On July 31, an accountant at a mid-sized U.S. private equity firm picked up the phone. The caller introduced herself as the firm’s outside counsel, ran through details about an upcoming acquisition, and walked the accountant through a routine wire transfer. The voice was right. The professional shorthand was right. The wire went out. By the time anyone realized “outside counsel” was a synthetic voice generated from fifteen seconds of YouTube audio, roughly $25 million was already in motion.
Reuters reported the campaign on August 7. Levi Strauss was named the same day, hit by an “unauthorized third party” that extracted corporate information. Google and a handful of internet-intelligence firms have linked the activity to a loose cluster of English-speaking extortion crews — groups that used to send mass phishes and now pick up the phone.
If you run a small or midsize business, this is the threat that should keep you up at night. Not ransomware itself — the *delivery mechanism* for ransomware, which is increasingly a friendly voice on the other end of a call.
Phishing has been the number-one way attackers break into small businesses for years. Verizon’s 2025 Data Breach Investigations Report put a fine point on it: 88% of breaches at small and midsize businesses involved ransomware, and ransomware almost never arrives first. It rides in on a stolen credential or a successful phish.
What changed in the last eight months is the quality of the bait. A February 2026 poll by Sagiss and Pollfish found 72% of U.S. desk workers say phishing emails have become more convincing in the past year. The grammar is cleaner, the context tightens to whatever you’re actually working on, and the sender sounds like someone in your building. That’s AI doing what AI does — pattern-matching your org chart, your vendors, your typical phrasing.
Voice cloning pushes it past email. A 2024 IBM survey of 1,000 marketing leaders found roughly 1 in 4 had already experimented with voice-cloning tools. The same tools are commodity-priced on criminal forums. ElevenLabs and a dozen competitors offer them with a credit card and a sixty-second audio sample. Some require less. The fake “counsel” on that $25 million call was built from a public earnings call recording.
The shift matters because phone calls carry trust. We are wired to lower our guard when we hear a human voice asking us to do something routine. A phishing email that asks for an out-of-band wire transfer gets a second look. The same request, in a familiar voice, often does not.
SMBs get hit four times harder than large organizations in raw breach counts, according to Verizon — and that gap is widening. The defenses that worked in 2022 don’t cover what attackers are doing now. Three shifts matter:
Treat every first-time wire instruction as suspect. The classic control here is “call back on a known number.” That’s still right, but it has to mean *a number you already had*, not one the caller gave you. If someone asks you to send money somewhere you haven’t sent money before, insist on a video call or an in-person confirmation, even if the voice sounds exactly right.
Lock down the tools voice cloners use. That public earnings call, the CEO’s podcast appearance, the all-hands Zoom recording — every minute of senior-staff audio posted online is fuel. Most of the damage in 2026 attacks has come from publicly available audio, not from leaked private material. Decide as a leadership team which voices are allowed to be in the public record, and treat the rest as sensitive even if they’re not secret.
Run phishing drills that include the phone. Most awareness training still treats phishing as an email problem. It isn’t anymore. The Sagiss poll found workers are roughly twice as likely to fall for an AI-generated voice call as for a polished phish. Your training program should test the same muscle — pause, verify out-of-band, escalate — across email, text, and voice.
You don’t need a SOC to do any of this. You need a written policy that anyone with the authority to move money knows cold, and a culture that says “weird gut feeling” is a legitimate reason to slow down.

Here is a workable routine for a 50-person company with a finance team of three:
None of this requires new software. It requires writing it down, repeating it, and rewarding employees who escalate instead of punishing them for slowing a $40,000 payment by ten minutes.
The attackers aren’t smarter. They have cheaper tools. A phishing kit that took a skilled operator a week to build in 2021 now takes an afternoon, and the voice-cloning equivalent fits in a chat prompt. That’s the entire shift: the floor has dropped out from under the small-business defender, and the controls written before 2024 assume an attacker who has to spend time and money to sound convincing.
They don’t anymore. Your controls need to assume they were convincing from the start, and your people need permission to slow the train when something feels off.
That $25 million wire started with a phone call. The next one starts with a calendar invite.

