phishing

Ken: Thanks, Nick. Phishing is the easiest way into your systems — your employees are letting them in. It remains the top attack vector, and it works because users unknowingly open the door. One wrong click is all it takes for an attacker to get in.

Ken: So what’s our defense? First, block malicious emails before they reach inboxes. Use strong protection — require SPF, DKIM, and DMARC for inbound mail, and run an advanced email threat-protection service that uses AI-based filtering to block messages before they ever hit the mailbox.

Ken: Second, train your users with realistic phishing simulations backed by real-world training — impersonation, invoice scams, credential harvesting, and the other methods your users will actually face. Combining email security with training creates a layer of defense: filters and AI block most threats before they reach the inbox, and when something slips through — and it will — a trained user becomes the final line of defense. This dramatically lowers the chance that a single mistake turns into a major breach.

Ken: In 2024, the top phishing method was impersonation, and the most common lures were emails that appeared to come from your bank, a vendor, or an executive inside your company. Let’s look at what that looks like.

Ken: This is a spoofed email made to look like it’s from me — it’s not — sent to Nick. At first glance it might look real: “As part of our continued effort to improve account security, all employees are required to update their Microsoft 365 password by 5:00 p.m. today. Please click the secure link below… Failure to comply will result in restricted access to your email and Office 365 services.

Ken: What looks right? The recipient is a real user. The email mimics a real IT process — changing passwords. The signature is real: my actual phone number, email address, and Macro’s website. But what’s wrong? The sending domain is a subtle look-alike, not the real macrotg.com. And the tone — an urgent 5:00 p.m. deadline, “failure to comply” — those are scare tactics designed to short-circuit logical thinking. My employees know I don’t talk like that, so knowing the person and having a relationship helps.

Ken: Hover over the link and you’d see a bogus URL or a URL shortener. One overarching tip: never change your password from a link in an email unless you requested it and received it in real time.

Ken: Say I didn’t catch any of that and clicked. In this example it takes me to a completely bogus URL — and that’s the biggest giveaway. Regardless of how real the page looks, the URL isn’t Microsoft. Our company uses company branding on the Microsoft 365 login page; that’s missing here, and the logo is in the bottom-right instead of the center. Phishing isn’t really about the email — it’s about what happens next. The whole goal of the page is to get you to log in. Once you enter your credentials, attackers can log in as you, potentially bypass MFA if token theft is involved, and start accessing your data.

8:44 · Attack #2 — Compromised Credentials

Ken: Even with all the new technology out there, weak or reused passwords are still one of the easiest ways attackers get in. They don’t need to hack your system — they just log in.

Ken: The defense is phishing-resistant MFA. Traditional MFA can be phished. One way is MFA fatigue: users get so many push prompts that eventually they just approve one — that’s exactly how Uber was breached. Another weak method is SMS text codes, because attackers have ported phone numbers at the provider level to a SIM card on their side, and a lot of Android apps silently forward text messages. Phishing-resistant methods like number matching or FIDO2 hardware keys prevent these.

Ken: You also need to flag risky sign-ins and leaked credentials. Tools like Microsoft Entra ID Protection and SOC monitoring automatically detect strange behavior — sign-ins from new countries, or passwords found on the dark web — and let you respond. Legacy authentication — any protocol that doesn’t require MFA, like legacy SMTP, IMAP/POP, or basic HTTP auth — needs to be disabled.

Ken: Require strong, unique passwords, enforced at the system level but also taught. Users almost always reuse passwords across services, so if, say, LinkedIn gets breached, that password could be the same or close for their email, computer, or bank. Adding an exclamation point or a number at the end doesn’t help — attackers see the password in clear text during a breach, and just changing the last character is a well-known habit. Better yet, passkeys, passwordless, biometrics, and device-bound credentials are growing fast because they’re secure and simple, and they can eliminate the password risk entirely.

Ken: There’s also token replay — too much to fully cover here, but essentially attackers use a real login page as a proxy and steal your session token. It can be blocked with tools like Conditional Access and Entra ID that detect and block suspicious session hijacking. If you’d like, we can do a whole webinar on just that one.

