AI is making cyberattacks faster. Is your small business keeping up?
CyberSecurity

AI is making cyberattacks faster. Is your small business keeping up?

One attacker used hundreds of AI bots to break into 395 companies in hours. Scary, but the defense hasn't changed, and it's simpler than you think. Here's what actually protects you.

In late August 2026, something happened that security experts had warned about for years. A single attacker used hundreds of AI agents, working largely on their own, to break into 395 organizations across 48 countries in a matter of hours. In one burst, 11 organizations were compromised in 26 seconds. One school went from first break-in to total control of its network in seven minutes. It was one of the first clearly documented cases of AI running an entire cyberattack, from start to finish, with barely a human touching the keyboard. If you run a small business, this sounds alarming, and it is significant. But the practical response is calmer and more reassuring than the headlines suggest. Here is what actually happened, what it means for you, and the basics that still protect you.

The short version

AI didn't invent a new kind of attack. It made old attacks faster, cheaper, and possible at massive scale, one attacker can now do the work of a whole team. The defenses that protected you last year still work: patch quickly, reduce what's exposed to the internet, use multi-factor logins, and keep backups. What has changed is speed. "We'll get to that update next month" used to be fine. Now, the window between a flaw becoming known and being attacked can be hours, so acting fast is the new baseline.

Cybersecurity news often reads like it's meant for large corporations with security teams. This story is different, because it makes the case for why small businesses, who often assume they're too small to be a target, need to take the basics seriously. Let's break it down without the jargon.

What actually happened

A skilled attacker found two flaws in a piece of business software (a print-management tool used by many organizations). Normally, exploiting those flaws across hundreds of targets would take a team of hackers weeks of tedious manual work. Instead, this attacker set up AI agents to do it, to scan the internet for vulnerable systems, break in, escalate their access, and move through the networks, largely automatically.

The results were striking not because the technique was new, but because of the speed and scale. Hundreds of organizations were hit in hours rather than weeks. Schools and universities were the hardest hit. The attacker went from a blank workspace to breaking into a real target in under four hours, and once the campaign launched, it compromised organizations in seconds.

The key insight: AI is an "attack compression" tool

Here is the part worth understanding, because it explains everything. The security researchers who analyzed this were clear: the AI's biggest impact was not a clever new hacking trick. It was removing the human effort. AI handled the boring, repetitive, time-consuming parts, researching, testing, fixing failures, and trying again across hundreds of systems at once. In plain terms, AI compresses the time, skill, and cost an attack requires. A task that needed a skilled team now needs one person directing software. That is why the same old attacks are suddenly more dangerous: they can happen to far more businesses, far faster, and much more cheaply than before.

What it means for a small business

The uncomfortable takeaway is that "we're too small to be worth attacking" no longer holds. When attacks are automated and cheap, attackers don't hand-pick targets, they let software sweep the entire internet and hit whatever is vulnerable. Being small is no longer camouflage; being unpatched is what gets you caught. The organizations hit in this campaign weren't targeted because they were valuable. They were hit because they were reachable and exposed.

But here is the reassuring flip side, and it's the most important point in this article. The attack succeeded by exploiting known weaknesses in systems that were exposed to the internet and, in many cases, not up to date. The defenses against it are not exotic or expensive. They are the same fundamentals security people have recommended for years, and they still work. AI has raised the cost of ignoring them, not the cost of doing them.

The basics that still protect you

You don't need an enterprise security team to be meaningfully safer. Focus on a short list of fundamentals, done consistently.

1

Update your software quickly

This attack exploited known flaws. Software updates and security patches exist to close exactly these holes. The single most important change is treating updates as urgent, not optional, especially for anything reachable from the internet. The old habit of delaying updates for weeks is now the biggest risk.

2

Reduce what's exposed to the internet

Every system directly reachable from the internet is a potential door. Ask a simple question of each one: does this actually need to be open to the world? Anything that can be put behind a login, a VPN, or taken offline when not needed is one less thing for automated attacks to find.