Last year, 63% of small businesses watched their cyber insurance premiums jump 200% or more. This year, the carriers are not just charging more. They are sending applications with a checklist that looks a lot like a security audit. For a lot of small business owners, that checklist is the first time anyone has told them, in writing, what the minimum actually is.
That is the real story right now. Attackers have always known small businesses are softer targets. What is new is that insurance companies have started pricing it that way too, and they are not willing to write checks to companies that cannot prove they are doing the basics.
A few data points that explain why this is happening:
These are not theoretical numbers. The $100,000 figure is not a worst-case scenario — it is closer to a median. Average ransomware payments from US small businesses last year ran about $115,000. Add forensic investigation, customer notification, legal fees, and the cost of downtime, and the real bill is usually two or three times the ransom itself.
The companies that survive these events are not the ones with the best security in their peer group. They are the ones that had enough working controls that an underwriter was willing to back them.
Cyber insurance used to be closer to a credit-card application. “Do you have a firewall? Yes. Approved.” That era is over. In 2026, carriers verify the answers. They ask for screenshots, logs, and configuration exports. The Coalition and Fisch Solutions renewal checklists for 2026 spell it out:
If a small business cannot produce those five items, the carrier either declines the policy, charges a deductible that makes the coverage almost pointless, or excludes ransomware from the policy entirely.

The frustrating part is that almost none of these controls are expensive or exotic. Phishing-resistant MFA is free with Microsoft 365 or Google Workspace for most companies. EDR tools from companies like CrowdStrike, SentinelOne, or even Microsoft Defender for Business run in the low double digits per endpoint per month. Backups to an immutable cloud target with quarterly restore tests are a weekend project, not a quarter-long engagement.
So why is the gap so wide? A few reasons, all familiar:
If you are a small business owner, here is the practical list. Not the long version, just the one that will get you through an insurance application and meaningfully reduce your real risk.
None of these are fun projects. All of them are cheaper than a bad week.

For most of the last decade, small businesses have been told that cybersecurity is “important” in the same vague way flossing is important. The insurance market has finally done what the awareness campaigns could not: it has attached a dollar amount to the gap, and it has started refusing to insure the gap.
That is a painful adjustment, but it is also the first honest market signal small business owners have ever gotten about what the minimum looks like. The companies that take the checklist seriously, even the ones doing it grudgingly while filling out a renewal form, will end up safer than the ones that wait for an incident to teach the lesson.
The 40% who cannot survive a six-figure attack are not going to learn it from a magazine article. They are going to learn it from the next invoice, the next claim denial, or the next morning when a workstation shows a ransom note instead of a desktop. The good news is that the checklist to avoid all three of those mornings fits on one page, costs less than a part-time hire, and does not require a security team to operate.
It just requires the decision to start.
Sources
Last week’s article looked at management consoles as the new front door. This week, the same idea is showing up in a different place: the network itself.
In July, more than 30 Minnesota water systems were targeted in a coordinated cyberattack. One plant went offline. Around the same time, The Hacker News reported that attackers were using a compromised third-party advertising script to swap cryptocurrency wallet addresses on customer sites. Different victims, different techniques, same weakness: organizations trusted the network path around a system more than the system’s own security.
For a small business, that should change the question from “Is the server patched?” to “What can move through our network, and who can make that happen?”
Most companies still draw their environments as a few boxes: users, servers, cloud apps, and maybe a firewall in front. Actual traffic is messier. A laptop moves between home Wi-Fi and the office. A vendor gets remote access to a building-control system. A SaaS integration receives an API token. A managed service provider can log into half the environment from one console.
Each connection creates a trust decision. Those decisions pile up quietly because they usually work. The HVAC vendor can reach the controller. The accounting software can pull payroll data. The developer can access the build server. Nobody notices until an attacker inherits one of those permissions.
The Minnesota water-system incident is a useful warning even for companies nowhere near critical infrastructure. An attacker does not need to own every machine to cause an outage. Access to one operational system, one remote-management account, or one poorly separated network segment can be enough.
Network security is therefore less about building a taller wall and more about limiting the blast radius when somebody gets through.
Small businesses depend heavily on outside providers. That is sensible. Few 100-person companies should run their own email, payroll, endpoint management, backup infrastructure, and building systems.
The problem is that vendor access tends to outlive the original project. A contractor receives a VPN account for a migration. The account remains active for years. A remote-management agent gets installed on every workstation. Nobody checks which technician can use it. A service account has broad permissions because narrowing them would take an afternoon that never appears on the calendar.
Recent incidents involving N-able N-central servers show why this matters. N-central is used by managed service providers to administer customer environments. The Hacker News reported that attackers were able to take over servers after an initial fix proved incomplete. A flaw in a central management layer can turn one compromise into a customer-by-customer problem.
The practical lesson is uncomfortable: your vendor’s security model is part of your network model. If a provider can reach your endpoints, domain controllers, backup systems, or firewall, that provider is effectively inside your security boundary.
Ask vendors four direct questions:
If the answers are vague, treat the access as a risk you own.