11:43 · Data Leaks & the Dark Web

Ken: Here’s an example of a credential dump floating around the dark web, from one of the LinkedIn database leaks — it includes 159 million credentials, emails and passwords in plain text. If any of your employees used the same email-and-password combo for LinkedIn as they did for a work service, attackers now have that too. This is where legacy MFA can let you down.

Ken: If an attacker has your email — say kwidmer@macrotg.com — and a password from a list like this, they can test those credentials across common login portals. If text-based MFA is enabled, many services reveal the last four digits of your mobile number during login. From there they do a reverse lookup on the number, find the carrier, gather a few personal details, and initiate a SIM swap — giving them your texts, calls, and MFA codes. So to reiterate: a lot of the time breaches happen not by hacking, but by getting access to your login.

Ken: We just covered two ways credentials get stolen — database leaks and entering them into malicious URLs. When a credential is compromised and appears on the dark web, you need a service that monitors for it. One option is Microsoft Identity Protection: if your email and password show up on the dark web, Microsoft can automatically trigger a playbook — emailing you, blocking the user, forcing a password change, and more. For actions like anonymous-IP sign-ins or password spray, we can block sign-ins automatically so the threat is stopped in real time.

14:00 · Attack #3 — Exploited Vulnerabilities

Ken: Another overlooked attack surface is your devices — this is where the actual hacking happens. Attackers don’t need to invent zero-days or hack like in the movies. Successful breaches happen when companies miss a patch, leave default settings, and fail to harden their systems.

Ken: The defense: automate patching on supported operating systems. Last month we talked about the importance of supported operating systems with Windows 10 going end of life — and that’s true for servers too. Once you’re on a supported OS, it needs to stay patched. We do this at Macro with Datto for our managed devices, but whatever the tool, every system and application needs to be up to date — especially with all the zero-day and critical vulnerabilities going around.

Ken: Use vulnerability-management tools. Something like Tenable scans your environment the same way an attacker would — looking for an exploit, an open CVE, or a poor misconfiguration — and makes your team aware so you can remediate before it’s exploited. And secure configuration has to happen, because default settings are not secure. We apply hardened baselines across Windows using Intune; if you still use Group Policy, it can be hardened there, but it needs to be done through management software.

Ken: Beyond patching and hardening, maintain 24/7 threat detection and response through SOC analysts who triage alerts, validate threats, and contain them across endpoints and cloud. And again — user education. The user is often the weakest link; no amount of patching or automation protects against a user who lets the attacker in, so train your users multiple times a year and test regularly, not just once.

16:27 · Attack #4 — Malware & Ransomware

Ken: We’ve all heard of companies brought to a standstill by ransomware — hospitals turning patients away, schools losing access to student data, businesses frozen for days. These attacks can lock you out in minutes, which is why rapid isolation, training, scanning, and daily ransomware-proof backups are critical.

Ken: We don’t rely on outdated antivirus anymore. The industry has moved to EDR backed by 24/7 SOC monitoring: if suspicious behavior is detected, the endpoint is isolated automatically, stopping the threat before it spreads. Everything we’ve talked about today — blocking the email, EDR, updated operating systems and applications, SOC monitoring — is about intercepting threats before they execute. It’s not just detection; it’s prevention across every layer.

Ken: A zero-trust security model enforces least-privilege access — Conditional Access, application allow-listing with AppLocker or similar — regularly checking that users and applications can only reach what they truly need. That minimizes the blast radius if a single account is compromised. Finally, back up daily: even with the best defenses you plan for the worst case, so systems need to be backed up at least daily, and the backup needs to be air-gapped and immutable so it can recover from ransomware quickly.

18:44 · Live Demo: An Attacker Inside a Workstation

Ken: Let’s go back to that phishing link. Say I clicked it — but instead of stealing my password, the goal was to find an outdated operating system or browser and release a payload on my desktop.

