Why attackers target small businesses too
Nobody would hack us, the most common security assumption, is also the most wrong. Attacks are automated, indiscriminate and profitable at small scale.
The short answer
“Nobody would bother hacking us” is the most common security assumption among small businesses and the most wrong. Almost no attack on a small business website involves a person choosing that business. Scripts scan the entire internet, continuously, for known weaknesses: an outdated plugin, a default login, an exposed configuration file. They find yours because they find everything. What happens next is a business too: access to compromised sites is sold in bulk and used for spam, phishing, search manipulation, mining and fraud against your customers. You were not chosen. You were found, and you were easier than the site next door.
What a compromised small site is used for
| Use | How it pays |
|---|---|
| Spam and phishing sending | Your domain and server reputation lend credibility until they are burned |
| Hosting phishing pages | A bank login page on a real, aged domain with a valid certificate |
| Search engine manipulation | Thousands of hidden pages and links, sold to whoever wants rankings |
| Crypto mining | Your server’s computing power, your bill |
| Data harvesting | Names, emails and messages from your forms; card details if you process them |
| Stepping stone | Access to your email, then invoice fraud against your customers and suppliers |
| Ransom | Your site and data encrypted or threatened with publication |
| Botnet membership | Your server attacking others |
Why small businesses are softer
- Older software. Updates are nobody’s job, so known vulnerabilities stay open for months or years.
- Shared and reused passwords, often without two-factor, on hosting, domain and admin accounts.
- No monitoring. A compromise is discovered by a customer, a blocklist or a search engine warning, often months in.
- No incident plan. The first hour is spent finding out who has the passwords.
- Accumulated plugins and scripts installed by several people over years, half of them abandoned.
- Trust in the wrong signals. A padlock and a working site are taken as proof of safety.
What actually protects a small business
Not obscurity, not size, not a security plugin. The basics, done consistently: updates within days, unique passwords with two-factor everywhere, a small attack surface, a network layer that drops known bad traffic, backups that are tested, monitoring that alerts a person, and someone whose job it is to keep all of that true. On a static site with no public admin and few dependencies, most of the list shrinks to almost nothing. That is a large part of why we build that way.
What this means for you
You are a target because everyone is, and you are an easy one only if the basics are not done. Stop relying on being small or uninteresting. Assign the basics to someone, shrink the attack surface where you can, monitor, and have a plan for the first hour. The scripts will keep knocking; the point is that the door holds and someone hears the knock.
Frequently asked questions
We are tiny. Who would spend time attacking us?
Nobody spends time. A script scans millions of sites for a known vulnerability, finds yours, exploits it and moves on, all without a human involved. Time is spent later, by the people who buy access to compromised sites in bulk and use them for whatever pays. You were not chosen; you were found.
What do they actually do with a small business website?
Send spam and phishing from it, host fake bank pages on it, inject links to manipulate search rankings, mine cryptocurrency on the server, harvest customer data from forms, and use it as a trusted-looking base to defraud your customers and suppliers with invoice changes. Each pays a little; at scale it pays a lot.
Is a small site harder to protect than a large one?
Usually easier. Fewer systems, fewer people, fewer integrations. The difference is attention: large organisations have someone whose job it is; small businesses have nobody, and the basics slide. Assign the basics to a partner or a person and most of the gap closes.