Why Phishing Still Works Even When Employees Know About It
Aug 07, 2026 / 41 min read
August 7, 2026 / 21 min read / by Team VE
Small and mid-sized businesses are being regularly attacked because many of the same tools, data and digital dependencies now exist in these companies, while the security controls around them are often thinner, less monitored and easier to exploit.
Small and mid-sized businesses have become attractive cyber targets because attackers no longer need to spend much time or money choosing victims. Automated scanning, stolen credentials, phishing kits and ransomware-as-a-service allow criminals to test thousands of companies for the same weaknesses, which means a 40-person business can be exposed to the same attack infrastructure as a multinational.
The problem is usually not one spectacular security failure. It is an accumulation of ordinary weaknesses: reused passwords, weak MFA, unpatched software, broad admin access, unmanaged devices, poor backups, informal payment processes and nobody actively monitoring suspicious behaviour. Small businesses often have enough valuable data and operational dependency to make an attack profitable, but not enough redundancy to absorb a long outage comfortably.
In 2019, Arkansas-based fundraising company The Heritage Company was hit by ransomware and eventually suspended operations while trying to recover, leaving roughly 300 employees without work. The company had even paid the ransom, but restoring its systems proved difficult enough that the incident became an example of how a cyberattack can become an operational crisis for a relatively small business.
The attackers did not need Heritage to be a household name or possess some extraordinary corporate secret. The company’s ability to operate depended on its systems, and disrupting those systems created value for the attacker.
That is increasingly how small-business cyber risk works. Criminals do not necessarily sit down and decide that a particular 80-person accounting firm or regional manufacturer deserves weeks of bespoke attention. Automated scanning can identify exposed services, stolen credentials can be tested across large numbers of accounts, phishing campaigns can reach thousands of employees, and ransomware operations can reuse the same infrastructure against many different businesses.
The 2025 Verizon Data Breach Investigations Report found that 96% of breaches affecting smaller organisations were concentrated in system intrusion, social engineering and basic web application attacks, which tells us something important about the economics of these attacks: criminals often do not need an exotic route when familiar weaknesses continue to work.
At the same time, the difference between a small company’s technology environment and a large company’s has narrowed much faster than the difference in security resources. A growing professional-services firm may depend on Microsoft 365, payroll software, cloud storage, a CRM, online banking and dozens of SaaS applications, while a manufacturer may rely on ERP systems, remote access and production software that cannot simply be switched off for several days.
The business may therefore have plenty worth stealing or disrupting, but only one internal IT person, an outsourced support provider, limited security monitoring and little redundancy if something critical fails.
The FBI’s disruption of the Dispossessor ransomware group showed exactly this pattern, with attackers targeting small and mid-sized organisations through weak passwords, vulnerable systems and missing multi-factor authentication.
This is why saying that small businesses are attacked because they have “weak cybersecurity” does not quite capture the problem. They are increasingly attractive because they combine meaningful digital dependency with thinner margins for security failure.
An attacker can automate much of the work required to find a weakness, while the company still has to protect every employee account, device, application, backup and supplier connection individually. The real question, then, is not why criminals would bother attacking a smaller company. It is why they would ignore one when the cost of testing whether it is vulnerable has become so low.
The technology stack inside a small business can now look surprisingly similar to the one inside a much larger company. Microsoft 365 or Google Workspace handles communication, customer data sits in a CRM, payroll runs through a cloud platform, accounting depends on SaaS, files live in shared drives, and staff may use remote-access tools, mobile devices and third-party apps every day.
The difference is that these systems are often managed by a very small internal team, an external IT provider, or sometimes nobody with dedicated security ownership at all.
That creates a familiar pattern: security controls exist, but they are uneven. MFA may be enabled for some users but not all. Old accounts remain active because offboarding is informal. Employees accumulate admin rights over time. Backups exist, but nobody has tested whether they can actually be restored under pressure.
Software updates are delayed because downtime is inconvenient. The UK National Cyber Security Centre’s guidance for small businesses focuses heavily on exactly these basics, including backups, malware protection, device security, passwords and phishing, because these are the controls most likely to break down when IT is stretched.
The problem is not that smaller companies are careless. It is that operational pressure usually wins. A 50-person firm cannot always afford a security engineer, an identity specialist and a 24/7 monitoring team, so one person may be handling laptops, email, user support, vendor access and security at the same time. That is manageable until something goes wrong, because the same lean setup that keeps costs under control can also leave gaps in visibility and response.
| Common small-business reality | Why it creates risk |
| One person manages most IT tasks | Security issues can compete with day-to-day support |
| MFA is only partly deployed | Stolen credentials remain useful |
| Shared or excessive admin access | One compromised account can do far more damage |
| Backups are assumed to work | Recovery may fail when it is needed most |
| Former staff retain access | Old identities become unnecessary attack paths |
| Security monitoring is limited | Suspicious activity can persist unnoticed |
This is also why basic controls matter so much more than complicated security products. A company that enforces MFA properly, removes stale accounts, patches exposed systems, limits admin rights and tests backups may be materially safer than one that has bought several security tools but still manages access informally.
