SMEs Facing a New Wave of AI-Driven Cyberattacks
According to a recent Kaspersky report, between January and April 2026, over 33,300 attacks targeting SMEs were blocked. These attacks utilized malware masquerading as popular artificial intelligence (AI) tools, such as ChatGPT, Claude, and DeepSeek. This figure represents a fivefold increase compared to the same period in 2025. (kaspersky.fr)
Understanding the Threat: AI Tool Impersonation
Cybercriminals are exploiting the enthusiasm for AI by distributing malware disguised as legitimate applications. By downloading these fake tools, users inadvertently install trojans capable of stealing sensitive data, spying on activities, or encrypting files to demand a ransom.
How the attack actually unfolds
- The fake desktop client: an employee searches for a “free” or “unlimited” version of a popular AI tool, downloads an executable from outside the vendor’s website, and installs a trojan that exfiltrates the address book, browser-stored credentials and open documents.
- The fake business extension: a browser extension or “AI” plug-in promising to optimise a dashboard or inventory management gains access to every page visited — including management tools and online banking. Some variants ship ransomware that encrypts every network share reachable from the workstation.
Key Considerations for SMEs
- Source Verification: Always download software from official publisher websites.
- Employee Awareness: Train your teams on the risks associated with downloading and using unverified tools.
- Regular Updates: Ensure all systems and software are up to date to benefit from the latest security patches.
- Security Solutions: Install robust antivirus and firewall solutions to detect and block potential threats.
Where to Start?
- Security Audit: Assess the current state of your company’s IT security.
- Develop a Security Policy: Define clear rules regarding software installation and the use of AI tools.
- Continuous Training: Regularly organize awareness sessions for your employees.
- Proactive monitoring: track what gets installed on workstations, and set alerts on unusual outbound traffic.
Our approach at D1 Consulting
The entry point is almost always the same: one workstation, one download, and no written rule about what may be installed. We start with an inventory of the AI tools actually in use, then a short installation policy your teams can follow — see our process automation & optimisation offer. The same blind spot is covered in SMEs and AI governance.
👉 Do you know which AI tools actually run on your team’s machines? Book a free 30-minute assessment: we build the inventory and the installation rules.

