Skip to content

Mid-sized Enterprises in the Crosshairs of Cybercriminals: Company Size Offers No Protection

In a nutshell: Automated attacks and spear-phishing target enterprises of all sizes, meaning company size provides no effective defense.

Cyber attacks no longer strike only large corporations – mid-sized businesses are increasingly becoming a focus of attackers. Often it is everyday vulnerabilities such as outdated systems and unprotected access points that enable entry.

Behind modern cyber attacks typically stand three perpetrator groups with different motives: state or state-aligned actors carry out sabotage operations to cripple IT systems and render infrastructure unusable. A second group operates from intelligence interests and targets the theft of know-how, trade secrets or technical data. Organised cybercrime groups, finally, extort enterprises either through threats to publish stolen data or directly with ransom demands.

Most attacks occur via email, although tactics have evolved from classical phishing to targeted spear-phishing. Criminals leverage publicly available information from corporate websites, social networks and press releases to create credible personalised messages – supported by artificial intelligence that enables fully automated scaling. Documented cases exist where attackers nearly completely copied corporate websites, operated them under slightly falsified web addresses and directed employees via prepared emails to the forgery, where they then entered their login credentials.

A central misconception among mid-sized enterprises is the assumption that they are too small to be targeted by attackers. In reality, the initial access in many attacks runs completely automatically: systems scan the internet for reachable devices, gather email addresses and test known vulnerabilities. Only after successful intrusion – whether via phishing or identified system vulnerabilities – do attackers assess which enterprise is affected and whether an attack is worthwhile. Company size thus offers no protection.

Technical vulnerabilities remain a primary entry point. In documented cases, business-critical servers with specialised applications ran for over 15 years without security updates while being directly reachable from the internet – because the risk of updates was not assessed. Beyond this, physical gaps also play a role: prepared USB sticks or external access by service providers leading to disclosure of security-relevant information. Effective risk mitigation therefore requires technical, organisational and personnel measures in equal measure.


Source: www.it-daily.net · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: