Skip to content

Why SMBs are targeted by cybercriminals

Attacks don’t pick a victim, they hunt for vulnerabilities. How automated target selection works, and why being small protects no one.

7 min read
Also inenit

How automated victim selection really works, and why “being small” protects no one.

We picture hackers as hooded computer wizards, lit by the pale glow of their monitors, fingers trembling across the keyboard. Sometimes idealistic activists, sometimes mercenaries of cyberspace.

The story goes that during Kevin Mitnick’s trial, one of the prosecutors went as far as claiming he could start a nuclear war by whistling into a phone.

Nothing could be further from the truth. And yet this myth, charming as it is, has a dark side: the false belief that “it won’t happen to me, I’m not a target.” We assume cybercriminals carefully pick their next victim and, unsettling as that sounds, it’s reassuring to believe we’re not interesting enough: a drop in the ocean.

The reality

First of all, we need to stop picturing cybercriminals as lone individuals. There are real organizations out there, sometimes state-sponsored, that design and industrialize the extortion of businesses and the sale of their secrets. This isn’t vandalism. It’s organized crime, in a market that earns more than the drug trade at a fraction of the risk.

And targets are selected at scale, automatically. It’s far easier and more effective to pick a vulnerability and look for who’s exposing it than the other way around. The targets number in the thousands.

A dam, a modem

It’s 2013. A group of Iranian hackers is searching the internet for systems that control physical devices: pumps, valves, sluice gates. They find the Bowman Avenue Dam in Rye Brook, about thirty miles north of Manhattan. The dam’s control system is connected to the internet through a cellular modem.

They get in. They see the water levels in real time, the temperature, the status of the sluice gate. They are inside the dam’s control system.

They fail to operate the gate only by a stroke of luck: it had been manually disconnected for maintenance. Downstream lies a densely populated area.

The motive has never been clarified: some speak of a dry run, others of a case of mistaken target.

The intrusion lasted three weeks, between August and September 2013. Nobody noticed. The news only became public in December 2015, and formal charges followed in 2016.

You probably don’t run a dam. But that doesn’t make you safe: it just puts you in a different category of the same problem.

The tool that puts all of this within anyone’s reach

There’s a search engine called Shodan. It doesn’t search websites. It searches devices: everything connected to the internet that answers a connection. Servers, routers, webcams, NAS drives, industrial PLCs, SCADA systems, control units, smart thermostats, hospital systems. If it’s online and has an IP address, Shodan has probably already found it, cataloged it and made it searchable, complete with software version, open ports and service banners.

Its creator, John Matherly, launched it in 2009. Some call it “the world’s most dangerous search engine.”

It isn’t an illegal tool. It’s used by researchers, system administrators, and anyone who wants to know what’s exposed on their own network. The problem is that “anyone” also includes people who shouldn’t have access to what they find.

A system can be visible on Shodan and perfectly secure. Its presence only says that it exists. What it says about itself (software version, open ports, accessible admin panels, default credentials never changed) is where the trouble starts.

The process nobody imagines

There’s a fundamental misunderstanding in the way most people think about cyberattacks.

The popular image is of a criminal who picks a victim, studies them, builds something tailor-made. It’s a cinematic image. And it’s almost entirely false for the vast majority of attacks that hit SMEs.

Reality works the other way around: you don’t start from the victim to find the vulnerability. You start from the vulnerability to find the victims.

Here’s how it goes: an automated scanner, one of the many sweeping the internet 24 hours a day, 7 days a week, looks for systems exposing a software version with a known vulnerability. It isn’t looking for you. It’s looking for a specific configuration. When it finds one, your IP address goes on a list.

That list is worked through automatically: login attempts with default credentials, off-the-shelf exploits for the vulnerabilities found, probes to see what lies behind. All without human intervention, all in parallel against thousands of targets at once.

The time between the public discovery of a vulnerability and the first large-scale exploitation attempts can shrink to just a few hours.

Want to check for yourself? With a free Shodan account, search for product:exim "4.91": at the time of writing, thousands of exposed systems still show up, vulnerable to a critical bug from 2019. A few, by the way, are honeypots! And that’s just one vulnerability. Tens of thousands are discovered every year.

Or, more simply, search shodan.io for your own public IP address. What you find is exactly what anyone else finds.

The surface we can’t see

There’s a feature of the problem that makes it especially treacherous for SMEs: the exposed attack surface is often much larger than the company realizes.

Every device connected to the internet is a potential entry in Shodan’s index. The NAS set up for remote access. The CCTV system installed three years ago with its default password never changed. The old mail server still online because “it still works.” The router’s admin panel reachable from outside because “that way the technician can step in remotely.”

None of these systems was connected out of negligence. They were connected for convenience, for operational needs, to solve a practical problem. The fact that they can be seen and queried by anyone in the world is a consequence that often goes unconsidered at setup.

The result is that many SMEs have an attack surface nobody has ever fully mapped, and that a cybercriminal can explore in minutes with free, public tools.

Size is no protection

There’s one belief worth taking apart head-on: the idea that being small means being uninteresting.

In the automated targeting model, a company’s size is almost irrelevant. What matters is the exposed vulnerability. A server running outdated software in a twenty-person manufacturing SME is exactly the same target as one in a two-hundred-person mid-sized company, if it exposes the same vulnerability.

If anything, SMEs are often preferred targets, precisely because the odds of finding unpatched systems, default passwords and sloppy configurations are statistically higher. Not out of negligence, but for lack of resources dedicated to security.

The numbers bear this out. The 2025 CLUSIT Report documents that in 2024 Italy suffered 10.1% of known serious attacks worldwide, while accounting for less than 2% of global GDP. We’re hit five times more than our economic weight would suggest.

You weren’t chosen. You were found

This distinction radically changes how you think about your own exposure.

If attacks were targeted and selective, the logic of “I’m not interesting enough” would make sense. But in an automated system processing thousands of IP addresses at once, selection happens on vulnerability, not on identity. It doesn’t matter who you are, what you do, how much you earn. What matters is what you expose.

The big numbers we thought were hiding and protecting us are, in fact, sharpened blades pointed at us.

The aim of this article isn’t to scare you into buying our solution. It’s to shed light on a little-known world that thrives on its own obscurity, and to help you prepare, concretely, for something that will happen sooner or later.

The first concrete step is knowing what you expose. Shodan shows you for free, in a few seconds, through the same eyes as everyone else.

The second step is asking what happens if someone on that list finds what they were looking for. And decides to keep going.

Published · Updated

Send threat actorsfrom your network into ours.

From €145 per decoy per month. Free trial available, no hardware, no setup fees.

Join The Hive

Threat intel from our own decoys, first-hand. Not another newsletter.

  • Intel from our network. What our decoys catch: the credentials threats try, the tools they bring, the techniques that are new. First-hand, not recycled.
  • Alerts, when it matters. When something we see is worth acting on, you hear it from us, with what to do.
  • Attack stories. The story behind the intel: a real attack, narrated step by step from the offensive side.

Low volume, high quality.

Plus occasional Hoxey news, and we remember your visits. Unsubscribe anytime.

Get in touch

Write to us here and we'll email you back.

We'll reply by email. Privacy policy Prefer a call? Book one