Written by Sarah Accongio, Market Development Specialist at Alvaka

For years, many smaller businesses have operated under an assumption that quietly shaped their cybersecurity decisions: Why would a ransomware group bother with us?

A regional dental practice is not a Fortune 500 company. Neither is a growing medspa, a 40-person law firm, an accounting practice, a property management company, or a regional manufacturer. But that may increasingly be the wrong question.

Artificial intelligence is changing the economics of cybercrime. As attackers automate more of the work traditionally performed by people, the amount of time and manpower required to target an organization can decrease. And if attacking a business becomes faster and cheaper, the business does not necessarily need to represent an enormous payday to become worth attacking.

How Is AI Changing Cyberattacks?

Cybercriminals face the same constraint every legitimate business does: labor. Finding potential victims, researching employees, scanning infrastructure, identifying vulnerabilities, creating convincing phishing messages, harvesting credentials, maintaining attack infrastructure, and troubleshooting failed attempts all require time.

AI is beginning to change that equation.

Google Threat Intelligence Group (GTIG) recently reported that threat actors are progressing from basic AI prompting toward agentic AI workflows and AI-enabled automation. In one financially motivated operation observed in 2026, an attacker compromised cloud infrastructure and then used an AI-enabled framework to plan, build, and execute a mass credential-harvesting campaign in less than six hours. The framework could autonomously manage vulnerability scanning, troubleshoot problems, rotate IP addresses, and harvest credentials with substantially less human intervention. Thousands of third-party credentials were compromised.

That represents an important shift. AI is not simply helping an attacker write a better phishing email. It is beginning to automate portions of the attack process itself.

For defenders, that can mean less time to recognize and stop an attack. For smaller businesses, it may mean something else too:

You may be becoming a more economical target.

Are Smaller Businesses Becoming Bigger Ransomware Targets?

Smaller and mid-sized organizations are already significant ransomware targets. Black Kite’s 2026 Mid-Market Ransomware Report analyzed 13,336 disclosed ransomware and extortion incidents with verifiable revenue across North America and Europe between January 2023 and June 2026. It found that 73% involved organizations earning between $10 million and $1 billion annually.

Within that group, businesses earning just $10 million to $50 million represented the largest portion of victims every year studied. Separate Black Kite research also found that the $1 million to $5 million revenue segment nearly doubled its share of ransomware victims in its latest reporting period.

The idea that ransomware is primarily a big-enterprise problem is increasingly difficult to defend. And AI could push that economics further down-market.

We should be careful about what the evidence does and does not tell us. We cannot yet say that AI is causing ransomware groups to systematically move toward every category of small business. But we can make a reasonable prediction based on what is changing:

As AI reduces the human effort required to identify, research, and attack potential victims, organizations that once appeared too small to justify an attacker’s time may become increasingly attractive targets.

Which Smaller Businesses Should Be Paying Attention?

Consider a growing medspa. It may have started with a single injector and grown into a multimillion-dollar operation with employees, multiple locations, patient records, photographs, payment information, email accounts, cloud applications, and regulated health information.

To its owner, it may still feel like a small business. To an attacker, it may look like valuable data, meaningful revenue, operational dependence on technology, and a relatively small IT/security operation protecting all of it.

The same logic applies to dental and orthodontic practices. A ransomware incident can affect patient records, imaging, scheduling, billing, and the systems required to operate the practice. But this extends far beyond healthcare.

Law firms possess privileged communications, financial records, litigation strategy, intellectual property, and sensitive client information. Accounting and bookkeeping firms may have tax returns, Social Security numbers, payroll information, banking information, and access to client financial systems.

Title, escrow, mortgage, and real estate businesses combine sensitive personal information with large and time-sensitive financial transactions. Property management companies hold tenant data, payment information, leases, banking details, vendor information, and increasingly connected property systems.

Manufacturers may have less regulated personal data, but downtime itself creates tremendous leverage. If systems are unavailable and a company cannot manufacture, fulfill orders, or ship products, every hour can have a measurable cost.

Construction companies, veterinary practices, insurance agencies, logistics providers, architecture and engineering firms, auto dealerships, private schools, and many other growing businesses share some combination of the same characteristics. They have something valuable to steal, something important to disrupt, and fewer cybersecurity resources than a large enterprise.

The ransomware data already reflects much of this. Manufacturing represents 25.8% of the mid-market victims in Black Kite’s dataset, followed by professional and technical services and construction. Healthcare, wholesale, information, and education also appear among heavily affected sectors.

Small Doesn’t Mean Invisible Anymore

AI is not necessarily creating an entirely new cybersecurity problem. In many cases, it is allowing attackers to find and exploit the security problems businesses already had, only faster and at greater scale.

An old employee account that was never disabled.

A remote-access system without multifactor authentication.

An unpatched internet-facing device.

A password reused across accounts.

