Picture a burglar standing in front of a locked door. He could painstakingly pick the lock, or he could just buy the matching key for a few euros. In the digital world, the second option has long been the norm. The romantic image of a hacker writing complex code through the night to break through firewalls no longer matches the economic reality of cybercrime.
An industrialized trade in credentials
Internal analyses by Baobab Risk Solutions for a current data breach report show a clear pattern: 91 percent of the analyzed data leaks contain passwords in plain text, immediately readable and ready to use. That makes initial access to a company trivial and cost-efficient. How industrialized this trade has become is illustrated by one observed Telegram channel: for a monthly subscription of around 250 US dollars, buyers get daily access to thousands of freshly stolen data records.
Independent data confirms this finding. According to the Verizon 2025 Data Breach Investigations Report, stolen credentials remain the most common initial attack vector, responsible for 22 percent of all breaches examined. In attacks on simple web applications, stolen credentials were used in as many as 88 percent of cases. Once you've ended up in the relevant dark web data collections, you stay marked as a target for years: according to Baobab, the duplication rate sits at around 88.7 percent, meaning the same stolen records keep resurfacing in new collections and get deployed against networks automatically. The main driver of this trend is info-stealer malware, which quietly extracts credentials directly from browsers, password managers, or active sessions. The attack strategy is therefore shifting away from single, massive server hacks toward scaling through thousands of small info-stealer infections, a trend in which password complexity becomes secondary the moment a password is up for sale in plain text.
"We're too small to be a target" is a dangerous fallacy
Leadership at smaller companies often clings to the assumption that they're not interesting to attackers. Yet according to Germany's BSI 2025 IT security report, around 80 percent of reported ransomware attacks targeted small and mid-sized businesses, which often lack the resources and knowledge to protect themselves. According to the BSI, SMBs meet only about 56 percent of basic IT security requirements on average and routinely overestimate their own level of protection.
A shift in perspective matters here: attackers don't measure a target's attractiveness by revenue, but by the volume of personal data it holds. Already 31 percent of all companies with less than 5 million euros in annual revenue manage more than 10,000 personal data records, and eleven percent of small businesses even hold between 100,000 and 500,000 records. If attackers do find their way into the system, the economic consequences are considerable: a single stolen record costs a company an average of around 134 euros, made up of first-party costs like incident response, forensics, crisis communication, fines, and legal advice, as well as third-party costs such as litigation from affected parties. If a mid-sized company loses 10,000 records, the theoretical damage already adds up to 1.34 million euros, an existentially threatening sum for many SMBs.
People remain the primary target
As much attention as the technical attack surface gets, the costliest damage often occurs elsewhere. Analysis of real claims shows that technical hacks are rarely the direct cause of financial losses; in most cases, people play the decisive role. First-party losses, such as those from phishing, make up the largest share at 39 percent, closely followed by business email compromise at 37 percent. Classic ransomware trails well behind at nine percent.
These figures gain urgency against the backdrop of a recent development: according to the ENISA Threat Landscape 2025, more than 80 percent of social engineering activity observed worldwide was already AI-assisted by early 2025. Phishing remains the dominant vector for initial access at 60 percent, and AI-generated messages are now barely distinguishable from genuine correspondence. Raising staff awareness alone is therefore no longer enough.
Three levers that make the difference
The good news: most attacks aren't highly sophisticated, they're opportunistic. Anyone who blocks the path of least resistance falls outside the net of automated mass attacks, and that doesn't take a digital fortress, just three consistently applied practices.
The most effective lever is multi-factor authentication. It ensures a login only succeeds when a second, personal factor is provided alongside the password, so even a stolen password fails at this hurdle. This is exactly where the biggest gap sits among SMBs: according to Baobab's data, 53 percent of companies with less than five million euros in revenue operate entirely without MFA, and it only becomes standard once revenue passes 50 million euros.
The second lever concerns detection. Since AI-assisted phishing keeps making deception more realistic, awareness alone isn't enough; continuous monitoring of internet-exposed systems is what counts. Around 75 percent of critical threat activity concentrates in just two areas: the network perimeter, covering VPNs and firewalls, and collaboration tools like email. Outdated VPN gateways or unpatched servers act like open windows on the ground floor. Smaller organizations show critical vulnerabilities at a rate of 12.7 percent, twice that of large enterprises at 6.23 percent, largely a matter of missing patch discipline.
The third lever is a verified backup. An untested backup isn't a security measure, it's a vague hope, a mistake that trips up even larger companies: 21 percent of large enterprises don't regularly test full restoration. Yet an analysis of 245 real ransomware cases shows that around 77 percent of affected companies didn't pay a ransom because working backups and professional incident response kicked in. And even where negotiations happened, the initial demand was almost never the final price; on average, it could be reduced by 51 percent.
Turning hygiene into routine
Companies aren't helpless against this risk. Because the overwhelming majority of attacks are opportunistic and rely on cheaply acquired identities, the danger can be drastically reduced through basic hygiene. In practice, that means rolling out MFA across the board, across every access point from VPN logins to email inboxes, not as a project with an end date but as the default configuration for every new account. Monitoring externally exposed systems becomes a fixed part of the operating rhythm, ideally tied to a clearly documented patching process. And the annual restore test belongs on the calendar just as much as the tax return. None of these measures requires a dedicated security operations center, what they require above all is commitment. Anyone who locks the obvious doors becomes simply too expensive for an automated attacker, who moves on.