MORE than half of all posts selling backdoor access to compromised companies on dark web forums now target small- and medium-sized businesses (SMBs), cybersecurity firm Kaspersky said on Thursday, a finding that carries outsized risk for the Philippines, where such enterprises make up nearly all registered businesses.
Kaspersky’s Digital Footprint Intelligence Unit, which analyzed hundreds of posts by so-called initial access brokers published from January to April 2026, found that offers of access to allegedly compromised small-sized organizations accounted for the largest share of listings at 40 percent, outstripping those for large corporations and nonprofits.
Posts targeting medium-sized firms took up another 20 percent, meaning SMBs together represented more than half of the illicit market.
Initial access brokers sell entry points into corporate systems, often detailing the victim company’s location, industry, revenue, and the type of access on offer. Buyers can then use these footholds to deploy ransomware, steal confidential corporate data, or carry out other fraud.
‘Despite the fact that posts concerning small-sized companies prevail, threat actors may target mediumsized businesses as they generate higher revenue than small businesses while they may have lower level of protection against cyberthreats than large ones,’ said Ekaterina Beloborodova, analyst at Kaspersky Digital Footprint Intelligence.
She added: ‘Thus, the common belief that small- and medium-sized enterprises are uninteresting to attackers is a misconception.’
Beloborodova said companies of any size need to understand the threat landscape, adhere to cybersecurity policies, deploy appropriate security solutions, and continuously train employees.
She noted that SMBs tend to be less protected than large enterprises while often serving as trusted contractors to them, making a compromised small firm a potential gateway into bigger, better-defended organizations.
To reduce exposure, Kaspersky advised SMBs to adopt security solutions matched to their size and budget, consider managed detection and response services if they lack round-the-clock security personnel, monitor the dark web for leaked credentials and lookalike websites, set clear rules on the use of external services, define access controls for corporate email and shared files, and regularly back up critical data.