Ask ten small business owners what a cyberattack looks like and you will probably hear about hackers in hoodies typing furiously in a dark room. The reality is more boring, and more useful to understand. Most attacks on small businesses start with an email that looks like it came from a vendor, a password that leaked online two years ago, or a phone call from someone claiming to be tech support. Nobody types furiously. Increasingly, nobody types at all. Software does the hunting.

Here is the encouraging part: the list of what actually hits small businesses is short. Verizon’s 2025 Data Breach Investigations Report found that just three attack patterns, system intrusion, social engineering, and basic web application attacks, accounted for 96 percent of breaches at small and mid-sized businesses. Underneath those categories sit five specific attacks that show up again and again, and every one of them has a cheap, proven counter. Let’s take the tour in plain English.

1. Phishing and Business Email Compromise

Phishing is any message built to trick someone into clicking a link, opening a file, or typing a password where they should not. Business email compromise, or BEC, is its expensive cousin. In a BEC attack, a criminal either breaks into a real email account or imitates one convincingly, then quietly talks someone into sending money to the wrong place. A vendor’s “updated bank details.” An owner’s “urgent wire request” sent five minutes before close of business.

The FBI’s Internet Crime Complaint Center logged 191,561 phishing and spoofing complaints in its 2025 Internet Crime Report, more than any other crime type. BEC produced far fewer complaints, 24,768, but more than 3 billion dollars in reported losses. That averages out to roughly 123,000 dollars per incident, which is not a rounding error for a small company.

  • Your odds: High. If your business has email, you are already in the pool. Check your spam folder if you doubt it.
  • The cheapest counter: A standing rule that any change to payment details, and any urgent money request, gets verified with a phone call to a number you already had on file. That rule costs nothing and defeats most BEC attempts cold.

If you are wondering why filters do not simply block all of this, we dug into that in our post on why phishing keeps getting through.

2. Ransomware

Ransomware is malicious software that scrambles your files and demands payment to unscramble them. Modern crews also steal a copy of your data first so they can threaten to publish it if you refuse to pay. That second trick matters, because it means backups alone no longer make you bulletproof, though they remain your single best lever.

This is the attack where company size changes the picture most. Verizon found ransomware present in 88 percent of breaches at small and mid-sized businesses, compared with 39 percent at large organizations. Criminals know smaller companies tend to have thinner defenses and less ability to survive two weeks of downtime, so the pressure to pay is higher.

  • Your odds: If a breach happens to your business, it very likely involves ransomware. It is the default business model of cybercrime against small companies.
  • The cheapest counter: Backups that are separated from your network, plus the step almost nobody takes: actually testing a restore. A backup you have never restored from is a hope, not a plan.

3. Stolen Credentials

Sometimes there is no trick at all. Attackers simply log in. Passwords leak in breaches at other companies, get harvested by infostealer malware, or get reused across a dozen accounts, and criminals buy them in bulk. Verizon’s data shows the use of stolen credentials appearing in roughly a third of breaches, and that holds for companies of every size.

This is why “we would notice a hacker” is a shaky bet. A login with a valid password looks exactly like your employee, at least at first, and by the time it looks like anything else the attacker has had plenty of time to explore.

  • Your odds: Near certainty that some of your team’s old passwords are circulating online right now. The real question is whether they still open anything.
  • The cheapest counter: Multi-factor authentication on email, banking, and remote access, plus a password manager so nobody has to reuse passwords just to get through the workday.

4. Social Engineering by Phone and Text

Not every con arrives by email. Pretexting is the industry term for an invented story: the caller claiming to be your bank’s fraud department, the text from “the owner” asking someone to grab gift cards, the friendly technician who needs a login to fix an outage you did not know you had. Verizon notes that pretexting attacks are actually more common at small businesses than at large ones.

Let’s be clear about something. Falling for one of these does not make anyone careless. These scripts are written, tested, and refined to work on smart, busy people, and newer AI tools help criminals sound local, polished, and legitimate.

  • Your odds: Moderate and rising, especially for whoever handles money or holds admin access.
  • The cheapest counter: A culture where verifying is praised, never punished. Hang up and call back on a known number. Any real bank, vendor, or IT provider will respect that every time.

5. Vendor and Partner Compromise

The last attack does not start with you at all. It starts with your bookkeeper, your software provider, or your IT company. When a business you trust gets breached, attackers inherit that trust: real email threads to reply into, real invoices to alter, sometimes direct access into your systems through tools you approved long ago.

You cannot patch someone else’s network. You are not helpless either.

  • Your odds: Lower than phishing, but growing, and harder to spot because everything about the message is genuine except the person behind it.
  • The cheapest counter: Give vendors the minimum access they need, remove it the day a relationship ends, and apply the same callback rule to vendor payment changes as to everything else. Then ask your key vendors one question: do you require multi-factor authentication internally? The answer tells you plenty.

The Bottom Line

You do not need a Fortune 500 budget to handle this list. Multi-factor authentication, tested backups, a payment verification rule, prompt software updates, and a healthy hang-up-and-call-back habit blunt all five attacks at once. What you no longer get to assume is time. CrowdStrike’s 2026 Global Threat Report clocked the average gap between an attacker’s first foothold and their move deeper into a network at 29 minutes. Defenses have to be in place before the email arrives, which is the case we made in why cybersecurity is no longer optional.

Harrison Ward Technology helps Denton County businesses put these exact defenses in place without drama or jargon. If you want a straight answer about which of these five would hit you hardest today, we will give you one. Contact us today


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).