Skip to content

WHT Cyber  /  Field Notes  /  Threat Education

Threat Education

The "it won't happen to us" bias: why SMBs are the #1 ransomware target in 2026.

Ransomware crews stopped chasing Fortune 500 headlines years ago. The economics quietly flipped — and the 30-person business that thinks it's too small to bother with is now the exact size they're optimized to hit.

By WHT Cyber Engineering July 21, 2026 8 min read

Every owner we sit with says some version of the same thing in the first five minutes: “We're too small to be a target.” They don't say it defiantly. They say it as a fact, the way you'd say “we're too small for the SEC to care about.” It feels true. It stopped being true around 2020, and by 2026 it's actively dangerous thinking.

Here's what actually happened to the economics of ransomware — and why the 15-to-200 person business that nobody's heard of is now the sweet spot, not the exception.

The old picture, and why it's outdated

The mental model most SMB owners still hold is from the 2017–2019 era of big-name ransomware: nation-state-adjacent crews carefully targeting large companies, spending weeks inside networks, chasing eight-figure payouts. Colonial Pipeline. JBS. Big headlines, big victims.

That world still exists, but it's a small fraction of what actually happens now. The FBI IC3 Annual Report and the annual Verizon Data Breach Investigations Report both show the same shift: ransomware complaints and confirmed breaches are dominated by small and mid-sized organizations. Verizon's most recent DBIR explicitly calls out that the median victim organization in confirmed ransomware breaches is well under 1,000 employees.

CISA's #StopRansomware guidance, originally aimed at critical-infrastructure operators, has spent the last two years quietly re-oriented around SMB and municipal victims. That's not a marketing choice. That's who's actually getting hit.

What changed: ransomware became a business

The shift that matters is that ransomware stopped being a craft and became an industry. Three specific changes drove it.

1. Ransomware-as-a-Service (RaaS)

The people writing the ransomware code are not the same people breaking into your network. Modern RaaS crews license their encryptors and their infrastructure to “affiliates” who do the actual intrusions and take a cut — typically 70–80% of the payout. The affiliates are numerous, opportunistic, and unskilled by nation-state standards. They don't care whether you're a bank or a bakery. They care about volume and effort.

The RaaS operators do the hard part (encryption, negotiation portals, leak sites, cryptocurrency laundering) so the affiliates can focus on quantity.

2. Access brokers

There's now a whole layer of criminal supply chain called Initial Access Brokers — specialists who compromise networks and sell that access on forums. A working VPN credential to a 40-person law firm might sell for $500–$2,000. A domain-admin foothold at a mid-sized manufacturer might go for $10,000+.

What this means practically: the group that phishes your login is not the group that ransoms you. Access is a commodity. If your network is standing at the end of Q3, chances are decent that a broker has already listed it or will soon. This dynamic is well-documented in CISA's joint cybersecurity advisories.

3. Automation

The reconnaissance and initial-access phases are now heavily automated. Attackers use continuous scanning against the entire IPv4 space for exposed RDP, VPN appliances with known CVEs, misconfigured OWA / M365 tenants, and unpatched Fortinet, Ivanti, and Cisco boxes. When something pops, the automation drops a first-stage payload and hands the access off to a human operator.

You don't have to be interesting to be scanned. You just have to be reachable.

Why SMBs specifically

Once you understand the industrialization, the SMB focus is obvious. Look at it from an affiliate's perspective.

  • Easier to breach. Enterprise has SOCs, EDR, threat hunting, mature identity, red teams. A typical 40-person business runs Microsoft 365 with default settings, an antivirus tool nobody's watching, a VPN box that hasn't been patched in 18 months, and no one on call after 6 PM. The effort-to-money ratio is much better.
  • More likely to pay. Big companies have IR retainers, cyber counsel, tabletop-tested playbooks, and often a philosophical stance against paying. A small business hit with encryption on Friday afternoon with payroll due Tuesday will negotiate. Insurance carriers, until recently, would advance the ransom.
  • Faster cycle time. An affiliate can rip through a small network in 24–72 hours. Getting into a Fortune 500 takes months. Ten SMBs in a year beats one enterprise attempt that may never land.
  • Lower media attention. A ransomware attack on a Charlotte-area 60-person business rarely makes the news, and the crew's leak site does the work of applying pressure. Enterprise attacks bring FBI attention, congressional interest, and international sanctions risk.

All of this is why independent tracking shows ransomware revenue continuing to grow even as high-profile enterprise victims decline. The volume is coming from below.

The bias that makes it worse

The reason SMB owners underestimate this isn't ignorance. It's a well-studied cognitive bias called optimism bias: people systematically underestimate the probability that bad things will happen to them specifically. In cybersecurity, it usually sounds like one of these:

  • “We don't have anything worth stealing.” (Attackers don't need something worth stealing — they encrypt what you already have.)
  • “Nobody's heard of us.” (They didn't hear of you. Their scanner found port 3389 open.)
  • “We have antivirus and backups.” (Antivirus is signature-matching from a different era. Backups are the first thing modern crews destroy.)
  • “Our IT guy would tell us if something was wrong.” (Your IT provider is not a SOC. Watching alerts at 3 AM is not their job.)

Every one of these sounds reasonable inside the business. None survives contact with how ransomware actually works in 2026.

The North Carolina angle

North Carolina is not a special target — but our client mix does show something worth naming. The most common Charlotte-area ransomware incidents we see aren't tech companies or big employers. They're professional services firms (RIAs, law, accounting), specialty contractors, healthcare practices, and small manufacturers. All are exactly the size the automation-plus-affiliate model is optimized for: 20–150 employees, cash flow that can't tolerate a week of downtime, minimal in-house security, and enough sensitive data that the leak-site threat lands.

“We're just a small NC business” is not protection. If anything, it's the profile.

What WHT recommends

You don't have to become an enterprise to survive this. You have to close the specific gaps SMB attackers exploit. Six controls do most of the work:

  1. Phishing-resistant MFA on every mailbox, VPN, and remote-access tool. Credential theft is the #1 initial-access vector. Kill it at the front door with number-matching MFA or FIDO2 keys for anyone with financial or admin authority.
  2. Real EDR on every endpoint, watched by a SOC. Antivirus isn't enough. EDR (with a human watching the console) is the difference between “isolated in 90 seconds” and “discovered Monday morning.”
  3. Patch the KEV list monthly, minimum. CISA's Known Exploited Vulnerabilities Catalog is the shortlist attackers are actively using. Nothing on that list should sit unpatched on internet-facing infrastructure.
  4. Immutable / offline backups with a tested restore. Not “we have Datto.” A signed restore test in the last 12 months. Assume attackers will try to delete backups first.
  5. Written incident-response playbook and 24/7 contact. When the encryption starts on Friday at 5 PM, you should already know who to call, in what order, with what authority. Figure that out now, not then.
  6. Cyber insurance you actually qualify for. Not just a policy in a drawer — a policy whose control questionnaire matches your reality, or you'll find out at claim time it doesn't cover you. (See our post on 2026 renewals.)

The bottom line

Ransomware in 2026 is a volume business, and the volume comes from SMBs. Attackers don't care whether you'd be an interesting headline. They care whether your VPN is patched, whether your MFA is enforced, and whether your backups will survive an admin token they already have.

The best time to stop assuming it won't happen to you is before it does. The second-best time is right now.

Want a 30-minute honest readout on where you stand?

We'll walk through the six controls above against your actual environment, tell you where you're exposed, and hand you a prioritized punch list. No pitch. No pressure. Just a straight readout you can act on.

Book the security review See how WHT protects SMBs →