The call comes in at 4:40 p.m. on a Friday. The voice on the line is the owner of a Pocatello construction firm — except it isn’t. It’s a thirty-second clip of his voice, scraped from a chamber of commerce video and cloned for less than the price of lunch. The bookkeeper wires $48,000 before the weekend. On Monday, the real owner finds out.
That scenario would have been exotic in 2023. In 2026 it is routine, and it is the single clearest illustration of how the threat landscape has shifted: the attacks aren’t more sophisticated in the technical sense, they’re more convincing, and they arrive far faster than most small businesses can react.
This guide breaks down what actually changed between 2025 and 2026, what the data suggests is coming in 2027, and — the part that matters — what a business in Idaho Falls, Pocatello, Rexburg, or Blackfoot should do about it before the next renewal or the next Friday afternoon.
What’s in This Guide
- The Headline: What Changed Between 2025 and 2026
- Trend 1: Unpatched Software Overtook Stolen Passwords
- Trend 2: AI Made Fraud Convincing
- Trend 3: Ransomware Went After the Backups First
- Trend 4: Your Vendors Became the Attack Surface
- 2025 vs. 2026: The Numbers Side by Side
- What to Expect in 2027
- What Small Businesses Should Actually Do
- Frequently Asked Questions
- Where to Start
The Headline: What Changed Between 2025 and 2026
The 2026 Verizon Data Breach Investigations Report — the closest thing the industry has to a census, built on more than 22,000 confirmed breaches across 145 countries — found one change that reframes almost everything else: vulnerability exploitation overtook stolen credentials as the leading way attackers get in, accounting for roughly 31% of breaches.
For years the standard advice was that breaches were a password problem. Turn on multi-factor authentication, the thinking went, and you’ve closed the front door. That advice was right, and enough businesses took it that attackers moved on. They now prefer the unlocked window: software that hasn’t been patched.
What makes this worse is the timing gap. The same report found the median time to patch a known vulnerability rose from 32 days to 43 days — a 34% increase — at exactly the moment attackers got faster at weaponizing new flaws. Defenders slowed down while offense sped up. That widening gap is the story of 2026.
Meanwhile the human element still appears in 62% of breaches, up slightly from 60%. People didn’t get more careless. The lures got better, which brings us to the second trend.
Trend 1: Unpatched Software Overtook Stolen Passwords
The practical consequence for a 15- to 60-person business is uncomfortable: patching is now a frontline security control, not IT housekeeping to be done “when there’s time.”
Most small businesses handle updates reactively — someone clicks “remind me later” on a workstation for three weeks, and the firewall or VPN appliance gets touched once a year. Attackers scan the entire internet for those specific devices within hours of a vulnerability being published. There is no obscurity to hide behind; automated scanning does not care that you’re a 22-person clinic in southeast Idaho.
The fix is unglamorous and it works: a documented patch cycle with a deadline, covering not just Windows but firewalls, VPNs, routers, and every internet-facing appliance. If nobody at your company can say when your firewall firmware was last updated, that’s the finding.
Trend 2: AI Made Fraud Convincing
This is where the change is most visible to non-technical staff.
The share of business email compromise attacks using AI-generated voice, video, or text has climbed to roughly 40% in 2026, up from under 5% in 2023. Voice cloning that once needed a lab now needs twenty to thirty seconds of audio and costs less than twenty dollars on commodity criminal marketplaces. Any owner who has recorded a podcast, a webinar, a radio spot, or a chamber video has already published the raw material.
The financial asymmetry is stark. Industry analysis puts average losses from AI-augmented BEC above $4.1 million per incident, versus roughly $1.3 million for traditional phishing — because the AI-assisted version is targeted at the people who can move money, and it clears the “does this feel right?” test that used to catch fraud. The FBI’s Internet Crime Complaint Center logged $16.6 billion in reported losses across 859,532 complaints, with $2.77 billion tied specifically to business email compromise.
