It’s the question we hear most often from small and medium business owners: why would anyone target us? We’re not a bank. We don’t have millions in the account. Surely we’re not worth the effort.
Kaspersky’s newly released 2026 SMB Threat Report puts some hard numbers behind why that thinking is backwards, and why SMBs remain one of the most attractive targets in the entire cybercrime economy.
The Numbers Don’t Lie
In the first four months of 2026 alone, Kaspersky detected over 33,300 attacks on SMBs disguised as popular AI tools. That is almost five times more than the same period in 2025. Add to that nearly 415,000 attacks using fake messenger and video conferencing apps, and another 24,000 disguised as office software, and a pattern emerges: attackers aren’t hunting for big fish. They’re casting wide nets, and small businesses are swimming right into them.
Even more telling: more than half of all “initial access” listings on dark web forums, where criminals sell their way into compromised networks, are for small and medium businesses. That’s not enterprises or banks, but rather businesses like yours.
So Why You?
There are three answers, and none of them require you to be famous, wealthy, or high-profile.
You’re easier to get into. Large enterprises spend millions on layered security, dedicated SOC teams, and round-the-clock monitoring. Most SMBs don’t, and can’t. Attackers know this. A smaller, less-defended target with a working bank account and live email system is a far better use of their time than trying to crack an enterprise firewall.
You’re a way in to someone bigger. This is the one most of us miss. Kaspersky’s research shows “trusted relationship attacks” — where criminals compromise a smaller supplier or contractor to reach a larger client — rose from 12.7% to 15.5% of initial attack vectors in the space of a year. If you invoice a larger company, hold their data, or have system access into their network, you’re not just a target, you’re a stepping stone.
You’re worth money on your own. Whether it’s a fake AI “invoicing tool” that takes a subscription payment and delivers nothing, a scam bank account setup page, or straightforward ransomware, criminals don’t need you to be rich. They just need your payment details, your credentials, or your data to be worth more to you than the ransom they’re asking.
The New Twist: Fake AI Tools
The most striking finding in this year’s report is how fast criminals have moved to exploit AI hype. Malware and scam apps disguised as popular AI tools jumped nearly 500% year-on-year, overtaking fake office software as a lure. Kaspersky specifically flagged fake versions of Claude and OpenClaw as being used to trick business owners into installing malware or handing over payment for tools that don’t exist.
The lesson isn’t “don’t use AI.” It’s the opposite. AI adoption is accelerating, and criminals are riding that wave, betting that curiosity and time pressure will beat caution. Only download AI tools from official sources, and treat any “must-have AI tool” pitch that lands in your inbox with the same suspicion you’d give a too-good-to-be-true loan offer.
Summary
You don’t need to be a target of interest to be a target of opportunity. The report makes clear that:
- Attackers follow trends, not reputations. Whatever’s popular, such as AI tools today, or something else tomorrow, will be weaponised as a lure.
- Being “too small to matter” is the misconception attackers are counting on.
- If you work with or supply larger organisations, your security posture is now part of their risk profile too.
Where to Start
Kaspersky’s own recommendations line up with what we tell clients every day: control who has access to what, back up your data properly, train your team to spot the fakes, and put layered protection in place that fits your size and budget.
If you’re not sure where your business sits on that spectrum, or whether your current setup would actually catch these kinds of attacks, that’s exactly the conversation our advisory team has with clients every week.