Skip to content
MarketsIndicesCommoditiesFXRates
Top News

Russian small businesses targeted in growing cyberattacks

Eighty-two percent of Russian small businesses faced cyberattacks over two years as hackers targeted firms lacking dedicated security teams.

Russian small businesses targeted in growing cyberattacks

Small and medium-sized enterprises in Russia are facing a surge in targeted cyberattacks as hackers shift away from attacking major corporations. Eighty-two percent of small and medium-sized companies encountered cyber incidents over the past two years, author Tatyana Dvortsova reported in an analysis featuring cover imagery from Unsplash.

Cyberattacks cost the Russian economy approximately 1.5 trillion rubles last year, while the overall number of incidents tripled compared to the previous year. Four out of five affected businesses operated without a dedicated IT specialist or information security department.

Small business owners frequently assume that low monthly revenues and modest client databases make them uninteresting to cybercriminals. However, cybersecurity specialists emphasize that hacker logic operates in the exact opposite direction.



Large corporations maintain firewalls, automated monitoring systems, trained security staff, and legal teams ready to respond instantly to security breaches. In contrast, a small sole proprietor with a monthly turnover of a couple of million rubles often relies on an unupdated antivirus program and a belief that cyber threats will not affect them.

Financial loss and contractor risks

Hacking a poorly protected small enterprise requires only a couple of hours, compared to the weeks of preparation needed to compromise a major corporate network. Savings on cybersecurity can result in financial losses that far exceed an enterprise's annual profit.

Data from cybersecurity firm Positive Technologies shows that Russia accounts for 14 to 16 percent of all successful cyberattacks worldwide. Industry experts expect the total number of attacks in Russia to grow by an additional 30 to 35 percent by the end of 2026.

Approximately one third of all cyberattacks last year occurred through contractors and software suppliers, which typically maintain weaker security protocols than their corporate clients. Cybercriminals gain control of a contractor and use its network access as a springboard to penetrate larger corporate partners.

A small company providing services to a coffee shop chain or acting as a contractor for a larger firm automatically becomes an attractive target, even if it stores no sensitive data of its own.



Targeted strikes and destructive malware

Cybercriminals have abandoned indiscriminate spam email campaigns in favor of targeted operations designed to disable corporate systems over long periods. Modern attacks increasingly focus on systemic destruction rather than simple financial extortion.

In many instances, hackers destroy infrastructure and backup copies without offering decryption keys or demanding ransom payments. Unlike traditional ransomware, wiper malware deletes data permanently rather than encrypting files, aiming solely to disrupt business operations.

Primary business entry points

Business owners routinely overlook three main technical entry points used by cybercriminals. The first critical vector involves online cash registers and card acquiring equipment.

An online cash register is an internet-connected device tied directly to a business settlement account. When cash register firmware remains unupdated for a year or two, known software vulnerabilities allow hackers easy access. Owners often treat cash registers as basic physical equipment that requires attention only during hardware failures, forgetting that operational equipment is not necessarily secure.

The second entry point involves customer relationship management systems and cloud spreadsheets containing client databases and order histories. Small businesses frequently distribute system login credentials across entire teams using a single shared username and password.

Accounting fraud and payment bots

Shared credentials are rarely changed, even when staff members leave the company. Allowing fifteen employees to share a single password for systems holding personal customer data and payment records makes a data leak inevitable over time.

Accounting departments face particularly severe risks from targeted cyber incidents. Central Bank of Russia figures show that the proportion of corporate account thefts rose to 11.3 percent during the second quarter of 2026.

Security experts report that fraudsters have shifted their primary focus from private individuals to corporate accounts, making accountants with payment access high-value targets. Opening a single malicious phishing file in an accounting department on a Friday evening can result in complete account depletion by Monday morning.

The third entry point involves instant messaging platforms and automated bots used to process customer payments. Service businesses have widely adopted messaging workflows where managers send payment links or banking details directly to customers.

Cybercriminals intercept manager communications or create duplicate social accounts, causing clients to transfer funds voluntarily to fraudulent accounts. Business owners usually discover the fraud only after receiving customer complaints regarding unpaid services.



Most cyber incidents originate from a basic human error when an employee clicks a phishing email link or message without verification. Standard antivirus software cannot protect a company when an employee manually allows unauthorized access.

Financial consequences and recovery costs

Extortion demands present catastrophic financial risks for commercial enterprises. Average ransom demands for medium and large businesses range between 4 million and 40 million rubles.

For a sole proprietor earning several million rubles per month, a demand of that scale causes immediate business failure. Paying a ransom provides no guarantee that data will be restored intact or that hackers will not sell stolen customer databases to third parties.

Downtime represents another severe cost that businesses rarely calculate prior to an incident. A store or service provider must suspend operations or process transactions manually while restoring access to cash registers or management software.

While a week of downtime causes inconvenience for a large firm, it can cost a small business more than a third of its monthly revenue, especially during peak seasonal demand. Furthermore, businesses face customer compensation claims and regulatory fines for personal data violations following data leaks.

Low cost defensive measures

Security specialists emphasize that small companies can eliminate most attack vectors through strict operational discipline without maintaining expensive security departments. Implementing basic protective steps requires minimal financial investment.

First, businesses must enable multi-factor authentication across all payment systems and customer databases. Setting up multi-factor authentication takes five minutes and prevents unauthorized logins even if password credentials leak.

Second, management must update cash register software and customer management systems promptly. Software updates close known vulnerabilities that hackers exploit prior to patch releases.

Third, companies must establish role-based access controls across all systems. Cashiers should not possess rights to alter system settings, and interns should not access complete customer databases containing phone numbers and residential addresses.

Fourth, organizations must create regular data backups and conduct practical recovery tests. Many companies discover that backup files are corrupted or outdated only when trying to restore systems during an active emergency.

Fifth, management should conduct basic staff training on identifying phishing threats. Training should focus on simple rules, such as avoiding suspicious email links, verifying sender addresses, and refusing to share passwords over the phone, even when callers claim to represent bank security services.



Emergency response protocols

Cybersecurity experts state that relying solely on an antivirus program and a system administrator is insufficient. Complete protection requires role-based access, regular software updates, verified backups, multi-factor authentication, and continuous event monitoring.

If a security breach occurs, business owners should take immediate action without panicking. Staff should disconnect compromised devices from the network immediately by pulling physical cables or disabling Wi-Fi on cash registers.

Next, workers must change all accessible passwords from a clean, uninfected device, prioritizing online banking accounts and corporate email addresses. Management should contact their bank immediately to report potential account fraud and attempt to halt pending transactions.

Finally, staff should record all available evidence, including screenshots, timestamps, and suspicious messages, to assist technical recovery and support official police reports.

Small businesses can no longer rely on the assumption that cybercriminals only target billion-ruble corporations. With cyberattacks expected to rise by 30 to 35 percent in 2026, implementing baseline security measures is essential to prevent business failure.

Related

Leave a comment

Your email address will not be published. Required fields are marked *