A flat network is convenient right up until ransomware arrives. Once an attacker lands on one workstation, every reachable system becomes part of the next move: file shares, identity services, backups, printers, cameras, and operational equipment.
Segmentation does not require a six-figure redesign. Start with a few boundaries that reflect business impact:
The rule is simple: a device should be able to reach what it needs, not whatever happens to share the same switch.
Test those rules from the outside and from inside. A firewall diagram is a plan, not proof. A quarterly review of actual routes and firewall logs will catch the forgotten exception that a policy document will not.
Network security also includes the services users barely notice. DNS decides where a browser goes. Advertising and analytics scripts decide what code loads in a page. Wi-Fi decides which network a device joins.
Attackers keep exploiting those layers because they sit between a user and the application they think they are using. Recent reports of poisoned web scripts and hijacked hotel Wi-Fi pushing fake software updates show the same pattern in public and private networks: control the path, then let the victim do the clicking.
For SMBs, a few controls make a real difference. Use a managed DNS resolver with malware and newly registered-domain blocking. Prevent endpoints from silently changing DNS settings. Require browsers and operating systems to update through trusted channels, and train staff to treat browser pop-ups that demand an update as hostile until proven otherwise.
For public-facing websites, maintain an inventory of third-party scripts. Remove anything nobody can explain. Pin versions where practical, monitor changes to the site’s JavaScript, and avoid loading payment or authentication pages with unnecessary external code.

The network is no longer background plumbing. It carries identity, automation, vendor access, and the commands that keep the business running. The organizations that handle the next breach best will not be the ones with the longest security product list. They will be the ones that made compromise boring: one account, one device, one segment, and no easy route to everything else.
Sources
Reply with ‘post it’ and the images will be added and the article will go live.
A deepfake video call cost Arup $25M. The same playbook is hitting SMBs every week — and most security programs haven’t caught up.
In early 2024, an accountant at the engineering firm Arup sat down for what looked like a routine video conference. The CFO was on the call. So were several other colleagues. Everyone looked right. Everyone sounded right. The only problem: none of them were real. A finance worker wired roughly $25 million to attackers who had fabricated the entire meeting with deepfake video and cloned voices.
That case made global headlines. The quieter story is the one playing out at thousands of small and mid-sized businesses every week: an “executive” emails an AP clerk asking for a wire transfer, a “vendor” calls about updating payment details, a “Microsoft technician” leaves a voicemail that sounds exactly like your IT director. Generative AI has turned social engineering from a craft into a production line, and most security programs have not caught up.
For most of the last decade, phishing emails were easy to spot. Bad grammar, mismatched sender domains, generic greetings. The defenders’ advantage was that attacks were expensive to personalize at scale. An attacker could blast a million generic “Nigerian prince” emails, or send a hundred highly targeted ones. They chose the first.
That trade-off is gone. Large language models let attackers produce clean, fluent, locally appropriate phishing copy in any language. Voice cloning tools need as little as ten seconds of audio to mimic a specific person. Deepfake video has moved from research demos to real-time face-swaps on a commodity laptop. The cost of a targeted attack has dropped by orders of magnitude, and the volume has followed.
A 2024 study by IBM’s X-Force found that AI-generated phishing emails had a click-through rate about 70% higher than the human-written kind. A separate analysis from the UK’s National Cyber Security Centre warned that the average employee can no longer tell the difference. We are past the point where user-reported “this email felt weird” is a reliable defense.
Three patterns are showing up over and over in incident reports.
1. The impersonated vendor. Attackers research a company’s real suppliers, then email the AP team from a look-alike domain saying banking details have changed. The invoice is real, the dollar amount matches a known contract, and the signature line includes a plausible employee whose LinkedIn profile they scraped last week. AI writes the email in flawless English, including the small talk about the recipient’s recent promotion.
2. The cloned executive. Voice cloning needs a target’s voice from a podcast, earnings call, or public video. Most executives in a public company have hours of this content online. The attacker calls an employee, often outside business hours, with a calm “I’m in a meeting, can you do me a quick favor” request. The request is usually a gift card purchase, a wire transfer, or the disclosure of an MFA code.
3. The deepfake meeting. The Arup case is the template. A fabricated Teams or Zoom meeting with multiple fake participants, all of whom look and sound like real colleagues. The goal is usually authorizing a financial transaction or harvesting credentials. The sophistication has been climbing through 2025 and 2026.