Notice what defeats this: not a better spam filter. A callback rule. Any request to move money, change bank details, or buy gift cards gets verified on a known-good phone number — one already in your directory, never a number supplied in the message itself. It costs nothing and it is the only control that reliably survives a convincing deepfake, because it doesn’t ask the employee to detect the fake at all.
Awareness training has to change with it. Teaching staff to spot bad grammar and odd formatting is now actively misleading advice; generative AI writes cleaner English than most of your real vendors. Train the process, not the tells.
Trend 3: Ransomware Went After the Backups First
Ransomware volume kept climbing through the period — U.S. incidents rose roughly 50% over the first ten months of 2025, and industry projections have attacks up around 40% by the end of 2026 against a 2024 baseline. But the volume isn’t the interesting part. The targeting is.
Two findings should change how you think about recovery:
- Roughly 96% of ransomware attacks attempt to reach backup locations. Attackers learned that encrypting production data is only leverage if you can’t restore. Destroying or encrypting the backup is now a standard step, not an afterthought.
- In about 54% of incidents, ransomware is deployed within seven days of initial access. The old assumption of a long, quiet dwell time — months to notice an intruder — no longer holds for this category.
And the exposure is not evenly distributed. Verizon’s own breakdown found ransomware present in 88% of small and mid-sized business breaches, compared with 39% at large enterprises. That gap isn’t because criminals prefer small companies philosophically. It’s because larger organizations run dedicated patch management and 24/7 detection, and most small ones don’t.
The takeaway is specific: a backup you have never restored from is a hypothesis, not a backup. It needs to be immutable (so it cannot be altered or deleted once written), isolated from the network that would be encrypted, and test-restored on a schedule with the date written down. That last detail matters more than it sounds — see the insurance section below.
Trend 4: Your Vendors Became the Attack Surface
The trend that gets the least attention from small business owners is the one with the widest blast radius.
Roughly 48% of breaches now involve a third party, and a 2026 survey found 43% of managed service providers and their customers experienced an incident that originated with a supplier or vendor in the preceding twelve months. Remote management platforms have been a repeated target, because compromising one provider inherits that provider’s access to every downstream client at once. One incident in April 2026 forced the isolation of 78 businesses from a single point of compromise.
We include this trend knowing exactly how it reads coming from an IT provider. It is a fair question to ask of us, and you should ask it of any vendor with administrative access to your systems: Is your remote access tooling patched and multi-factor protected? Who at your company can reach my environment, and how is that logged? What happens to my systems if you get breached?
A provider that gets defensive about those questions has told you something useful. This is also why continuous monitoring rather than business-hours-only support has stopped being a premium upsell and started being the baseline — the seven-day deployment window above doesn’t respect your office hours.
2025 vs. 2026: The Numbers Side by Side
| Measure | 2025 | 2026 | Direction |
| Top breach entry point | Stolen credentials | Vulnerability exploitation (~31%) | Shifted |
| Median time to patch | 32 days | 43 days | Worse (+34%) |
| Human element in breaches | 60% | 62% | Slightly worse |
| BEC attacks using AI/deepfakes | Rising from a small base | ~40% | Sharply worse |
| Ransomware in SMB breaches | High | 88% (vs 39% enterprise) | Concentrated on SMBs |
| Breaches involving a third party | ~30% | ~48% | Worse |
| Insurers requiring MFA / EDR | Common | 96% / 88% | Now effectively mandatory |
What to Expect in 2027
Predictions deserve more humility than they usually get, so here is the honest split between what follows directly from the data and what is genuinely uncertain.
Reasonably confident:
- The patch gap keeps widening before it narrows. Exploitation is now the leading entry point and remediation is getting slower, not faster. Nothing in the 2026 data suggests that reverses on its own within a year. Expect exploitation of internet-facing devices to remain the number one entry point through 2027.
- Deepfake-assisted fraud becomes the default, not the variant. At 40% adoption and falling costs, the trajectory points toward AI-assisted social engineering being the majority of BEC attempts. Verification-by-callback moves from best practice to table stakes.
