🔑 MyPillow Ransomware: 5 Small Business Lessons
On this page
MyPillow, the Minnesota-based bedding company founded by Mike Lindell, appeared on the Play ransomware gang's data leak site on Monday with a ransom deadline of just a few days. The gang threatens to publish "private and personal confidential data, client documents, budget, payroll, IDs, taxes, finance information" unless MyPillow pays up. For small business owners watching this unfold, the message is stark: ransomware isn't a problem for big corporations alone — small and medium businesses are the primary targets.
The Play ransomware group claims to have breached MyPillow's systems and exfiltrated sensitive corporate data. According to threat-intel firm FalconFeeds, the gang has given the company until Friday to meet the ransom demand before the stolen data goes public. Play is one of the most active ransomware crews operating today, having hit approximately 900 organizations since 2022, including Microchip Technology (which incurred $21.4 million in incident-related costs) and the Swiss government's IT supplier Xplain.
For small businesses — the core audience of StrongPassFactory — this story hits uncomfortably close to home. According to the Verizon 2025 Data Breach Investigations Report, 43% of cyber attacks target small businesses, yet only 14% of those businesses are prepared to defend themselves. The average ransom demand for small businesses has climbed to $150,000 according to the IBM Cost of a Data Breach 2026 report, and many simply cannot afford to pay — or to recover without paying. We explored how these credential vulnerabilities cascade in our guide to why passwords fail.
Why Small Businesses Are Ransomware's Favourite Target
Ransomware operators don't discriminate by company size. In fact, small and medium businesses are often preferred targets because they typically have weaker security postures, fewer dedicated IT staff, and less sophisticated backup systems than enterprises.
The Play ransomware group's tactics are instructive here. According to Cisco Talos incident responders, Play is among the crews that use so-called "EDR killers" — tools designed to disable endpoint detection and response software before deploying the encryption payload. This military-grade attack technique is now available to any ransomware operator, meaning even a small bedding company like MyPillow faces the same calibre of threat as a Fortune 500 firm.
The True Cost of a Ransomware Attack
When a small business gets hit by ransomware, the visible cost is the ransom demand. But the hidden costs are often far larger: - Downtime and lost revenue — The average small business experiences 21 days of downtime after a ransomware attack (National Cybersecurity Alliance) - Recovery costs — Restoring systems, rebuilding data, and engaging incident response firms - Reputational damage — Customers lose trust when their data may have been exposed - Legal liabilities — GDPR, CCPA, and data breach notification laws impose fines - Insurance premium increases — Cyber insurance rates have risen 300%+ since 2023
How to Protect Your Small Business from Ransomware
1. Enforce Strong, Unique Credentials
Weak or reused passwords are the number one entry point for ransomware operators. Every employee should have unique, cryptographically generated passwords for every business account. Use the StrongPassFactory Generator to create them.
2. Deploy Endpoint Protection
Modern endpoint protection platforms detect ransomware behaviour patterns before encryption completes. Kaspersky Premium includes ransomware-specific protection layers.
3. Implement Offline, Immutable Backups
The 3-2-1 backup rule: three copies of data, on two different media types, with one copy stored offline. Test restoration quarterly.
4. Secure Remote Access
Ransomware operators gain initial access through compromised RDP, VPN credentials, and email. Use Trekmail for encrypted business email and Turbo VPN for remote connections.
5. Train Employees to Recognise Phishing
74% of breaches involve the human element (Verizon 2025 DBIR). Regular security awareness training is your most cost-effective defence. Use Hide My Name VPN for anonymous security research.
6. Create an Incident Response Plan
Document who to contact, how to isolate systems, when to involve law enforcement (CISA, FBI IC3), and the decision framework for paying or not paying.
FAQs
What is the Play ransomware group? Play is a ransomware-as-a-service operation active since 2022, known for double-extortion tactics. It has hit over 900 organisations worldwide including Microchip Technology and Swiss government suppliers.
Why do ransomware groups target small businesses? Small businesses have weaker security infrastructure, fewer dedicated IT staff, and less frequent backup testing. 43% of cyber attacks target small businesses.
Should my small business pay a ransom? The FBI, CISA, and NCSC all recommend against paying. Only 60% of victims who pay get all their data back.