Big banks and tech firms have spent twenty years building layered defenses. They still get hit, but the cost per attempt is high enough to push attackers elsewhere. A 50-person marketing agency or a regional medical practice has none of that. The CEO’s voice is on the company website. The accounting team’s job titles are on LinkedIn. The whole org chart is one Google search away.
The defender’s math is also worse. A large enterprise can absorb a six-figure loss. A small business that loses $200,000 to a fraudulent wire transfer is often looking at layoffs, or closing. Ransomware actors know this, which is why attacks on companies under 200 employees have roughly doubled in the last two years.
There is no silver bullet, but a few practical moves close most of the gap.
Use a verbal callback on any out-of-band financial request. If the CFO emails asking for a wire transfer, call her back on a number you already have. Not a number in the email. A cloned voice sounds real on a first listen, but the attacker cannot answer your callback because they do not control your executive’s actual phone. This one habit stops the majority of BEC fraud in incident data, and it costs nothing.
Treat any change-of-payment-details request as hostile by default. Require that changes be confirmed through a known channel, with a second person signing off. The friction is real. It is also the reason your finance team has not already been robbed.
Train on the new reality, not the old one. Most security awareness programs were built around 2015 phishing: bad grammar, obvious scams, hover-to-preview. Update the curriculum. Show staff real AI-generated phishing samples. Run a tabletop exercise that uses voice cloning. The goal is not to make people paranoid; it is to make them skeptical in a structured way.
Lock down public executive content where you can. You do not have to delete the CEO’s podcast appearances. But you can stop posting new high-quality video of their face and voice on public pages, and you can coach executives to use work accounts for sensitive calls. Audio and video of a person walking through an airport is enough to build a convincing clone.
Adopt phishing-resistant MFA. Hardware security keys (FIDO2/WebAuthn) and platform-bound passkeys cannot be phished by a fake login page, no matter how convincing. They are the single highest-ROI control most small businesses are still not using.

AI has not invented a new category of attack. Social engineering has always worked because humans are the easiest part of any system to fool. What AI did was make the cost curve bend sharply in the attacker’s favor. The defenses that worked when attacks were expensive and rare are eroding, and the ones that work now (out-of-band verification, hardware MFA, structured skepticism) require actual process change, not just another product.
The companies that are handling this well are the ones that stopped expecting email to be a trustworthy channel for money, credentials, or sensitive instructions. That is a cultural shift more than a technical one, and it is the work of the next few years.
If you do one thing this week, pick the highest-risk workflow in your business (the one where a single email or phone call can move money or grant access) and add a verbal callback step. It will feel slow. It is also the reason you will not be in the next incident report.
Why “we have multi-factor authentication” stopped being a reassuring sentence in 2026 — and what SMBs should do this week.
If you bought MFA in 2020 and forgot about it, this article is for you.
On May 24, 2026, the FBI put out an unusual flash alert. A phishing kit called Kali365 — sold as a subscription on Telegram, of all places — was hitting Microsoft 365 accounts at hundreds of organizations. The headlines screamed that it “bypasses MFA.” A few hours of reading made me realize that’s the wrong way to think about it. Kali365 doesn’t bypass MFA. It bypasses you — the part of the system that is still, embarrassingly, the easiest thing to attack.
If you run IT for a 50-to-500-person company, here’s what changed, why it changed, and what to do before the next vendor breach shows up in your inbox.

For a long time, MFA was the line in the sand. You drew it between “people who got phished” and “people who didn’t.” In 2026, that line is somewhere it isn’t useful anymore.
Three things happened in the last month that I think every IT leader should know about:
1. Kali365 and the rise of consent phishing. The FBI alert describes a kit that tricks a user into clicking “Allow” on a malicious OAuth app. No password is typed. No MFA prompt is shown. The user authorizes an app, the app gets a refresh token, and from that point forward the attacker is the user — until someone revokes the token or it expires. Microsoft 365 sits behind more than a million U.S. companies. Most of them have no idea which third-party apps their employees have already authorized. (FBI warning, May 24, 2026; reported by TechRadar, HotHardware, TechTimes.)
2. CrowdStrike’s 2026 Financial Services Threat Report found that the single most common attacker against banks and insurers last year never phished a password at all. They phished a session. Once a user authenticated successfully, the attacker stole the cookie and rode it across the rest of the network. The report’s framing is sharp: MFA verifies who logged in. It has no idea what they do next.
3. SonicWall CVE-2024-12802. A previously-patched SSL-VPN authentication bypass got re-bypassed by a new flaw disclosed in mid-May. The lesson isn’t about SonicWall specifically. It’s that identity-layer bugs are showing up in the patches designed to fix identity-layer bugs. Every appliance you expose to the internet deserves a second look this quarter.
Put those three stories next to the GitHub breach on May 20 (a poisoned VS Code extension on an employee’s laptop, 3,800 internal repos gone in a single worm) and the picture is hard to argue with: the attackers have moved past your login screen.
When I say “you have MFA,” I want to know which kind. The difference matters more than it used to.
| Method | Can Kali365 / token-theft beat it? |
|---|---|
| SMS codes | Yes. SIM swap, SS7 routing, prompt bombing. |
| Authenticator app (TOTP) | Mostly yes. Real-time phishing proxies relay the code before it expires. |
| Push notifications (Duo, Microsoft Authenticator push) | Yes. Prompt bombing (“are you sure? are you sure?”) and adversary-in-the-middle kits. |
| FIDO2 / WebAuthn / Passkeys (YubiKey, Windows Hello, Apple passkeys) | No. The key is bound to the real domain. A fake login page can’t complete the handshake. |