For smaller organisations, the gap between “we have security” and “our security actually works under pressure” is often where the real risk sits.
Most cyberattacks against small businesses do not begin with an exotic zero-day or a highly specialised intrusion team. They begin with something familiar that has been left slightly too exposed: a reused password, an unpatched internet-facing system, a convincing phishing message, an old remote-access account or a third-party service that already has access to the environment.
Verizon’s 2025 breach research found compromised credentials were the initial access vector in 22% of breaches, while exploitation of vulnerabilities accounted for another 20%, which helps explain why attackers keep returning to basic access routes that are cheap to test at scale.
For smaller companies, the issue is often not that any one control is completely absent, but that coverage is inconsistent. MFA protects Microsoft 365 but not the remote desktop gateway. Most laptops are patched, but an old firewall or VPN appliance has been forgotten.
Former employees are removed from payroll but not from every SaaS application. Verizon’s credential-stuffing analysis found that even among small organisations, around 12% of authentication attempts in the data it studied were credential-stuffing attacks. Attackers can afford to keep testing because automation makes failed attempts almost free.
The entry routes tend to repeat:
| Common entry route | Why smaller businesses are exposed | What the attacker is trying to gain |
| Stolen or reused credentials | MFA may be missing or unevenly deployed | Email, SaaS or remote-access control |
| Phishing and business email compromise | Employees handle payments, invoices and customer requests directly | Credentials, money or trusted access |
| Unpatched internet-facing software | Smaller IT teams may struggle to patch every system quickly | Initial foothold into the environment |
| Remote-access tools | Older VPN, RDP or support tools may remain broadly exposed | Direct network access |
| Third-party services | MSPs, vendors and SaaS tools often hold privileged access | A route into multiple systems or customers |
The third-party route is becoming especially important because smaller companies rely heavily on external providers for IT, payroll, accounting, hosting and specialist software.
Verizon’s 2025 DBIR found third-party involvement in breaches had doubled to 30%, which means a business can improve its own security and still inherit risk through someone it trusts. (Verizon) The problem becomes more serious when external accounts have broad privileges, shared credentials or access that remains active long after the original work is finished.
This is why the first stage of small-business defence is less about predicting sophisticated attackers and more about closing ordinary doors consistently. CISA recommends MFA across email, file storage and remote access, starting with administrative accounts and users handling sensitive data, alongside patching, backups and stronger account hygiene.
(CISA) These controls sound basic precisely because the attack routes are often basic. What makes them dangerous is that an attacker only needs one of them to be neglected once.
A large company can absorb a surprising amount of disruption because it usually has redundancy. There may be a secondary environment, a larger IT team, incident-response retainers, cyber insurance, alternative suppliers and enough cash flow to keep operating while systems are restored.
Smaller businesses often have much less room to absorb the same event. If the accounting platform, customer database or file server goes down, there may not be a parallel system or spare team waiting to take over.
Ransomware makes this especially painful because the financial damage is rarely limited to the ransom itself. Downtime can stop invoicing, customer support, production, bookings or payroll, while recovery costs accumulate through external IT support, forensic investigation, legal advice and replacement hardware or software.
The U.S. Federal Trade Commission warns small businesses that ransomware can block access to critical files and systems and cause substantial operational disruption, which is often the part that turns a technical incident into a cash-flow problem.
The asymmetry becomes clearer when you look at the business consequences rather than the attack itself:
| Impact | Why it can be harder for a small business |
| System downtime | Fewer backup systems and less operational redundancy |
| Lost revenue | A few days of disruption can materially affect monthly cash flow |
| Recovery costs | External specialists can be expensive relative to company size |
| Customer loss | A small number of major clients may represent a large share of revenue |
| Legal and regulatory work | The same obligations can apply even without a large internal legal team |
| Reputation damage | Smaller firms may rely more heavily on trust and referrals |
| Staff pressure | The same employees often have to manage both recovery and normal operations |
This is why backup quality matters more than simply having backups. A company may discover during an incident that backups are incomplete, connected to the same environment that was encrypted, or too slow to restore at the speed the business needs. CISA’s ransomware guidance recommends maintaining offline or otherwise isolated backups and testing restoration procedures regularly, because an untested backup is only a theory about recovery.
For smaller companies, resilience is therefore part of cybersecurity in a very practical sense. The question is not only whether an attack can be prevented, but whether the business can continue operating if prevention fails.
A company with clean backups, an incident-response contact, clear customer communication procedures and a way to keep critical functions running manually for a short period may recover from the same attack that leaves another business effectively frozen.