Ken: Here’s a side-by-side. On the right is the user’s workstation right after they clicked the link; a payload executed through a browser vulnerability and allowed remote access — that’s the attacker’s view on the left — while the user has no idea anyone’s connected. On the workstation there’s a “sensitive documents” folder; it’s easy to search for keywords an attacker would want. Knowing the user has no clue, the attacker can take their time browsing the folders, find the files they want, and simply transfer them to themselves. And there they are.

21:03 · Attack #5 — Insider Threats

Ken: Not all threats come from outside hackers or misclicks. Some come from trusted insiders abusing their access to steal data or do harm.

Ken: The defense is similar to protecting against a breach: audit access regularly and give users only what they need, which lowers how much an insider can take. Institute sensitivity labels and DLP policies — classifying data and restricting its movement with data-loss-prevention software like Microsoft Purview Information Protection blocks users from sending sensitive info such as Social Security numbers or financials outside the organization, whether by accident or on purpose. You can set these to block emailing, downloading, or uploading, however you like.

Ken: Monitor user activity in real time — we use Microsoft Defender for Cloud Apps to audit logs and watch for unusual behavior like mass downloads, sign-ins from new locations, or weird Exchange roles. When an alert fires, you can run a playbook to block the user or open a ticket. And trace activity with audit logs: every system needs auditing turned on — domain, Microsoft 365, any cloud provider — so you can go back and see who accessed what, when, and have what you need for an investigation.

23:12 · The Ultimate Tech Stack

Nick: Thanks, Ken. Let’s talk about the ultimate tech stack and the products we at Macro use ourselves to keep clients as secure as possible. The key point: no single tool can do it all — true resilience lives in layers.

Nick: First, Microsoft 365 handles identity, compliance, and collaboration. Then AppRiver email threat protection filters out malicious messages and junk before they reach a user. Third, SentinelOne next-gen antivirus and EDR focuses on endpoint detection and response, stopping threats before they spread through a device or the network. A footnote I always add: typical AV like McAfee or Webroot uses a defined list of known viruses — what we call the “yellow pages” of viruses, a reactive approach. SentinelOne pairs that list with advanced process monitoring for a far more proactive, superior product.

Nick: Acronis handles backups and ransomware recovery — encrypted, stored offsite, and immutable. KnowBe4 provides security-awareness training so you can educate users on what to watch for when a “fishy” email or text reaches them — you’re only as strong as your weakest link, so keeping users trained and vigilant strengthens your security. Pillar operates as our 24/7/365 SOC (Security Operations Center), where dedicated experts monitor the environment via a lightweight agent that works alongside SentinelOne to identify and quarantine malicious activity before it spreads. And Tenable manages vulnerability assessment and exposure, helping prioritize and remediate risks.

Nick: The takeaway: no single tool does it all. True resilience comes from layering these tools together into a comprehensive defense that covers every aspect of IT security — making your infrastructure robust, secure, and capable of withstanding a variety of threats.

27:18 · What to Do Next

Nick: So where do you go from here? First, test your defenses against common threats like phishing, password reuse, and unpatched vulnerabilities — those are the entry points attackers exploit. Next, review and harden your access controls so only authorized people can reach sensitive information. Then strengthen user awareness and reporting — educate your team on the latest phishing tactics and encourage them to report suspicious activity.

Nick: Finally, book a cybersecurity risk assessment — a proactive step that identifies vulnerabilities before they become a problem. That’s where we can help: our team offers comprehensive risk assessments and a range of managed-service plans to fortify your environment, so your defenses are robust, up to date, and give you peace of mind in an ever-evolving threat landscape.

28:44 · Q&A

Nick: Let’s open it up. First question is for Ken — can you share a recent example of a breach with a client, how it happened, and how we handled it?

Ken: Some of you may have gotten a call or text from me last night. SonicWall was issued a zero-day: if you use their SSL VPN to connect remotely to the office, the vulnerability let someone without the username, password, or MFA connect to the VPN and deploy ransomware from there. We received the alert and proactively turned it off. Thankfully none of our environments were affected — it was a security alert we responded to right away.