Microsoft, Google, and CISA have all said, in writing, that FIDO2-based credentials are the only MFA worth buying for new deployments. If your authenticator app has a green “Approve” button, you should be planning a migration. Hardware keys cost roughly $25-$50 per employee. For a 100-person shop, that’s a one-weekend project and a meaningful dent in your attack surface.

If I were running IT at a small business and could only pick five things, this is the list — in order of how much risk it actually buys down:
Turn on conditional access. In Entra ID (Azure AD) or Google Workspace, require device compliance, block legacy authentication, and restrict sign-ins by country or IP range. Legacy auth is where most of the OAuth-token attacks still land. Microsoft has a one-click toggle in the Entra admin center. Do it this afternoon.
Audit OAuth consents. Go to https://myapps.microsoft.com (or the Google equivalent) and click “My Apps.” Look at every third-party app a user has authorized. You will be horrified. Revoke anything you don’t recognize. The Kali365 attack leaves a long trail of “Mailbox.Read” or “Files.ReadWrite” grants with publisher names like “K365Sync” or “CloudBackup365.” Train your finance and HR teams to never click “Accept” on a Microsoft 365 consent screen — full stop.
Move admin accounts to phishing-resistant MFA. Domain admins, finance, anyone who can move money or change payroll. Hardware key only. No exceptions. The single biggest dollar-loss events in 2025 all started with a privileged account.
Set session lifetime to 8 hours or less. A stolen token is only useful until it expires. Shorter sessions mean more re-auth prompts, but the alternative is a 30-day refresh token that an attacker can hand around the dark web.
Watch the post-authentication behavior, not the login. This is the conceptual shift. Push alerts, Slack messages, MFA prompts — those are login-layer signals. You also need post-login signals: which mailbox rules were created, which OAuth grants were added, which file-share permissions were changed in the last 24 hours. Microsoft Defender, Huntress, and a dozen newer tools now do this. Pick one and turn it on.
I don’t say this to scare anyone. The attackers aren’t smarter than they were in 2022. They just got more patient. A Kali365 subscription costs a few hundred dollars a month. An hour of a junior analyst’s time at your company is worth more than that. The economics have flipped, and the defense has to flip with it.
MFA is still the best thing most of you have done. It’s just no longer the last thing. The next layer — what happens after a user proves who they are — is where the work is now. The good news: most of it is policy, not purchases. You can do a meaningful chunk of it this week, before the next alert shows up in your inbox.
Have a question about your own MFA setup? Reply to the newsletter — I read every message. If you want a second pair of eyes on your Microsoft 365 or Google Workspace tenant, that’s exactly the kind of thing we do.
Word count: ~1,090
The old advice was simple: you’re probably too small to bother with. Cybercriminals go after the big fish, the enterprises with millions of customer records and deep pockets. Run a 50-person accounting firm or a regional plumbing supply company? You’re safe.
That logic is now dangerously outdated.
In 2025, 80% of small businesses experienced at least one cyberattack. Not because they were unlucky or singled out, but because automated attack tools have made it cheap and easy to sweep for vulnerabilities across millions of small business systems simultaneously. You’re not being targeted. You’re being fished.
Small businesses have the same digital footprint as large enterprises, minus the security budget. You run Microsoft 365. You have remote employees accessing shared drives. You probably use some cloud-based accounting software, a CRM, maybe a VoIP phone system. Each connection point is a potential entry.
A Fortune 500 company has a security operations center monitoring those entry points 24/7. You have whoever handles IT when they’re not doing something else.
This is exactly what attackers exploit. Ransomware-as-a-Service platforms now let anyone with a few hundred dollars and minimal technical skill launch professional-grade attacks. The tools have gotten better; the barrier to entry has dropped to nearly zero. Three ransomware groups were responsible for nearly half of all ransomware attacks in a recent month, and they weren’t exclusively going after big targets.

