Prepared for Texas MSPs, healthcare practices, multi-location operators, and small business owners who don’t have time to become IT experts
Nextechnologies Labs Private Limited · AstraLink CONNECT
Executive Summary
Running a business in Texas means wearing a lot of hats. Network security is rarely the one anyone signed up for. But over the last several years, a clear pattern has shown up in breach after breach across MSPs, healthcare providers, cities, and the small businesses that depend on all of them: the damage almost never came from some genius hacker outsmarting a team of experts. It came from an ordinary gap. A shared login. A VPN with no second check. A vendor with more access than they needed. A door nobody remembered was unlocked.
This paper walks through six real incidents that touched Texas directly, in plain language, and lays out exactly where AstraLink CONNECT would have closed the gap that let each one happen. The goal isn’t to scare anyone into buying something. It’s to show, incident by incident, that the fix for most of this is a lot simpler than people assume.
The Common Thread
Whether the victim was a two-truck ambulance service or a pipeline running the length of the Gulf Coast, three things kept showing up:
- A login or remote-access tool with no real second layer of protection behind it.
- A vendor, contractor, or IT tool with more reach into the network than anyone had checked on in a while.
- No clear, immediate signal that something unusual was happening, until it was already too late to stop it.
AstraLink CONNECT was built around closing exactly these three gaps, without asking a busy owner or office manager to become a network engineer to do it.
Case Studies
1. The MSP Domino Effect — Texas Municipalities (August 2019)
Roughly 22 to 23 small Texas towns, including Borger and Keene, hit within hours of each other
What happened: Attackers broke into a Texas-based managed service provider that handled billing, scheduling, and court systems for local governments, then used that provider’s own remote administration tools to push ransomware into every client at once. Police departments couldn’t run license plates. Towns couldn’t process utility payments or issue basic certificates.
Root cause: One shared remote-access tool, trusted by every downstream client, became a single point of failure for all of them.
How AstraLink CONNECT closes this gap: CONNECT’s local-first design means each site keeps running its own network even if the cloud connection or the MSP’s own tools are compromised. Every organization, site, and device is walled off from every other one at the API level, so a breach in one customer’s environment has no path into another customer’s network, even when the same MSP manages both. There is no single shared remote-admin credential that, once stolen, unlocks every client at once.
2. The Vendor Blind Spot — ESO Solutions, Austin (September 2023)
Austin-based vendor serving hospitals, EMS, and state trauma registries; millions of patient records exposed
What happened: An outside party got into ESO’s systems, quietly pulled sensitive data out, and then encrypted core systems with ransomware. The exposed information included names, Social Security numbers, and injury records tied to trauma care across multiple hospital networks.
Root cause: A trusted vendor connection with broad access and no layered detection in front of it, so the intrusion and the data leaving the building both went unnoticed until it was already done.
How AstraLink CONNECT closes this gap: CONNECT’s DNS protection and Suricata-based intrusion detection watch outbound traffic continuously and flag the kind of unusual data movement that signals exfiltration, not just malware signatures. Combined with the Threat Center’s real-time alerting, an office would know something is happening in minutes, not months.
3. The Ransom Standoff — Acadian Ambulance (June 2024)
Emergency medical transport provider operating across Texas; PHI of roughly 2.9 million people compromised
What happened: The Daixin Team ransomware group claimed to have pulled 10 million patient intake records and demanded $7 million. Acadian refused the full demand and was listed on a dark web leak site as a result.
Root cause: Sensitive patient data sat reachable enough that a large-scale extraction could happen before anyone caught it.
How AstraLink CONNECT closes this gap: CONNECT’s device and network segmentation places every device on the appropriate VLAN — trusted, guest, or quarantined — so a compromised laptop or tablet can’t freely reach the systems holding patient records. Firewall rules and geo-blocking add another layer, and every access attempt is logged in an audit trail that can be exported for compliance and incident response.