Nick: Lisa asks: leaked credentials can be flagged — how would we even know if one of our passwords showed up on the dark web?

Ken: In my example I used Microsoft Entra, but there are other services too. These vendors actually buy the breach lists — Microsoft pays for the breach data, uploads it, and runs checks against their database of passwords. Other monitoring tools will simply email you the username and password that were exposed, in clear text. There’s also a website, Have I Been Pwned (haveibeenpwned.com), where you can check your own email; if you’re in a breach you can sign up and it’ll show the exposed credentials. It’s eye-opening.

Nick: Cerillo notes he still uses SMS MFA on a few systems and wants examples of how attackers bypass it.

Ken: It’s more on the Android side than Apple, because the Android store is less locked down — some apps set up SMS forwarding automatically. But what we’ve actually seen in the last year is phone providers allowing numbers to be ported. The fix you should do right away: call your carrier — say Verizon; T-Mobile was especially bad for this — and put a port-out password on your phone number. With a leaked username and password, attackers have a whole runbook of sites they try; wherever you still have SMS, it’ll likely show the last four digits of your number, and with a reverse lookup on your name they get the rest and convince the carrier to port it. These are targeted attacks, but very preventable — make sure your provider won’t port your number without a password and additional ID. If a service only supports SMS and won’t let you use a hardware key, the port-out lock is your protection.

Nick: Jen asks: if our whole company has the entire stack in place, is the only real threat from inside — and can you train our people, and how often?

Ken: Training is the key. Nothing is 100%. If you’d asked us on Monday, we’d have said SonicWall’s SSL VPN is an extremely secure way to connect — and then a vulnerability appears. Even with the full stack, you need someone watching every CVE coming out through CISA and other sources and responding in real time; in that SonicWall case, it was the SOC team that caught it. Training should be required. At a minimum we phish our clients every month and train every other month, depending on the organization’s appetite. Tools like KnowBe4 let you increase training for people who fail more — we gear training toward risk groups: high-risk users train once or twice a month, lower-risk users less often, freeing those hours for more advanced threats like SMS and other social-engineering attacks.

Nick: Jen added that she’s usually the one flagged for remediation and feels like “the failure.” We don’t see it that way at all, Jen. The point is that the weakest link gets identified, and threats are always changing. Ask us about SonicWall yesterday and we’d have had no qualms — the next day there’s a vulnerability. Which leads to Mike’s question: isn’t our antivirus enough — why do we need EDR and SOC monitoring? Because antivirus is reactive and limited, whereas EDR isolates live threats and SOC monitoring watches everything 24/7/365. You can never be too sure when something will hit; being proactive and not waiting for something to happen first is the best way to stop a threat.

Ken: A lot of it is training, and it’s situational. We’ve all gotten the “pay your E-ZPass toll” text. If I actually drove a toll road recently and forgot, I’m more inclined to click it. Same with QR codes: during COVID, restaurants swapped paper menus for QR codes, so attackers pasted their own malicious QR codes over the real ones — you scan to order food and the embedded link delivers a payload. So we’re focused on training and remediation — getting you from where you are to where you should be — and it has to be continuous.

Nick: Wrapping a bow on it: it’s important not just to train, but to continuously train. In the example I gave, that organization trained only once a year, with the same training every year. Pre-COVID, QR-code menus weren’t a thing — then something new gets introduced and you have a new threat. Continuous training is how you get to where you want to be.

41:15 · Closing

Nick: Looks like the well has run dry on Q&A. Ken and I really want to thank everyone for joining. The live webinar was recorded, so you’ll receive an email with the recording soon — probably from my address. As always, we’re here to help with whatever you need for your IT; if you’d like to book a consultation, my contact details are here, so don’t be a stranger. Thank you all again, and we hope to see you in the next one.

Ken: Thanks, everybody. Have a great rest of your day.

Speakers

Ken Widmer
Chief Technology Officer, Macro Technology Group

Nicholas Frangopoulos
Technical Account Manager, Macro Technology Group