The good news is that smaller businesses do not need an enterprise security stack to reduce a large amount of risk. The priority should be to close the attack paths criminals use repeatedly and make recovery less fragile if something still gets through.
CISA’s small-business guidance focuses first on phishing resistance, strong passwords, MFA and software updates, then adds logging, backups and encryption as the next layer. That order is sensible because it addresses the weaknesses most likely to turn a routine attack into a serious incident.
| Priority | What to do first | Why it matters |
| Email and accounts | Enforce MFA and remove stale accounts | Stolen credentials become much less useful |
| Patching | Prioritise internet-facing systems, browsers, operating systems and remote-access tools | Closes known vulnerabilities attackers can scan for automatically |
| Admin access | Remove unnecessary local and cloud admin rights | Limits what one compromised account can change |
| Backups | Keep protected copies and test that they can actually be restored | Turns ransomware from a potential business shutdown into a recovery problem |
| Finance workflows | Independently verify bank-detail and unusual payment changes | Reduces business email compromise and invoice fraud |
| Third-party access | Review vendors, MSPs and contractors regularly | Prevents forgotten external accounts becoming permanent entry points |
| Incident response | Decide who to call, what to isolate and how customers will be informed | Saves time when the company is already under pressure |
Backups deserve particular attention because “we back everything up” is often only discovered to be false during recovery. The NCSC’s current guidance for small organisations specifically recommends checking that backups contain the information the business needs and that the company knows how to restore them.
For a smaller organisation, a successful restore test can be more valuable than another security dashboard because it answers the question that matters once prevention has failed: how quickly can the business work again?
Ownership matters just as much as technology. Security gaps tend to survive when everyone assumes someone else is handling them, particularly where an external IT company manages day-to-day systems.
The business should know who owns account reviews, patching, backup testing, incident response and vendor access rather than treating “IT” as one undifferentiated responsibility. The NCSC’s incident-preparation guidance recommends identifying critical systems in advance and sharing responsibility so the response does not depend on one person being available.
The broader point is that small-business cybersecurity becomes much more manageable once the company stops trying to defend everything equally. Protect the accounts that can move money or administer systems, patch what is exposed to the internet, make sure recovery actually works, and remove access that no longer has a business purpose. Those controls are not glamorous, but they directly attack the economics that make smaller businesses attractive in the first place.
The uncomfortable truth is that many small-business attacks are not especially personal. Criminals do not need to know the owner, understand the company in depth or spend weeks studying its systems if they can automate large parts of the attack.
Stolen credentials can be tested across thousands of services, internet-facing systems can be scanned continuously, and phishing campaigns can be sent at scale with very little additional cost for each target. That changes the equation because even a modest payout becomes worthwhile when the cost of finding and testing victims is low.
Ransomware made that model even more attractive because the attacker does not need to steal uniquely valuable information. They can monetise the victim’s dependency on its own systems.
A small manufacturer may pay because production has stopped, a professional-services firm may pay because client files are inaccessible, and a healthcare provider may face pressure because scheduling or records systems are unavailable. The value is created by interruption, not just by the data itself.
This is also why the idea that “we are too small to be targeted” is misleading. A company may be too small to justify a highly bespoke intrusion, but it is not too small to appear in a credential list, expose an unpatched service, receive a phishing campaign or be reached through a vulnerable supplier.
Attackers increasingly operate on a portfolio model: test many organisations, exploit the ones that respond, and spend more effort only after access has already been achieved.
For smaller companies, the practical lesson is not to become paranoid about being individually selected. It is to recognise that cyber risk is increasingly driven by exposure rather than profile. If a weakness can be found cheaply and exploited repeatedly, company size does not provide much protection.
The businesses that reduce their risk most effectively are the ones that make those common attack paths harder to use and make recovery much less profitable for the attacker.
Small businesses are unlikely to outspend larger companies on cybersecurity, and they do not need to. Their advantage comes from reducing the number of easy wins available to an attacker. Strong MFA, disciplined access control, regular patching, tested backups and tighter payment processes can remove a large amount of practical risk without turning security into a major enterprise programme.
The second advantage is recovery speed. A company that knows which systems are critical, who owns the response, how backups will be restored and how customers will be informed is in a very different position from one trying to work those things out during an incident. For a smaller business, that preparation can matter as much as prevention because downtime and uncertainty can become financially damaging very quickly.
The important shift is to stop thinking about cyber risk in terms of whether a company is “important enough” to attract attention. Most attackers do not need the business to be important. They need the business to be reachable, exploitable and dependent enough on its systems for the attack to create leverage.
Small businesses keep getting hit because the economics still favour the attacker. The way to change that is not to become impossible to breach, but to become expensive to exploit, difficult to move through, and quick to recover.
