Something happened this month that every small business owner should understand, even the non-technical ones. Security researchers watched a single attacker turn a swarm of AI agents loose and compromise 440 servers across 395 organizations in 48 countries, hitting eleven organizations in twenty-six seconds at peak. Not a big team, not a nation-state operation, one operator, orchestrating AI to do the work of many. It is a preview of where cyberattacks are heading, and it quietly demolishes the comforting myth that small businesses are too small to bother with.
What actually happened
According to the researchers who tracked it, the attacker started essentially from scratch and used AI coding tools (an OpenAI model as the execution engine, paired with another AI and orchestration software) to analyze a vulnerability, build attack tools, and hunt for victims automatically. They chained two flaws in PaperCut, a widely used print-management product, and achieved their first break-in less than four hours after starting. The agents then scanned the internet and struck at machine speed. More than half the victims were schools and universities, but the method is what matters, not the targets.
Why this changes the calculus for small businesses
The old reassurance was a numbers game: there are millions of small businesses, attackers are limited, so the odds of being singled out are low. AI breaks that logic. When one person can direct AI agents to find and exploit thousands of targets automatically, there is no longer a meaningful cost to going after small, obscure organizations too. Attacks become opportunistic and universal, if you are exploitable, you get hit, not because anyone chose you, but because automation does not need to choose. "Too small to target" is no longer true.
What to actually do about it
- Patch fast. These campaigns weaponize known flaws at machine speed, so the window between a fix being available and attacks arriving is shrinking. Prompt patching is now front-line defence.
- Cover the basics that stop opportunistic attacks: MFA everywhere, no exposed services you do not need, and least-privilege access, since automated attacks feed on easy, common weaknesses.
- Assume you are in scope. Drop "we are too small" from your thinking and give security the same seriousness a bigger target would.
- Be ready to respond, because at machine speed, detection and a fast response matter more than ever.
The bigger picture
This is the same story as AI everywhere, a force multiplier, now pointed at attacking. It does not require new fear so much as retiring an old assumption. The defences have not changed (patch, MFA, least privilege, backups, a response plan); what has changed is that skipping them is no longer a bet you are likely to win because you are small. If anything, this is the clearest argument yet that solid basics are not optional for a small business. We help you put exactly those basics in place.