How can password policies help prevent ransomware? Strong, unique passwords prevent credential-stuffing attacks and limit breach blast radius. Our small business password policy guide covers this in depth.
What is the 3-2-1 backup rule? Three copies of data on two different media types, with one copy stored offline. CISA and NIST recommended.
Does having cyber insurance cover ransomware payments? Policies vary widely. Most require MFA, offline backups, and security awareness training before they pay out.
Sources
- FalconFeeds.io, Play ransomware victims list, May 2026
- Verizon 2025 Data Breach Investigations Report
- IBM Cost of a Data Breach 2026
- NIST SP 800-184: Guide for Cybersecurity Event Recovery
- Cisco Talos: Play ransomware EDR-killer capabilities
What the MyPillow Incident Reveals About Third-Party Risk
The MyPillow ransomware attack is a reminder that a breach rarely starts where you expect it. In many small business incidents, the entry point is not the main network but a connected system — a payment processor, a shipping integration, or a third-party plugin. Once attackers are inside one part of your ecosystem, they look for paths to move laterally.
For small businesses, third-party risk is easy to overlook because these connections feel like someone else's responsibility. They are not. If a vendor has access to your customer data or your internal systems, their security posture becomes your problem too.
- Audit every service that has access to your systems, even read-only access.
- Remove integrations you no longer actively use — dormant connections are still open doors.
- Ask vendors directly what their incident response process looks like and whether they carry cyber insurance.
The Backup Problem Most Businesses Discover Too Late
Having a backup is not the same as having a working backup. Ransomware operators know this. A common tactic is to let an infection sit dormant long enough that your backups themselves become encrypted or corrupted before you notice anything is wrong. By the time you try to restore, every copy you have is useless.
The fix is not simply backing up more often. It is verifying that your backups are isolated and that you have actually tested restoring from them.
- Follow the 3-2-1 rule: three copies of your data, on two different media types, with one stored offline or offsite.
- Test your restores on a schedule. Pick a non-critical file or folder monthly and practice the full recovery process, not just the backup step.
- Ensure at least one backup is air-gapped — meaning it is physically disconnected from your network when not in use, so ransomware cannot reach it.
- Check that your backup software logs show completed jobs, not just that the software is running.
Access Credentials: The Overlooked Entry Point
Weak or reused passwords remain one of the most common ways ransomware gets its initial foothold. Attackers purchase lists of leaked credentials from past data breaches and run automated tools that try those combinations against business logins — email accounts, remote desktop tools, admin panels, and cloud services. This is called credential stuffing, and it works at scale because so many people reuse passwords across accounts.
A compromised email account alone can be enough. From there, an attacker can reset passwords for other services, intercept invoices, and eventually reach systems that connect to your broader network.
- Use a unique, strong password for every account — especially anything with admin access or payment data.
- Enable multi-factor authentication on every service that offers it. This single step stops the majority of credential-based attacks even if a password is exposed.
- Check whether any business email addresses have appeared in known breach databases using publicly available lookup services.
- Do not allow employees to use personal email accounts for business logins, since personal accounts are far less likely to have strong security practices.
How to Verify Your Defences Are Actually Working
One of the most common mistakes small businesses make is assuming that because security tools are installed, they are doing their job. Software needs to be updated, configured correctly, and monitored. An outdated endpoint protection tool running on an old definition database is not meaningfully protecting you.
Verification does not require a dedicated IT team. It requires building a short, regular checklist.
- Confirm that operating system updates and security patches are applied promptly across all devices, including any used by remote workers.
- Review who has admin or elevated access to your systems at least once a quarter. Remove access for anyone who no longer needs it.
- Check that remote access tools — such as anything used for working from home — require multi-factor authentication and are not exposed on standard ports.
- Log and review failed login attempts. A sudden spike in failed logins is an early warning sign of a credential attack in progress.
- Walk through your incident response plan once a year. Know who to call, what to shut down first, and how to notify customers if data is involved.
The businesses that recover fastest from ransomware are not necessarily the ones with the most sophisticated tools. They are the ones that prepared, tested their preparations, and knew exactly what to do when something went wrong.