SMEs Facing a New Wave of AI-Driven Cyberattacks
According to a recent Kaspersky report, between January and April 2026, over 33,300 attacks targeting SMEs were blocked. These attacks utilized malware masquerading as popular artificial intelligence (AI) tools, such as ChatGPT, Claude, and DeepSeek. This figure represents a fivefold increase compared to the same period in 2025. (kaspersky.fr)
Understanding the Threat: AI Tool Impersonation
Cybercriminals are exploiting the enthusiasm for AI by distributing malware disguised as legitimate applications. By downloading these fake tools, users inadvertently install trojans capable of stealing sensitive data, spying on activities, or encrypting files to demand a ransom.
Real-World Cases: SMEs Victimized by These Attacks
-
Service Company: An SME downloaded an application claiming to be an enhanced version of ChatGPT. Shortly after, client data was exfiltrated, leading to a loss of trust and regulatory penalties.
-
Retail Business: An employee installed an AI tool to optimize inventory management. The application contained ransomware that encrypted the entire IT system, paralyzing operations for several days.
Key Considerations for SMEs
-
Source Verification: Always download software from official publisher websites.
-
Employee Awareness: Train your teams on the risks associated with downloading and using unverified tools.
-
Regular Updates: Ensure all systems and software are up to date to benefit from the latest security patches.
-
Security Solutions: Install robust antivirus and firewall solutions to detect and block potential threats.
Where to Start?
-
Security Audit: Assess the current state of your company’s IT security.
-
Develop a Security Policy: Define clear rules regarding software installation and the use of AI tools.
-
Continuous Training: Regularly organize awareness sessions for your employees.�
