When researchers at security firm Sysdig dissected the first documented AI-driven ransomware operation this summer, one detail stood out. Midway through the intrusion, the attack hit a login error — the kind of snag that used to buy defenders hours while a human attacker troubleshot it. The AI fixed it in 31 seconds and kept moving. If your security plan quietly assumes a scammer with limited time, limited patience and office hours, that assumption has expired.
The month the attacker's costs collapsed
In August, Google's security team warned that AI agents are changing attacks across three dimensions: sophistication, scale and speed. Ransomware groups and access brokers are already using agents to scan documentation, hunt for weak credentials and move through systems before anyone has read the alert. Google also expects openly available models to match frontier-level cyber capability within six to twelve months — at which point the tooling becomes effectively free.
The economics are the real story. Anthropic documented a case in August 2025 where its own coding tool had been abused to automate extortion against at least 17 organisations, with ransoms that sometimes exceeded $500,000 — an operation run largely by automation rather than a criminal crew. And in May 2026, Google's Threat Intelligence Group reported disrupting a criminal group that had used AI to build a working zero-day exploit intended for a mass exploitation campaign.
Here is why that matters for a ten-person business in Ghent or Lyon. You were never worth a week of a skilled hacker's time. You are absolutely worth thirty minutes of a machine's. When the cost of attacking approaches zero, small targets stop being safe by obscurity.
The voice on the phone may not be human
The same cost collapse applies to social engineering. According to McAfee's research, about three seconds of audio — a voicemail greeting, a clip from your website — is enough to clone a voice with roughly 85 percent similarity. CrowdStrike reported a jump of more than 1,600 percent in deepfake-enabled voice phishing in a single quarter of 2025. And the now-infamous Hong Kong case, where a finance employee wired about $25.6 million after a video call in which every other participant turned out to be a deepfake, shows where this goes at the top end.
The uncomfortable finding underneath all of this comes from identity firm iProov: in its testing, only 0.1 percent of people could reliably tell high-quality deepfakes from real footage. Recognising your supplier's voice, or your boss's face on a call, is no longer verification. It is just familiarity — and familiarity can now be manufactured on demand.
Six unglamorous moves that still win
The striking thing about Google's defensive advice for this new era is how basic it is. Machine-speed attacks are mostly automated versions of old attacks, and the old defences still block them — if they are actually switched on.
Multi-factor authentication everywhere, starting today. Email, banking, accounting software, your website admin, your cloud storage. AI agents excel at harvesting and testing leaked passwords at scale; MFA breaks that entire pipeline. Prefer app-based codes or hardware keys over SMS.
Kill password-only logins. Google's checklist specifically includes hunting for exposed passwords and removing unused accounts. Every dormant login of a former employee, every shared "info@" mailbox with one weak password, is an open side door that a scanning agent will eventually try.
Verify payment changes out-of-band. If a supplier emails new bank details, or the "CEO" calls asking for an urgent transfer, confirm through a different channel you initiated yourself — a phone number you already had, not one in the email signature. Make this a written rule, not a habit.
Brief your team on voice cloning — and agree a code word. Everyone who can move money or change access should know that a familiar voice proves nothing. A shared verification phrase for genuinely urgent requests costs nothing and defeats the clone.
Prune, patch, repeat. Software updates and an audit of who has administrator access were both on Google's list. Fewer accounts with fewer rights means less for an agent to find.
Test your backups by restoring them. A backup you have never restored is a hope, not a plan. Ransomware at machine speed makes recovery time your most important metric.
Put a leash on your own agents too
The other half of Google's August guidance is aimed at businesses deploying AI agents themselves, and its core idea is worth stealing: the hard limits belong outside the model. Google's framework for safer agents recommends controls the AI cannot talk its way past — transaction and spending caps, isolated environments for code execution, approval gates before consequential actions, and signed, traceable changes to data. Its Secure AI Framework adds three plain principles: agents must have well-defined human controllers, their powers must be carefully limited, and their actions must be observable.
For a small business the translation is simple. An agent that drafts invoices should not also be able to send payments. An agent with access to your inbox should not have access to your bank. Set spending limits where the money moves — at the bank or payment provider — not in the prompt. And keep a log of what your agents actually did, because under GDPR you still carry the responsibility, and a personal-data breach can trigger a 72-hour notification duty to your supervisory authority.
When not to panic
Honesty helps here. Most attacks on small businesses are still opportunistic and lazy, and the six basics above stop the overwhelming majority — Europol and national CERTs have said versions of this for years. You do not need an AI-powered security product this quarter; you need MFA switched on this week. Nor will regulation save you in real time: the EU AI Act does require deepfakes to be labelled, with penalties reaching €35 million or 7 percent of global turnover, but criminals are not known for compliance. The rules protect the market; the checklist protects you.
The deeper shift is that trust signals we relied on for decades — a familiar voice, a plausible email, a fast, fluent reply — are now cheap to fake. The businesses that adapt are not the ones buying the most tools, but the ones that decided, in writing, what gets verified and what their own AI is allowed to do.
If you are rethinking where AI fits in your business — including which tasks are safe to hand to an agent and which controls should sit around it — that is exactly the kind of question Cresly's AI Readiness Scan is built to answer. It maps where AI can genuinely help your business, and where a human should stay firmly in the loop.