Back to Blog

Do Hackers Target Small Businesses? What the Data Actually Says

"We're too small to be a target." If you run a small business, you've probably said some version of this, and it doesn't come from carelessness. It comes from a reasonable mental model of how crime works: thieves case the biggest house on the street, so hackers must go after the Fortune 500. Why would a criminal in another country care about a 15-person company in Georgia?

The short answer is that they don't care, and that's exactly the problem. Modern cybercrime doesn't work like casing a neighborhood. It works like fishing with a net. Understanding that difference is the single most useful mental shift a business owner can make about security, so let's walk through what the data shows, without the scare tactics this topic usually attracts.

A hooded figure at a laptop formed from streams of binary code on a dark background, representing an anonymous, automated cyberattacker
Most attacks aren't personal. Automated tools and mass phishing catch whoever is exposed, regardless of company size.

First, an Honest Word About the Statistics

If you search this question, you'll find a statistic repeated everywhere: "60% of small businesses close within six months of a cyberattack." We're not going to use it. That number has circulated for over a decade without a verifiable source, and the organization it's usually attributed to has distanced itself from it. It survives because it's scary, not because it's solid.

That matters here, because this topic doesn't need inflated numbers. The verifiable data is convincing on its own, and it comes from one of the most respected datasets in the industry: the Verizon Data Breach Investigations Report, which analyzes thousands of real-world breaches every year.

What the Data Shows

Here is the finding worth sitting with. According to the Verizon DBIR, ransomware or other extortion malware shows up in 88% of breaches at small and mid-sized organizations, compared with 39% at large enterprises. Read that again in plain terms: when a smaller company gets breached, it is overwhelmingly likely to be a ransomware event, the kind that encrypts systems, halts operations, and comes with a demand attached. Large companies see a much broader spread of attack types. Small companies get the extortion.

Estimates of how much overall attack volume hits small businesses vary by study, from roughly a quarter to half of all attacks depending on how you count. The precise share matters less than the direction every dataset agrees on: small businesses are not being skipped. They are absorbing a large slice of global attack volume while employing a small slice of the world's security staff.

88% of SMB breaches involve ransomware or extortion, per the Verizon DBIR
39% the same figure at large enterprises
64% of victims now refuse to pay the ransom, up from 50% two years ago

Why Attackers Come After Smaller Companies

The "too small to matter" logic fails because it assumes a human is choosing targets. Mostly, nobody is.

The targeting is automated. Attackers run scanning tools that sweep the entire internet for exposed systems, unpatched software, and open remote-access ports. Phishing campaigns go out to millions of addresses at once. Your business isn't selected the way a burglar selects a house; it's caught the way a fish is caught in a trawl net. The net doesn't know or care how big you are. It only cares whether you're catchable.

Smaller businesses are softer. Enterprises have security teams, monitoring, segmentation, and tested recovery plans. Many small businesses have an antivirus subscription and good intentions. Attackers know this, and the DBIR numbers reflect it: the extortion-heavy attack mix at SMBs exists because ransomware works more often there. A criminal doesn't need a million-dollar payday from you. A five-figure payment from a business that can't operate without its systems, multiplied across hundreds of victims, is an excellent business model.

You're also a door to bigger targets. Small companies sit in the supply chains of larger ones. Attackers routinely compromise a small vendor to reach its customers, which is one reason your bigger clients have started sending you security questionnaires. Being small doesn't take you off the map; being connected puts you on it.

What It Actually Costs

Skip the apocalyptic framing; the ordinary version is expensive enough. A ransomware event typically means days to weeks of disrupted operations, emergency IT costs, possible data loss, breach notification obligations if customer data was involved, and hard conversations with clients. Even when nothing is paid, and 64% of victims now refuse to, the downtime alone is the real bill. For a business that runs lean, losing a week of operations is not an abstraction.

The BEC variety of attack, where a fraudulent email tricks someone into wiring money, routinely costs tens to hundreds of thousands per incident. We wrote a full breakdown of how those scams work in our business email compromise post, and they hit small companies precisely because the controls that stop them, like dual approval on wire transfers, often aren't in place.

The Good News Buried in the Data

Here's the part the scary articles leave out: the same data shows that basic, unglamorous controls stop most of this.

The attacks hitting small businesses are mostly commodity attacks. They're automated, high-volume, and built to exploit the absence of fundamentals. That means the defense isn't an enterprise security budget. It's the fundamentals themselves: multi-factor authentication everywhere, endpoint detection on every machine, tested offsite backups, email authentication, patched software, and employees who know what a phishing attempt looks like. None of that is exotic, and together it takes your business out of the "catchable" category for the large majority of what's floating in the net. We covered several of these in 5 IT Mistakes Small Businesses Make, and the overlap is not a coincidence.

A useful way to think about it: you don't have to outrun the bear. Automated attacks succeed by finding the easiest available victims at scale. A small business with the fundamentals in place is a worse deal for an attacker than the thousands of businesses without them, and commodity crime follows the deal.

So, Are You a Target?

Yes, in the same way every business with an internet connection is: not personally selected, but permanently in the water where the nets are. The comforting version of "too small to matter" isn't supported by any dataset we can find, and the businesses that internalize this early spend modestly on fundamentals. The ones that internalize it after an incident spend much more, all at once, at the worst possible time.

The question worth asking isn't whether you're a target. It's whether you're an easy one, and that part, unlike the attack volume, is entirely within your control.

Common Questions About Small Business Cyberattacks

Do hackers really target small businesses?

Yes, though not by hand-picking them. Modern attacks are automated: scanning tools sweep the whole internet for exposed systems and phishing goes out to millions of addresses at once, so a small business is caught like a fish in a net rather than chosen like a house to burgle. The Verizon DBIR finds ransomware or extortion in 88% of breaches at small and mid-sized organizations, versus 39% at large enterprises.

Why would a hacker go after a small business?

Because the targeting is automated and small businesses tend to be softer targets, with an antivirus subscription where an enterprise has a security team. A five-figure ransom from a company that can't operate without its systems, multiplied across hundreds of victims, is an effective business model. Small companies are also a door to bigger ones, since attackers compromise a small vendor to reach its larger customers.

How can a small business protect itself from cyberattacks?

Most attacks hitting small businesses are commodity attacks that basic fundamentals stop: multi-factor authentication everywhere, endpoint detection on every machine, tested offsite backups, email authentication, patched software, and employees who can spot a phishing attempt. None of it is exotic, and together it moves your business out of the easy-target category for the large majority of automated attacks.

Not sure whether your fundamentals are actually in place?

CNI can assess where your business stands, tell you plainly what's covered and what isn't, and fix the gaps that matter first. No pitch, no pressure.

Talk to CNI  

Sources: Verizon 2025 Data Breach Investigations Report, SMB Snapshot (88% vs. 39% extortion malware figures); Infosecurity Magazine: Verizon DBIR, Small Businesses Bearing the Brunt of Ransomware Attacks (64% of victims refusing payment); Verizon 2025 DBIR full report. Attack-share estimates vary by study; ranges cited reflect Verizon DBIR analysis and Cybersecurity Ventures figures.