An employee who receives an extremely convincing email appearing to come from an executive or vendor.

A backup environment accessible with credentials connected to production.

A malicious message that reaches an employee’s inbox.

Poorly controlled administrative privileges.

Those weaknesses mattered before generative AI. The difference is that attackers are gaining better tools for finding and exploiting them.

That makes basic cybersecurity discipline more important, not less.

You Don’t Need an Enterprise Security Budget. You Need Security Discipline.

A 30-person company does not need to replicate the cybersecurity department of a multinational corporation. It does need to stop treating cybersecurity as something that can wait until the company becomes bigger.

CISA’s guidance for small and medium-sized businesses emphasizes fundamentals including phishing protection, strong passwords, multifactor authentication, software updates, logging, backups, and encryption. Its ransomware guidance specifically recommends phishing-resistant MFA for email, VPNs, and accounts that access critical systems, as well as offline, encrypted, regularly tested backups.

For smaller organizations, we believe several areas deserve particular attention.

Protect identity. Require MFA wherever possible, particularly for email, remote access, administrators, and systems containing sensitive information. Remove stale accounts, limit administrative privileges, and make sure access disappears when an employee or vendor no longer needs it.

Protect email. Email remains an important point where technology and human trust intersect. Organizations should use layered email security capable of identifying malicious messages, impersonation attempts, suspicious links, and other threats before they reach employees. Solutions such as Alvaka’s Mailworx can add another layer of protection around one of the most frequently used business communication systems.

Patch what attackers can see. Know which systems are exposed to the internet and establish a repeatable vulnerability and patch-management process. A critical vulnerability should not sit unnoticed because nobody knew which system was responsible for it. Alvaka’s Patchworx helps organizations maintain the patching discipline necessary to reduce that exposure.

Monitor the environment. As attack timelines shrink, relying on someone to manually notice suspicious activity becomes increasingly dangerous. Continuous monitoring and managed detection can help identify abnormal behavior before an attacker has had days to operate unnoticed. This is part of the reason Alvaka developed ODIN 360 around ongoing visibility, monitoring, and protection.

Protect your ability to recover. Backups should be protected from the same credentials and systems attackers may compromise. They should also be tested. Finding out during a ransomware incident that a backup is inaccessible, incomplete, or encrypted is too late.

Create verification procedures. Employees should know that familiarity is no longer proof of authenticity. An email that sounds exactly like the CEO, a message written perfectly in a vendor’s normal style, or even convincing audio should not override established procedures. Requests involving money, credentials, sensitive data, or unusual access should have an independent verification process.

What Does Safe AI Adoption Look Like for a Small Business?

There is another side of this conversation that matters just as much.

The answer is not to stop using AI.

AI can give a smaller organization capabilities that previously required a much larger staff. It can help employees analyze information, automate repetitive work, improve customer service, create content, write software, and operate more efficiently. Businesses should absolutely be exploring those opportunities.

But AI adoption and cybersecurity cannot be treated as two separate initiatives. GTIG has also observed attackers targeting AI assets themselves, including proprietary models, source code, prompts, API credentials, and cloud computing resources.

As businesses adopt AI, they need to know:

  • What AI tools are employees using?
  • What customer, patient, financial, or proprietary information are employees allowed to enter into those tools?
  • Who has access to company AI accounts?
  • Where are API keys and credentials stored?
  • Are AI-generated code and automations reviewed before being deployed?
  • What happens when an employee leaves?
  • Are third-party AI vendors being evaluated before sensitive information is shared with them?

And perhaps most importantly: Does adopting AI introduce a new connection to data or systems that nobody on the security side knows exists?

Shadow AI can become the next version of shadow IT.

The goal should not be to prevent employees from using transformative technology. The goal should be to adopt it intentionally, with security controls developing alongside the technology rather than years behind it.

Protect Your Business From AI While Learning to Use It Safely

Small businesses are being presented with an enormous opportunity. AI can allow a 20-person company to operate with capabilities that once required a much larger organization.

But the same economic advantage is becoming available to the people trying to attack it.

That means business owners should be asking two questions at the same time:

How can we use AI to make our company better?

How do we make sure AI doesn’t make us easier to attack?

The answer to the second question does not begin with some futuristic AI security product. It starts with the fundamentals.

Protect identities. Secure email. Patch vulnerabilities. Monitor systems. Segment access. Protect and test backups. Train employees to verify unusual requests. Know where sensitive information lives. Understand which AI tools are being used inside the organization.

And have a plan for what happens if those defenses fail.

The businesses that benefit most from AI won’t necessarily be the ones that adopt it the fastest. They’ll be the ones that learn how to use it without abandoning the security practices protecting everything they’ve built.

At Alvaka, we help organizations strengthen those fundamentals, monitor their environments, reduce exposure, and prepare for the incidents they hope never happen.

Because as attackers become faster and more automated, being “too small to target” is not a security strategy.