4. The Quiet Exfiltration — Texas Hearing Institute, Houston (March 2026)
Houston pediatric hearing center; 540 GB of records taken, about 29,500 Texans affected
What happened: The Interlock ransomware group gained unauthorized access and pulled pediatric medical records, financial details, and Social Security numbers out of the network before anyone noticed.
Root cause: No real-time visibility into what was leaving the network, so a large, slow data pull went unnoticed until the damage was done.
How AstraLink CONNECT closes this gap: CONNECT’s Activity and Applications views show exactly what’s moving across the network, by device and by application, in plain terms an office manager can actually read. Unusual volume or an unrecognized destination shows up as a clear alert instead of a mystery discovered weeks later.
5. The Legacy Account — City of Dallas (May 2023)
Royal ransomware group; 1.169 TB exfiltrated, nearly 1,000 hosts encrypted, local small businesses paralyzed for weeks
What happened: Attackers used a phishing email to get into an old service account that had never been set up with multi-factor authentication. From there, they moved through the network largely unchecked. The fallout reached far past city hall: permits, court filings, and city utility payments for local contractors and small businesses ground to a halt for weeks.
Root cause: An old account nobody had circled back to secure became the way in, and there was no second check to stop it once the password was known.
How AstraLink CONNECT closes this gap: CONNECT requires a second verification step for every dashboard login, and every user’s role and access is enforced centrally rather than trusted to whatever was configured on one old account years ago. Role-based access control means a support or service account only ever has the access it was explicitly granted, and every login and access change is written to an audit trail an owner can actually review.
6. The Leaked Credential — Colonial Pipeline (May 2021)
Breach originated at network infrastructure in Houston; 100 GB of billing data taken, pipeline shut down 5 days, over 11,000 small fuel retailers and transport businesses hit by the resulting shortage
What happened: The DarkSide group used a single leaked password, found for sale online, to get into an old VPN account that had no multi-factor authentication turned on. The pipeline itself was shut down as a precaution while the company worked to contain the damage.
Root cause: One password, reused or leaked elsewhere, was all it took to open a remote-access door that had no lock behind it.
How AstraLink CONNECT closes this gap: CONNECT’s remote access runs on NetBird over WireGuard, using device certificates rather than a password sitting on a list somewhere on the internet. There are no open VPN ports for an attacker to find and try a stolen password against in the first place, and every remote session shows up in the VPN Sessions log for review.
What These Breaches Have in Common, and What CONNECT Does About It
| The Recurring Gap | How CONNECT Closes It |
|---|---|
| Passwords and remote access with no second layer of protection | Second-factor verification on every dashboard login, plus certificate-based VPN access with no exposed ports for attackers to target |
| A vendor, MSP, or old account with more reach than anyone tracked | Every organization and site is walled off from every other; role-based access limits exactly what any user or support account can touch, and it’s all logged |
| No real-time signal that something unusual is happening | Continuous intrusion detection, DNS-level threat filtering, and a live Threat Center that surfaces problems in minutes instead of months |
| Sensitive systems reachable from anywhere on the network | Automatic device segmentation (trusted, guest, quarantine) keeps a compromised device from wandering into the systems that hold the data that matters |
What CONNECT Doesn’t Replace
We’d rather be straight with you than oversell this. CONNECT is a strong, central piece of a security setup, but it isn’t the whole picture. It doesn’t replace having offline, air-gapped backups you can restore from if the worst happens. It doesn’t replace basic employee awareness training on phishing emails. And it doesn’t replace cyber liability insurance. Think of it as the part of the house that keeps the wrong people from getting in and tells you right away if someone’s trying. The rest of the plan still matters too.
The Bottom Line
None of the businesses in these six stories thought they’d be the ones in the headlines. Most of them were doing what felt like enough at the time. The pattern across every single case is the same: a small, ordinary gap, left unattended, turned into a very expensive problem. Closing that gap doesn’t require a full IT department or a technical overhaul. It requires the right things running quietly in the background, doing their job, so you can get back to running yours.
AstraLink CONNECT was built for exactly this: real network security for MSPs, healthcare offices, multi-location operators, and small business owners across Texas, without the jargon and without needing to become an IT expert to stay protected.