Hackers target small businesses because the economics often make sense. Many attacks are automated, which means criminals can scan exposed systems, test stolen credentials and send phishing campaigns across thousands of companies without spending much additional effort on each one. A business does not need to be famous or especially valuable if it is easy to reach and has something that can be monetised, whether that is data, account access, money movement or operational disruption.
Small businesses can also present a useful combination of dependency and weaker security depth. They may rely heavily on email, cloud apps, payroll systems, CRMs and online banking, but have limited monitoring, fewer security specialists and less redundancy if something fails. That can make even a relatively ordinary attack disproportionately disruptive.
Yes. Ransomware does not depend on the victim being large. It depends on the victim needing access to its systems badly enough that disruption creates pressure. A small manufacturer that cannot run production, a professional-services firm that cannot reach client files or a medical practice that loses access to scheduling can all face serious operational consequences.
The attacker does not necessarily need to steal highly sensitive data to create leverage. Encrypting systems, threatening to leak information or simply keeping the business offline can be enough. This is why tested backups and a clear recovery plan matter just as much as preventive controls.
There is no single route, but the same entry points appear repeatedly: stolen credentials, phishing, vulnerable internet-facing software, weak remote-access controls and third-party access. These methods remain popular because they are relatively cheap for attackers to test at scale.
The pattern is often less dramatic than people expect. A reused password works somewhere it should not, an employee approves a convincing login request, a VPN appliance has not been patched, or an old contractor account is still active. The attack becomes serious because the initial weakness opens access to something more valuable.
MFA is one of the highest-value controls a small business can deploy, especially for email, administrative accounts, finance systems and remote access. It can prevent a stolen password from immediately becoming a successful login, which removes one of the easiest attack paths criminals use.
But MFA is not enough on its own. If old accounts remain active, admin rights are excessive, software is unpatched or employees can approve sensitive payment changes without verification, attackers still have other ways to cause damage. MFA should be part of a broader set of basic controls rather than treated as a complete security strategy.
Not necessarily. Many of the biggest improvements come from getting the fundamentals right before adding more products. Strong MFA, regular patching, clean user access, tested backups, endpoint protection and safer payment workflows can reduce a large amount of risk without requiring an enterprise-level security stack.
The more important question is whether the controls already in place are being managed properly. A company with several security tools but no clear ownership for patching, access reviews or incident response may still be more exposed than a smaller company with fewer tools and much stronger discipline.
Backups should be tested regularly enough that the business knows they can actually be restored when needed. The exact schedule will depend on how quickly data changes and how much downtime the company can tolerate, but simply seeing that a backup job completed successfully is not the same as proving that recovery works.
A proper restore test should answer practical questions: is the required data present, how long does recovery take, who performs it and can critical systems be brought back without depending on the same environment that was compromised? These questions matter far more during an incident than the fact that backups technically existed.
The first priority is containment. That may involve isolating affected systems, disabling compromised accounts, revoking active sessions and stopping further access while preserving enough evidence to understand what happened. The business should also contact its IT or incident-response provider quickly rather than attempting random fixes that could make investigation harder.
The next steps depend on the incident. The company may need to restore systems, notify customers, involve insurers, seek legal advice or report the matter to authorities. Having those contacts and responsibilities defined before the incident can save valuable time when the business is already under pressure.
Employee training matters because phishing, payment fraud and credential theft often depend on someone making a decision under pressure. Staff should know how to recognise unusual requests, verify sensitive changes and report mistakes quickly without worrying that they will be blamed for raising an alarm.
Training should not carry the whole security burden, though. A well-trained employee can still be deceived by a convincing attack. The stronger approach combines awareness with controls such as MFA, restricted privileges, payment verification and safer account-recovery processes so that one human mistake does not automatically become a serious incident.
Outsourcing can make sense when the company does not have enough internal expertise to manage security consistently, especially for monitoring, patching, endpoint protection and incident response. A good provider can bring skills and coverage that would be difficult for a small company to maintain internally.
The business still needs ownership, however. Outsourcing IT or security does not outsource accountability. Management should understand what the provider is responsible for, how incidents are handled, which systems are monitored and what happens if the provider itself is compromised.
Start with the controls that reduce the most common attack paths: strong MFA, patching of exposed systems, restricted admin access, endpoint protection, clean offboarding, tested backups and independent verification for payment changes. These controls are relatively straightforward and directly address the weaknesses attackers use most often.
After that, the company can improve logging, vendor access, incident-response planning and more advanced monitoring as the environment becomes more complex. The aim is not to build a perfect security programme overnight, but to remove the easiest paths into the business and make recovery much more reliable if an attack still succeeds.
Aug 07, 2026 / 41 min read
Aug 07, 2026 / 27 min read
Aug 07, 2026 / 33 min read