Kaspersky says dark web targets SMBs

  • DCV Desk
  • 12 Jul 2026, 03:49 PM
Kaspersky says dark web targets SMBs Photo: Courtesy
ad
Ahead of International SMB Day on June 27, Kaspersky warns that small and medium-sized businesses remain prime cybercrime targets. In the first four months of 2026, 40% of dark web posts offering initial access involved small businesses, while 20% targeted medium-sized firms—together accounting for over half of all such listings. Initial access brokers sell compromised network access, enabling cybercriminals to launch ransomware attacks, steal sensitive data, or conduct other fraudulent activities against businesses, a press release said.
“Despite the fact that posts concerning small-sized companies prevail, threat actors may target medium sized businesses as they generate higher revenue than small businesses while they may have lower level of protection against cyberthreats than large ones. Thus, the common belief that small  and medium sized enterprises are uninteresting to attackers is a misconception. Companies of any size need to understand the cyberthreat landscape, adhere to cybersecurity policies, use appropriate cybersecurity solutions, and continuously improve employees’ awareness”, says Ekaterina Beloborodova, Kaspersky Digital Footprint Intelligence Analyst. 
Read the full report on the SMBs threat landscape here:  To strengthen cybersecurity, businesses should adopt solutions that match their size, budget, and operational needs while remaining scalable as they grow. Organizations with limited IT resources can benefit from managed detection and response services that provide continuous monitoring and expert support. Monitoring the surface, deep, and dark web for leaked credentials, exposed data, and fraudulent websites also helps identify risks early. Companies should establish clear policies for using external AI tools and online services, define strict access controls for corporate accounts and shared resources, and regularly back up critical data to minimize disruption and ensure business continuity during cyber incidents.


Comment