Why SMEs are cybercriminals’prime target in the age of AI

Takanori Nishiyama, SVP APAC & Japan Country Manager, Keeper Security

For decades, the golden rule of cybersecurity was simple: trust your gut and look for the typos. Today, thanks to generative AI, the typos are gone, and your gut is no match for an algorithm designed to perfectly mimic your most trusted contacts.

Artificial intelligence has quietly erased the traditional warning signs, such as suspicious email addresses, poor quality graphics and spelling errors, that we were all taught to look out for. A phishing email can now read like genuine correspondence from a supplier or a bank, and familiar voices on the phone are easily replicated. Research from security awareness training provider KnowBe4 found that 82.6% of phishing emails now contain AI-generated content. The cues we relied on are disappearing, and most people have not yet caught up.

This is the defining shift in cybersecurity today. Attacks are personalized, fluent and produced at scale. Criminals can now generate thousands of tailored lures at once, each engineered to exploit your trust.

The Verizon Data Breach Investigations Report continues to find that the human element is involved in roughly six out of every ten breaches, suggesting attackers are still aiming at people rather than firewalls.

Credentials remain the prize

The objective of a cybercriminal rarely changes. The simplest path to access within an organization is a valid set of credentials.

Usernames and passwords remain the keys to conducting business for most organizations, from email and banking to customer records. Credentials are attractive because they are efficient: an attacker with working credentials does not need to break in, they simply log in. With a working login, the attacker can then escalate privileges and move laterally to reach connected systems – quietly extracting company data.

A stolen credential rarely stops at the account it opened. Password reuse remains common, and a single credential often unlocks far more than the single account it came from. If attackers have no immediate use for what they steal, there is still a market for it.

Stolen credentials are bundled and sold on underground forums, where they fuel identity theft, fraud and the next wave of cyber-attacks.

That persistence is what makes credentials such a valuable prize.

Why this hits smaller businesses the hardest

There is a widespread myth that cybercriminals only target large enterprises, however the data tells a different story. Research from cyber insurance firm Embroker found that 46% of all cyber-attacks worldwide affect organizations with fewer than 1,000 employees, and the smallest businesses face substantially more social engineering attempts than their larger peers.

Operational downtime, regulatory penalties and the loss of customer trust can compound quickly, and oftentimes, one incident is enough to put a company out of business altogether. Small and Medium-sized Enterprises (SMEs) face the same threat landscape as global corporations, but with smaller budgets, fewer specialists and less time.

Fundamentals that still work

The encouraging part of this story is that the most effective defenses are not the most expensive solutions. The fundamentals that protect credentials remain the strongest protection against the majority of cyber-attacks, and they are within reach for any organization – regardless of size or security expertise.

  • Use strong, unique passwords for every account. A password manager makes this sustainable rather than aspirational, removing the need to generate or memorize complex passwords.
  • Implement Multi-Factor Authentication (MFA) everywhere it’s available. MFA ensures a stolen password alone is not enough to get in, providing an extra layer of verification.
  • Reduce network access to minimize the attack surface and limit how far an attacker can move within the organization. Grant access only to what a role requires and remove it the moment it is no longer needed. A Privileged Access Management (PAM) solution enforces least-privilege access based on role-defined policies.

None of these steps demand large security teams or a specialist budget, only consistency and the right solutions. The threats facing small businesses have never been more convincing, but the answer is not complicated.

Organizations that protect their credentials and limit access are the hardest to catch off guard.

Previous articleStudy examines how distraction reshapes workplace engagement
Next articleAI adoption value may lag without workflow integration