Forty-one percent of small business cyber incidents in 2025 were AI-driven. Phishing emails that used to announce themselves with bad grammar and obvious red flags now read like internal memos from your CEO. Business Email Compromise attacks, where attackers impersonate executives or vendors to wire money, increasingly use AI to generate convincing correspondence. In Q2 of last year, 40% of BEC emails were AI-generated.
This matters for small businesses because you lack the dedicated training resources that larger organizations can throw at employee awareness. Your team isn’t getting quarterly phishing simulations and security briefings. They get a memo once a year, maybe.
Attackers know this. They’ve calibrated their tools accordingly.
The numbers are grim. For companies with fewer than 500 employees, the average cost of a data breach now runs $3.31 million. That’s not a typo. That’s direct costs, regulatory fines, legal fees, lost business while systems are down, and the customers who never come back.
Most small businesses don’t have cyber insurance that covers this. Many don’t have any cyber insurance at all. Of those that do, policy language often excludes certain types of attacks or requires documentation standards that small businesses can’t meet in the chaos of an incident.
The survival rate after a significant cyberattack for a small business is grim. Not because the attacks are technically unstoppable, but because the financial shock is often terminal.
“We use a cloud provider, so we’re covered.” Your cloud provider secures their infrastructure. You’re responsible for your data, your access controls, your configuration. The 2019 Capital One breach happened because of a misconfigured web application firewall, not a failure at Amazon’s end.
“Our employees would never click on that.” The most sophisticated phishing emails don’t look like phishing emails. They look like DocuSign notifications, QuickBooks invoices, or a Slack message from your office manager about a voicemail. By the time someone realizes something’s wrong, it’s too late.
“We’d know if we were attacked.” dwell time, the period between a breach and its discovery, averages over 200 days for small businesses. Your systems might be compromised right now, with an attacker watching your email traffic and mapping your financial processes, waiting for the right moment to strike.
You don’t need enterprise security to dramatically reduce your risk. The basics work; they just require consistency.
Multi-factor authentication on everything. If your email is compromised, attackers have a foothold into everything else. One compromised email account has been the starting point for breaches that cost companies millions. Every account, no exceptions.
Offline backups. Ransomware attackers specifically target backups first. If your backup solution is connected to your network, it can be encrypted along with everything else. Offline, tested backups that you can actually restore from are non-negotiable.
Patch management. A decade-old vulnerability in a VPN appliance was responsible for millions in breach costs in 2024. The vulnerability had been patched. The companies affected hadn’t applied the update. Pick one day a month to update critical systems and treat it like a business meeting you can’t cancel.

Incident response plan. Only 34% of small businesses have a formal incident response plan. When you’re in the middle of an attack is a terrible time to figure out who does what, which systems to shut down first, and how to communicate with customers. Write the plan now, while your systems are running normally.
Assume your vendors are a risk. Your IT managed service provider, your payroll processor, the software your accountant uses to access your books, all of these are potential entry points. Ask your vendors about their security practices. If they can’t give you a straight answer, that’s information.
You can’t prevent every attack. Nation-state actors and determined criminals will sometimes get through no matter what you do. What you can do is make yourself a harder target than the business next door, build systems that recover quickly, and understand that security is not a product you buy but a practice you maintain.
The attackers aren’t going to stop targeting small businesses. The tools are getting cheaper and more sophisticated. The only question is whether you’re going to do anything about it before something happens, not after.
The FBI’s Internet Crime Complaint Center received over 21,000 BEC complaints with adjusted losses exceeding $2.9 billion in 2023. Industry analysts estimate the real number is significantly higher because most businesses quietly absorb losses rather than report them publicly.
The average BEC wire transfer loss for mid-size companies now sits around $498,000, according to an AFP/Fortress Security survey. For companies under 100 employees, the median loss is lower but still devastating in proportion to revenue.
BEC works because it doesn’t hack systems — it hacks people. An attacker impersonates a vendor, CEO, or IT administrator and asks for something routine: an invoice paid to a new account, a wire transfer, a change to direct deposit credentials.
The sophistication has increased dramatically. Modern BEC actors research their targets: they know the vendor relationships, the CFO’s travel schedule, the timing of quarterly payments. They don’t need malware or phishing links. A convincing email voice and a sense of urgency are enough.

The most common BEC variant — vendor email compromise — exploits the trust between businesses. An attacker compromises a vendor’s email, monitors invoices, and then sends a convincing update asking the customer to route payment to a new account.
By the time the real vendor follows up on the unpaid invoice, the money is gone and the bank account is empty. Recovery rates are near zero. Law enforcement can track the funds but the money moves through multiple intermediary accounts in days.
BEC emails share common patterns that are obvious in retrospect:
Urgency is the biggest tell. “We need this processed today” or “The CEO is asking personally” creates pressure that bypasses normal verification steps. Legitimate requests from real vendors rarely demand same-day wire transfers out of nowhere.

