Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026

Here’s what you should know

February 6, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»“Cyber Tax” Warning as Two-Fifths of SMBs Raise Prices After Breach
News

“Cyber Tax” Warning as Two-Fifths of SMBs Raise Prices After Breach

Team-CWDBy Team-CWDDecember 13, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The vast majority of US small businesses suffered a data or security breach over the past year, with many (38%) putting up their prices as a result, according to a new study from the Identity Theft Resource Center (ITRC).

The non-profit’s 2025 Business Impact Report is based on interviews with 662 owners or executives at businesses with under 500 employees.

ITRC president, James Lee, argued that the inflationary impact of breaches acts as a “hidden cyber tax” on consumers. He claimed the data should serve as a wake-up call to lawmakers and spark new public policy initiatives at a state and federal level to alleviate the financial burden of cyber-threats.

“This shadow tax creates a drag on the US economy, fuels inflation and places a disproportionate burden on the small businesses that generate jobs and sustain communities. These businesses, which generally lack the resources of their larger enterprise counterparts, are being forced to choose between investing in growth, keeping prices low and defending against an ever-present digital threat,” Lee said.

“The current landscape is not a fair fight. We are at a point where the resilience of our national economy is increasingly linked to the cybersecurity of our small business community.”

Read more on the threat to small businesses: Verizon DBIR: Small Businesses Bearing the Brunt of Ransomware Attacks

Of the 81% of small businesses that suffered a security or data breach, or both, over the past year, a sizeable share (41%) blamed AI-powered attacks. The remainder were explained by external threat actors (43%) and malicious insiders (42%).

The ITRC warned that AI is increasingly being used to generate hyper-realistic phishing emails, deepfake audio/video for business email compromise (BEC), adaptive malware and automated reconnaissance.

“The primary advantage of a malicious insider has always been their intimate knowledge of internal processes, communication styles and organizational hierarchies, allowing them to bypass defenses through trust and familiarity,” the report explained.

“AI tools now allow external actors to replicate this advantage at scale.”

People, Process and Technology

The report also noted a “dangerous disconnect” between how confident small business leaders are about their cyber-resilience and their adoption of security controls.

Even as the number of respondents who said they felt “very prepared” for an attack or breach plummeted from 57% last year to 38% in this report, implementation of multi-factor authentication (MFA) also fell, from 34% to 27%. Investment in new security tools was down 15% annually.  

The ITRC advised small businesses to tackle the threat from AI-driven attacks by focusing on people, process and technology, as follows:

  • Update security training to ensure staff can spot AI-generated content and ensure they feel empowered to question unusual or urgent requests
  • Implement and enforce a strict out-of-band verification policy for sensitive requests like financial transactions and changes to privileged account access
  • Invest in modern, AI-powered cyber defenses that use behavioral analysis to identify anomalous activity on the network or endpoints, and look for AI-generated phishing content



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCritical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution
Next Article Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts
Team-CWD
  • Website

Related Posts

News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
News

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026
News

Chinese-Made Malware Kit Targets Chinese-Based Edge Devices

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

When ‘hacking’ your game becomes a security risk

October 17, 2025

Your information is on the dark web. What happens next?

January 13, 2026

What is it, and how do I get it off my device?

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.