Technology
How Ransomware Attacks on Small Businesses Can Become a Gateway to Bigger Targets

Ransomware attackers are increasingly shifting their focus towards small and medium-sized businesses (SMBs), many of which are rapidly adopting digital technologies but still lack dedicated cybersecurity teams and advanced protection systems. Data from cybersecurity firm Kaspersky shows that ransomware detections among Indian SMBs increased from 3.18 per cent in the first quarter of 2025 to 4.07 per cent during the same period in 2026. Although the rise may appear small, experts say it reflects a steady change in cybercriminal behaviour, with smaller businesses becoming regular targets rather than experiencing isolated attacks.
Cybersecurity specialists believe the actual level of risk could be much higher than detection numbers indicate. Jaydeep Singh, General Manager for India at Kaspersky, explained that such statistics generally capture only the final stage of an attack, when criminals encrypt systems, while earlier activities such as gaining access, stealing credentials and moving through networks often remain undetected. Ransomware has evolved significantly over the years. Earlier attacks mainly involved encrypting files and demanding payment in exchange for restoring access. Today, cybercriminal groups often spend considerable time inside a victim's network, collecting sensitive information, compromising accounts and extracting data before launching encryption.
This shift has made ransomware more damaging because even organisations that recover their systems through backups may still face risks if stolen confidential information is later leaked or misused. Small and medium businesses are becoming increasingly attractive targets because of two major trends. The first is India's rapid digital transformation, which has pushed SMBs to adopt cloud platforms, online payment systems, connected manufacturing technologies and digital supply chains. The second is the rise of ransomware-as-a-service models, which have made advanced attack tools easily available to a wider range of criminals.
According to Singh, ransomware groups are not replacing large enterprises with smaller businesses as targets. Instead, they now view Indian SMBs as valuable victims because many have weaker security measures while still holding important business data and network access. India's MSME sector contributes significantly to the economy, accounting for around 31.1 per cent of GDP, 35.4 per cent of manufacturing output and nearly half of the country's exports. As these businesses become more connected with larger companies, their cybersecurity weaknesses can create risks across entire supply chains.
Cybercriminals increasingly see suppliers, logistics providers, IT vendors and manufacturing partners as possible entry points into bigger organisations. A compromised small business can provide attackers with access to larger corporate networks, making SMB security a concern not only for the companies themselves but also for their business partners. The ransomware ecosystem has also become more organised. Groups such as The Gentlemen, a ransomware-as-a-service operation tracked by Kaspersky researchers, have expanded rapidly by targeting industries including manufacturing, healthcare, IT services, financial services, construction and logistics.
Unlike traditional ransomware groups, modern operators often use specialised tools to study their victims before launching attacks. Researchers have identified malware capable of gathering network information, communicating with attackers and conducting reconnaissance activities long before files are encrypted. Kaspersky's Q1 2026 threat report said The Gentlemen accounted for 9.25 per cent of victims listed on ransomware leak websites, placing it among the fastest-growing ransomware groups.
The growing popularity of ransomware-as-a-service has lowered the technical skills required to launch attacks. Criminal groups can now purchase access, malware tools and support services, allowing more attackers to target businesses with limited cybersecurity resources. Industries such as manufacturing, healthcare, IT services, financial services, construction and logistics are currently facing increased ransomware activity. Experts say attackers are not necessarily interested in what these companies produce but are instead targeting sectors that have become highly digital and interconnected without making equal investments in cybersecurity.
Manufacturing is considered particularly vulnerable because information technology and operational technology systems are increasingly linked. While this improves efficiency, it also creates more opportunities for attackers if security controls are not strengthened. The nature of ransomware attacks is also changing. Criminals are moving away from relying only on file encryption and increasingly using data theft and extortion tactics. Instead of simply blocking access to systems, attackers steal confidential information and threaten to publish it unless their demands are met.
The use of initial access brokers has further complicated the threat landscape. These specialised cybercriminal groups break into networks and sell access to ransomware operators, with remote access services, VPN systems and internet-facing portals often becoming common entry points. Artificial intelligence has introduced another challenge. While fully automated AI-powered cyberattacks are still developing, criminals are already using the popularity of AI tools to trick users into downloading malicious software.
Kaspersky researchers found that attacks disguised as popular AI applications increased significantly among SMBs in 2026. Fake AI tools, including fraudulent versions of widely used assistants, have become a growing method for spreading malware. Despite the increasing sophistication of ransomware campaigns, many SMBs continue to struggle with basic cybersecurity practices. Lack of dedicated security teams, poor patch management, weak backup strategies and limited monitoring capabilities remain major vulnerabilities.
Experts also warn that backups alone are no longer enough protection. Modern ransomware groups often steal data before encrypting systems, meaning businesses need stronger detection, response and data protection measures. Another challenge is regulatory preparedness. Many Indian organisations are still in the early stages of implementing requirements under the Digital Personal Data Protection (DPDP) framework, leaving them exposed to both cybersecurity threats and compliance risks. As India's SMB sector continues to digitise, cybersecurity is becoming a critical part of business survival. Ransomware is no longer just an IT problem affecting individual companies; it has become a wider economic risk that can impact entire supply chains and larger organisations connected to smaller businesses.