The most effective BEC defense is also the simplest: out-of-band verification. If someone requests a wire transfer or payment change via email, you call them back on a known-good number — not the number in the email. This one control breaks the attack chain entirely.
For vendors and financial requests, establish a callback verification process as standard operating procedure. Any request to change payment details should trigger a mandatory confirmation call before processing.
Dual authorization on wire transfers above a threshold dollar amount adds a second human to the decision, which dramatically reduces the effectiveness of urgency-based attacks.
Training employees to recognize BEC patterns is table stakes. But training alone fails because BEC emails don’t look like phishing — they look like normal business communication. The cultural shift that matters is making it safe for employees to slow down and verify, without feeling like they’re questioning authority or slowing down the business.
The $2.9 billion figure from the FBI is a floor, not a ceiling. Companies don’t report BEC incidents because of reputational concerns, legal exposure, and the uncomfortable admission that someone in accounting got fooled by a stranger pretending to be a trusted vendor.
This silence benefits attackers. Every successful BEC that goes unreported means the attackers can use the same playbook again against another company in the same industry, with the same vendor relationships, without fear of law enforcement catching on.
BEC is not a technology problem you can solve with better email filtering. It’s a human problem that requires human solutions: verified processes, dual controls, and a culture where verification is a habit, not a怀疑.
Last month, researchers flagged 73 malicious VS Code extensions delivering GlassWorm v2 malware — backdoors that spread across IDEs and steal credentials from developers who thought they were installing productivity tools. The unsettling part: these extensions had been sitting in the marketplace since December 2025, building reputation before the malicious update dropped.
Then came the Checkmarx news. A supply chain attack through the Trivy ecosystem let attackers tamper with GitHub Actions workflows and VS Code plugins. The ripple effect: Bitwarden’s CLI npm package got briefly compromised. Source code, employee databases, API keys, and database credentials for an Israeli security company ended up on a dark web leak site.
These aren’t freak events. They’re the pattern now. And small businesses are especially exposed.
## The Trust Problem Nobody Talks About
Developers trust their tools. That’s the vulnerability. When you install an extension in your IDE, you’re handing a third party access to every file you open, every secret you type, every credential sitting in your environment variables. Legitimate extensions need these permissions to work. Malicious ones abuse them.
The 73 fake VS Code extensions followed a playbook that’s become standard: real-sounding names, copied descriptions from popular extensions, months of harmless behavior, then a poisoned update. By the time the payload fires, thousands of developers have already granted broad permissions.
For a small dev shop, one compromised machine means production access, client data, and potentially your entire CI/CD pipeline. The blast radius is massive.

## What’s Actually Hitting Small Businesses Right Now
The Checkmarx incident is the headline, but it’s one data point in a larger picture:
– Fake help desk operations are calling employees directly and landing in Slack DMs
– AI prompt injection is being used to booby-trap websites that your team visits
– Wiper malware variants originally built for energy infrastructure are being repurposed
– RMM tools are getting compromised, giving attackers persistent remote access that looks legitimate to antivirus software
– Phishing kits have become cheap enough that amateur operators are running them
Most small companies don’t have a security team. They have one or two IT people who are already stretched across everything else. When a convincing phishing message lands in an employee’s inbox, there’s no second set of eyes to catch it.
## What You Can Actually Do About It
This isn’t theoretical. Audit your developer tools today. Every VS Code extension, Chrome add-on, npm package, GitHub Action — if you can’t verify what it does and who maintains it, remove it. Tools like Socket.dev and Snyk can monitor dependencies automatically and flag behavior that changes after installation, like an extension suddenly trying to read your environment variables.
Lock down your CI/CD pipelines. If anyone with repo write access can modify workflow files, that’s an privilege escalation path. Use CODEOWNERS files, enforce branch protection, and audit who actually has workflow modification permissions. The Checkmarx attackers got in through GitHub Actions — a part of the stack most teams never review.
Treat your RMM software like critical infrastructure. If you use ConnectWise, Datto, or similar tools, enforce MFA everywhere, limit who has access, and watch for anomalies. Attackers target RMM because it gives them remote access that blends in with normal administrative activity.
For your help desk and frontline staff: run real scenario-based exercises, not the annual video training that everyone fast-forwards through. “You get a Teams message from IT asking you to run a command — what do you do?” Make it specific. Make it uncomfortable. The fake help desk operators rely on people not questioning authority.
Before installing any extension, check when it was published, who published it, and whether that publisher has a track record. A one-off extension with a thousand installs and broad permissions is a different risk than something from a known vendor. Better yet, maintain a curated list of approved extensions for your team instead of leaving it to individual judgment.