3

Turn on multi-factor login everywhere

Multi-factor authentication, where logging in needs a second step like a code on your phone, stops a huge share of attacks even when a password is stolen. It's free or cheap, and it's one of the highest-value protections a small business can turn on today.

4

Keep working backups

If the worst happens, reliable backups are what let you recover without paying a ransom or losing everything. Keep them separate from your main systems, and test occasionally that you can actually restore from them. A backup you've never tested is a hope, not a plan.

Why this is a reason to act, not to panic

It's easy to read a story like this and feel that AI has made defense hopeless. It hasn't. The same technology that speeds up attacks also speeds up defense, security tools increasingly use AI to detect and respond faster too. And crucially, this campaign did not rely on some unstoppable new weapon. It relied on organizations being slow to patch and leaving systems exposed. Those are fixable. The honest conclusion is that AI has raised the stakes on doing the basics well, and lowered the safety margin for neglecting them. A business that patches promptly, limits its exposure, uses multi-factor login, and keeps backups is in a genuinely strong position, no matter how fast attackers move.

Your action this week

Pick the one that applies most to you and do it now. Check that your important software, especially anything accessible from the internet, is fully up to date, and set updates to happen promptly from now on. Turn on multi-factor login for your email, key accounts, and admin tools if you haven't. Confirm you have a recent backup of your important data and that it's stored separately. None of these require deep technical skill, and together they close the exact kind of gap this AI-driven attack relied on. The threat got faster; your fundamentals still hold, as long as you actually do them.

Frequently asked questions

Did AI create a brand-new type of cyberattack?

No, and that's the key point. The attack used known techniques against known software flaws. What AI changed was speed, scale, and cost: it automated the tedious human work of researching, testing, and running the attack across hundreds of targets at once. Security researchers describe this as "attack compression", the same attacks, made far faster and cheaper.

Is my small business really at risk from something like this?

Potentially, yes, and being small no longer protects you. Because these attacks are automated, they don't hand-pick valuable targets; they sweep the internet and hit whatever is exposed and unpatched. The organizations compromised in this campaign were caught because they were reachable and out of date, not because they were chosen. The fix is doing the security basics.

What is the single most important thing I can do?

Update your software quickly, especially anything reachable from the internet. This attack, and most like it, exploit known flaws that already have fixes available. Treating updates as urgent rather than optional closes the exact gap these campaigns rely on. After that, turn on multi-factor login and keep tested backups.

Do I need to buy expensive security software to be safe?

Not to cover the fundamentals. The most effective protections here, prompt updates, reducing internet exposure, multi-factor login, and backups, are free or low-cost and available to any business. Advanced security tools help, but they don't replace the basics, and neglecting the basics is what these attacks exploit.

Does AI help defenders too, or only attackers?

Both. The same speed and automation that help attackers are increasingly built into defensive tools, which use AI to spot and respond to threats faster. The concerning part of this story is the automation of attacks; the reassuring part is that it succeeded by exploiting basic neglect, patching and exposure, which businesses can control.

Stay ahead of AI, calmly and clearly

AI is changing fast, in both useful and risky ways, and not every headline deserves panic. AISetApp cuts through the noise with clear, honest guides on what's real, what matters, and what to actually do about it.

Explore more on AISetApp
Sources and further reading
  1. GreyNoise threat-intelligence analysis of the AI-orchestrated PaperCut NG/MF campaign, September 2026
  2. Help Net Security, The Hacker News, and Dark Reading reporting on the campaign's scale, speed, and method, September 2026
  3. Blackpoint Cyber analysis on AI as "attack compression", reducing the human effort of exploitation, September 2026
  4. UK National Cyber Security Centre assessment on AI increasing the frequency and effectiveness of cyber threats through 2027

Reviewed September 2026. This is general guidance, not specific security advice. For your organization's specific risks, consult a qualified security professional.

Researched and drafted with AI assistance, reviewed and edited by Yasser El Hardouz, who takes editorial responsibility for this article.