Small businesses are not too small to be targets. In fact, they're often the preferred target — they hold real data and real money, but typically have far fewer security resources than large enterprises. Attackers know this and exploit it systematically.
43% of cyberattacks target small businesses — and 60% of small businesses that suffer a major cyberattack close within six months. The attacks are not random. They follow predictable patterns. Source: Verizon Data Breach Investigations Report
The five attack methods below account for the vast majority of successful breaches against small businesses. None require exotic technical expertise to defend against — but all of them require you to actually take action. Here's what you're up against, and what to do about it.
Phishing and social engineering
Phishing is the most common initial entry point for small business attacks — responsible for over 80% of reported security incidents. An attacker sends an email that looks exactly like it came from your bank, your domain registrar, your email host, or a trusted vendor. The email links to a convincing fake login page. Your employee enters their credentials. The attacker now has access.
Why small businesses are especially vulnerable: Large enterprises run phishing simulation programs, have dedicated security training, and use enterprise email filtering. Small businesses typically rely on default spam filters and hope for the best. Employees handle a wide range of tasks and are used to receiving requests from unfamiliar addresses. A request to "verify your account" or "approve an invoice" doesn't raise flags the way it should.
What to check:
- Do you have multi-factor authentication (MFA) enabled on all critical accounts — email admin, banking, domain registrar?
- Does your domain have DMARC configured? (Without it, attackers can send email that appears to come from your domain)
- Has your team received any phishing awareness training in the past 12 months?
- Do you use DKIM and SPF records to authenticate outgoing email?
Credential stuffing from data breaches
There are billions of username/password pairs available for sale on the dark web, harvested from data breaches at companies like LinkedIn, Adobe, Yahoo, and thousands of others. Attackers use automated tools to try these credentials against your website's login page, your admin panel, your email, and your hosting account. This is called credential stuffing — and it works because people reuse passwords.
The math is brutal: If your employee used the same password for their old LinkedIn account (breached in 2016) and your company's CMS admin panel, attackers already have the key. They just need to try it. Automated tools can attempt thousands of combinations per minute against a standard login form.
What to check:
- Are any of your team's email addresses in known data breaches? (Check at
haveibeenpwned.com) - Do your critical accounts enforce unique passwords — or are passwords reused across services?
- Is MFA enabled on your website admin, hosting panel, and email admin accounts?
- Does your website's admin login page have rate limiting or lockout after failed attempts?
Not sure how exposed your domain is?
Aegisly scans your SSL, DNS records, and HTTP headers in under 30 seconds.Get our free Small Business Security Checklist
10 steps to protect your business — sent to your inbox in 30 seconds
Unpatched software and vulnerable plugins
When a vulnerability is discovered in WordPress core, a popular plugin, or a web framework, the vendor releases a patch. When patch notes are published, attackers immediately read them — the patch notes tell them exactly what vulnerability exists and where. Automated scanners then probe every site on the internet for the unpatched version. The window between patch release and active exploitation is often 48–72 hours.
The plugin problem: The average WordPress site runs 15–25 plugins. Each plugin is a separate software project with its own update cadence, its own security team, and its own vulnerability history. Plugins go unmaintained and abandoned — the developer moves on, but the plugin stays installed, frozen at a version with known vulnerabilities, used by thousands of sites that never get a patch notification.
What to check:
- When did you last update your CMS (WordPress, Squarespace, Wix, or custom platform)?
- Are all your plugins and themes on current versions — or are some years behind?
- Do you have any plugins installed that are no longer actively maintained?
- Is your TLS/SSL configuration up to date? (TLS 1.0 and 1.1 are deprecated and exploitable)
Misconfigured cloud storage and public databases
Cloud storage services like AWS S3, Google Cloud Storage, and Azure Blob Storage are set to private by default — but it's remarkably easy to accidentally flip a single setting that makes a bucket publicly readable. The same applies to databases: MongoDB, Elasticsearch, and Redis instances left accessible without authentication have exposed millions of records. Automated scanners trawl the internet continuously looking for these open doors.
What gets exposed: Customer lists, invoices, employee records, contracts, backups of your entire database — whatever happens to be stored in that bucket or database. Once discovered, the data is downloaded, ransomed, or sold. You often won't know it happened until you receive a ransom demand or a customer reports suspicious activity.
What to check:
- Are any of your AWS S3 buckets, GCS buckets, or Azure containers set to "Public"?
- Are your databases (MySQL, PostgreSQL, MongoDB) accessible from the public internet — or restricted to your application servers only?
- Do you have any cloud storage URLs that you've shared publicly — for example, direct links to customer invoices or documents?
- Is your backup storage encrypted and access-controlled?
Ransomware via exposed RDP and VPN credentials
Remote Desktop Protocol (RDP) is how most Windows systems are managed remotely. Many small businesses leave RDP exposed directly to the internet on port 3389 — and attackers know this. Brute-force tools attempt thousands of username/password combinations against publicly exposed RDP ports. When they succeed, the attacker has full interactive control of your server. The most common next step is ransomware deployment — encrypting all your files and demanding payment to recover them.
VPN vulnerabilities are a related attack surface: Older VPN appliances (Cisco, Citrix, Pulse Secure, Fortinet) have had serious authentication bypass vulnerabilities in recent years. When these vulnerabilities are public and patches are available but not applied, attackers exploit them at scale. A compromised VPN gives an attacker network-level access to everything behind your firewall.
What to check:
- Is RDP (port 3389) exposed directly to the internet — or is it behind a VPN or IP whitelist?
- Are your VPN appliances on current firmware versions with all security patches applied?
- Do you have off-site backups that are isolated from your main network? (Ransomware typically targets everything it can reach — including mapped network drives and cloud sync folders)
- Is MFA required for remote access logins?
What these five attacks have in common
None of these are zero-day exploits or nation-state techniques. Every one of them is preventable with basic security hygiene that costs more in time than money. What they share:
- They target the path of least resistance. Attackers don't break down the reinforced door — they try the unlocked window. Your patched systems, MFA-protected accounts, and correctly configured DNS records are not interesting to them. Your unpatched plugin or reused password is.
- They're automated. Attackers don't manually test each business. Automated scanners probe millions of targets continuously. If your site has a known vulnerability, it will be found.
- They work because of inaction. Most of the businesses that get hit knew they had these gaps. They just hadn't gotten around to fixing them. "We'll deal with it later" is a security strategy that reliably fails.
The single most effective thing you can do right now: run an external security scan on your domain and fix whatever it finds. SSL configuration, DNS email security records, and HTTP security headers can all be checked without any access to your systems — and they're the first things attackers probe.
Read more: 5 Security Gaps Most Small Businesses Don't Know They Have and How to Check If Your Website Has Been Hacked.
Run your free security scan now
Aegisly checks your SSL, DNS security records, and HTTP headers automatically. Get an A–F security grade and plain-English fixes in under 30 seconds — no account required.
Run your free security scan →No credit card. No signup. Results in 30 seconds.