- Insurance tightens from attestation to evidence. Carriers have already begun requiring proof — sign-in log exports, conditional access screenshots covering the prior 90 days — rather than a checkbox saying MFA is enabled. More than 70% of small businesses reportedly fail these assessments today. Expect documentation burden to increase and expect it to be enforced at claim time, not just at renewal. We covered the specifics in our guide to cyber insurance requirements for Idaho businesses.
Genuinely uncertain, and worth watching:
- Autonomous attack agents. Multiple forecasters expect AI systems that plan, execute, and adapt attacks with limited human direction to become meaningful in 2027. Whether that arrives as a step change or a gradual creep is unknown. What’s more concrete is the flip side: as businesses deploy their own AI agents with access to email, files, and systems, those agents become a target — through prompt injection, tool misuse, and memory poisoning. An AI agent with broad permissions and no oversight is a new kind of insider risk.
- AI security spending lags AI adoption. Analysts note organizations are spending vastly more on deploying AI than on securing it, and that a large share of agentic AI projects will be abandoned partly because the cost of monitoring them was underestimated. If you’re planning to adopt AI in your operations, budget for governing it, not just for licensing it.
The practical read: 2027 does not require a new category of defense. It raises the penalty for not having done the 2026 fundamentals.
What Small Businesses Should Actually Do
Ranked by impact per dollar, for a business without a full-time security team:
- Institute a callback rule for money movement. Free. Defeats deepfake fraud without asking anyone to detect a deepfake. Put it in writing and make it apply to the owner too — executives are the most impersonated and the most likely to be waved through.
- Patch on a deadline, including network appliances. Firewalls, VPNs, and routers included. Assign an owner and a date, not an intention.
- Make backups immutable, isolated, and test-restored — and write down the test date. Given that 96% of ransomware attacks go after backups, an untested backup is the single most common gap between “bad week” and “existential event.”
- Put MFA on everything that touches business data, then keep the evidence. Your insurer will want proof, not assurance.
- Get detection that runs outside business hours. A seven-day deployment window means a Friday intrusion is a Monday encryption event.
- Audit your vendors’ access. Including ours. Know who can reach your systems and how it’s logged.
- Retrain staff for the AI era. Drop “look for typos.” Teach verification of process and authority instead.
Regulated environments carry extra weight here — clinics and dental practices have breach notification obligations that turn a contained incident into a reportable one, which is why healthcare IT support has to treat documentation as part of the control, not paperwork after the fact.
Frequently Asked Questions
We’re small. Are we really a target?
Targeting is mostly automated, so size doesn’t provide cover — scanners find exposed devices regardless of company size. The relevant statistic is that ransomware appears in 88% of SMB breaches versus 39% of enterprise breaches. Smaller organizations aren’t attacked because they’re chosen; they’re compromised more often because the controls that stop the automated stage are missing.
Is antivirus enough?
No. Traditional antivirus matches known signatures. The dominant 2026 entry point — exploiting an unpatched internet-facing device — often doesn’t involve a file that antivirus would inspect. Endpoint detection and response, which watches behavior rather than signatures, is what insurers now require, and 88% of them require it.
How would we know if we’re already compromised?
Common signals include MFA prompts nobody requested, mailbox rules forwarding mail externally, new admin accounts, and backup jobs failing quietly. Most small businesses find out from a third party. If you have never had someone check, assume the question is open.
Does cyber insurance cover us if a control was missing?
Often not. That’s the shift — carriers increasingly verify controls at claim time, and a gap between what was attested and what was in place at the moment of the incident is a common basis for denial.
Where to Start
Nothing above requires an enterprise budget. It requires knowing which of these gaps you actually have, which is a different problem from knowing they exist in general.
If you want a straight answer on where your business stands — patch status, backup restorability, MFA coverage, and vendor access — book a tech checkup and we’ll walk through it with you. If you’d rather start with the broader picture of what ongoing coverage looks like, our Idaho cybersecurity solutions and managed IT services pages lay out how the pieces fit together.
MOATiT works with businesses across Idaho Falls, Pocatello, Rexburg, Blackfoot, and southeast Idaho — and the honest starting point for most of them is a conversation, not a quote.