## The Hard Truth
Small businesses get hit not because attackers are particularly sophisticated, but because defenders don’t have the time. The economics of cybercrime have shifted: access to corporate networks gets sold on forums, phishing kits go for pocket change, and supply chain attacks turn every victim into a distributor.
You can’t out-budget this problem. But you can reduce exposure by focusing on the things attackers keep exploiting: trusted tools that turn malicious, overpermissioned integrations, and employees trained to trust anything that looks official.
Those 73 fake VS Code extensions are still out there. The next Trivy-style compromise is probably already in progress somewhere. The question is whether you’ll find out before it finds you.
The good news: small practices don’t need to outrun the bear. They just need to be harder to penetrate than the practice down the street.
Attackers are opportunistic. Most ransomware groups run automated scanning that flags easy targets — unpatched VPNs, legacy protocols left exposed, admin accounts without MFA. Solid MFA, current patches, and offline backups will stop a large percentage of the automated attacks before they ever become incidents.

The sophisticated operators — the ones who do hands-on intrusion, move laterally, and exfiltrate data over weeks — are typically targeting larger organizations with deeper pockets and more valuable data. A regional medical practice, a local accounting firm, a construction company with $10M in annual revenue: these aren’t their primary targets.
That doesn’t mean small businesses are safe. It means the bar is different. You’re not defending against nation-state APT groups. You’re defending against automated toolkits, opportunistic ransomware operators, and the occasional targeted attack that lands in your inbox.

**Multi-factor authentication on everything.** Every remote access point, every admin console, every cloud service. This alone stops the majority of automated attacks. If your VPN doesn’t support MFA, replace the VPN.
**Patch management that actually runs.** Not “we try to patch within 30 days.” Automated patching for endpoints, and a documented process for critical infrastructure patches within 72 hours. Most exploited vulnerabilities in recent attacks were known and patched months before the incidents happened.
**Offline backups, and test them.** Ransomware operators know backups. They target them. Your backup strategy needs to assume that your online backups will be compromised alongside the primary systems. One offline copy, tested quarterly, with a documented restore procedure.
The goal isn’t perfection. It’s making your practice harder to compromise than the one down the street. Attackers aren’t making emotional decisions — they’re running economics. The time and cost to breach your network versus the likely payoff.
When you harden your environment, you move yourself off the automated target list and into the “too much work for too little return” category. That’s a winning security strategy for a small organization.
You don’t need a massive security budget. You need the right controls, applied consistently, with backups you can actually rely on when it matters.
Most organizations are deploying AI faster than they’re building security controls for it. The result is a growing gap between what AI can do in your environment and what your security team can actually see or defend.
AI security governance is about closing that gap — establishing a structured set of policies, controls, and oversight mechanisms before an incident forces the conversation.

**AI Asset Inventory**
You can’t secure what you don’t know exists. Build a comprehensive catalog of every AI model, AI-enabled tool, and AI-integrated system in your environment. This includes vendor-hosted models your users access through SaaS applications, internal models served via APIs, and anything connected to your data pipelines. Treat this inventory with the same rigor you’d apply to your critical asset list.
**Model Risk Tiering**
Not all AI systems carry the same risk. A model that summarizes internal documents sits in a different risk category than one that makes access control decisions or processes customer PII. Tier your models by consequence: what happens if this model is compromised, poisoned, or leaks data? Use that consequence level to drive controls — higher tier means stricter access controls, more logging, and more frequent evaluation.
**Input and Output Monitoring**
AI systems are an attack surface through their inputs and outputs. Monitor for adversarial inputs — prompt injection attempts, malformed requests designed to bypass safeguards, or data that signals reconnaissance against your AI infrastructure. Log AI outputs with enough context to support forensic investigation if something goes wrong. This is also where you catch model behavior drift that might indicate tampering.
**Incident Response for AI-Specific Breaches**
Your existing IR playbook probably doesn’t cover what happens when a threat actor manipulates a model’s behavior, steals training data, or uses your AI system as an attack vector against other targets. Build AI-specific scenarios into your tabletop exercises. Define escalation paths, containment steps, and communication protocols for AI incidents before they happen.

MITRE ATLAS — the Adversarial Threat Landscape for Artificial-Intelligence Systems — documents the specific techniques adversaries use against AI systems. Once you have your AI inventory and risk tiers, you can map your existing controls against ATLAS techniques most relevant to your environment. Gaps in coverage become your priority remediation list.
You don’t need to build all four pillars at once. Start with inventory and tiering — those two steps alone give your team enough visibility to have an honest conversation about AI risk. From there, add monitoring where the consequence of an incident is highest, and build the IR playbook as a distinct workstream.
The organizations that will be in the best position two years from now are the ones that started building governance structures today. Not perfect structures — just functional ones, with enough foundation to grow as the threat landscape evolves.