1. What you will learn
Before choosing controls, you need a realistic picture of who attacks businesses like yours and how. This lesson surveys the main threats facing Indian small and mid-sized enterprises. You will learn to:
- describe the main threat actor types and their motives;
- explain how ransomware, business e-mail compromise, payment fraud, malware and insider threats work;
- recognise the stages of a typical attack using the idea of an attack chain;
- match threats to your own business profile so that later risk assessment is grounded.
2. The idea explained
Threat actors and motives
- Financially motivated criminals are the largest group affecting small businesses. They want money directly (fraudulent transfers, ransom) or indirectly (selling stolen data or access). Many operate as organised groups offering ransomware-as-a-service, where developers rent tools to affiliates.
- Opportunistic attackers use automated scanning to find any exposed, unpatched system or weak password. They do not choose you by name; they find you by weakness.
- Insiders are current or former employees, contractors or partners who misuse legitimate access, deliberately or through carelessness.
- Competitors or disgruntled parties may seek customer lists, pricing or designs.
- Hacktivists deface websites or leak data for a cause; state-linked actors mainly target government, defence and critical sectors, though suppliers to those sectors can be caught up.
Major threat types
Phishing and social engineering. Social engineering manipulates people into doing something harmful: clicking a link, opening an attachment, revealing a password or OTP, or making a payment. Phishing uses e-mail; smishing uses SMS; vishing uses voice calls; messaging-app scams follow the same pattern. It is the most common entry point for other attacks.
Business e-mail compromise (BEC). An attacker either takes over a genuine business e-mail account or impersonates it with a look-alike domain, then sends convincing instructions: "Our bank account has changed, please pay this invoice to the new account", or "I am in a meeting, transfer this amount urgently". Losses can be large because payments go through normal banking channels and are authorised by the victim's own staff.
Ransomware. Malicious software that encrypts files and systems, followed by a ransom demand. Modern groups also practise double extortion: stealing data before encrypting it and threatening to publish it. Entry is usually through phishing, stolen remote-access credentials, or an unpatched internet-facing system.
Malware in general. Includes information stealers that harvest saved browser passwords and session cookies, trojans disguised as useful software (often cracked or pirated software), keyloggers and remote-access tools.
Payment and UPI fraud. Fake payment screenshots, "collect request" tricks where the victim approves a debit believing they are receiving money, QR code swaps at shop counters, and fraudulent calls posing as bank or courier staff.
Account takeover. Attackers use leaked or guessed passwords to take over e-mail, social media business pages, marketplace seller accounts or cloud storage.
Website and application attacks. Exploiting outdated content management system plug-ins, weak admin passwords or insecure code to deface a site, plant malicious scripts or steal customer data.
Insider data theft and error. Staff copying customer lists before leaving, or sending files to the wrong recipient.
Supply chain attacks. Compromise of a vendor that has access to your systems: an IT support provider's remote tool, a compromised software update, or an accounting firm whose e-mail is hacked and used to send fake invoices to its clients.
The attack chain
Security writers often describe attacks as a sequence of stages, such as the cyber kill chain: reconnaissance, weaponisation, delivery, exploitation, installation, command and control, and actions on objectives. For a small business, a simplified version is enough:
- Reconnaissance — the attacker learns names, e-mail formats and suppliers from websites and social media.
- Initial access — phishing, stolen password, exposed remote desktop, or unpatched system.
- Establishing control — installing tools, creating accounts, setting e-mail forwarding rules.
- Expansion — moving to other systems, finding backups and financial data.
- Impact — fraud, encryption, data theft or publication.
The value of this model is that every stage is a chance to stop the attack. MFA blocks initial access through stolen passwords; alerts on new forwarding rules detect establishing control; separated, offline backups limit impact.
3. Let us work through it
Step 1 — Describe your business profile. Sector, size, how payments are made and received, what data you hold, whether you have a website or online store, remote working, and major vendors.
Step 2 — Match threats to the profile. A business making frequent supplier payments is exposed to BEC; one with an online store is exposed to website attacks and payment fraud; one with remote staff is exposed to account takeover.
Step 3 — Identify likely entry points for each threat in your environment: which e-mail accounts, which remote-access tools, which internet-facing systems.
Step 4 — Walk the attack chain for your top two threats, noting where you could currently stop the attacker, and where you could not.
Step 5 — Record the top five threats with a one-line description of how each would hit your business. These feed directly into the risk register in the next lesson.
Worked example
4. Worked examples
Example 1 — BEC at an engineering supplier. A supplier in Coimbatore receives an e-mail that appears to come from its regular steel vendor, stating new bank details for pending invoices. The domain differs by one letter. The accounts clerk updates the bank details and pays. Attack chain: reconnaissance (the attacker knew the vendor and invoice cycle, probably from a compromised mailbox at the vendor), delivery (look-alike domain e-mail), impact (payment diverted). Points where it could have been stopped: a policy of verifying any bank detail change by calling a known number; e-mail filtering that flags look-alike domains.
Example 2 — Ransomware through remote desktop. A diagnostic lab exposed a computer to the internet using remote desktop with a weak password so the owner could work from home. Attackers guessed the password, disabled antivirus, found the backup drive attached to the same network and encrypted everything. Entry: exposed remote access with weak authentication. Expansion: reached the backup. Controls missing: MFA or a secure remote-access method, and an offline backup.
Example 3 — Information stealer from pirated software. An employee at a marketing agency installs a cracked video editing tool. It contains an information stealer that captures saved browser passwords and session cookies, including the agency's social media manager logins. Days later, a client's Instagram page is taken over. Lesson: a single unlicensed download can compromise accounts even where passwords are strong, because stolen session cookies can bypass login.
Example 4 — UPI collect-request fraud at a shop. A caller claiming to be a bulk buyer says he will send an advance, and asks the shop owner to "approve" a request to receive it. Approving a collect request actually authorises a debit. The control here is knowledge: in UPI, you never need to enter your PIN to receive money.
5. Common mistakes and how to fix them
- Assuming attackers only pursue large firms. Fix: recognise opportunistic and automated attacks that target weakness, not size.
- Focusing on exotic threats. Fix: prioritise phishing, BEC, ransomware and account takeover first.
- Trusting e-mails because they look familiar. Fix: verify payment instructions through a separate, known channel.
- Allowing pirated or unknown software. Fix: permit only licensed software from official sources.
- Ignoring vendors as a route of attack. Fix: include suppliers and IT providers in your threat thinking.
- Believing that entering a UPI PIN can receive money. Fix: remember a PIN is only needed to pay.
Key takeaways
6. Board summary
Most attacks on small firms are financial and opportunistic. Phishing is the commonest door; BEC and ransomware are the costliest outcomes. Double extortion: steal the data, then encrypt it. Attack chain: reconnaissance, access, control, expansion, impact. Every stage is a chance to stop the attacker. Match threats to your own business profile before choosing controls.
Check your understanding
7. Practice and self-check
- What is business e-mail compromise?
Answer: An attack that uses a compromised or impersonated business e-mail account to trick staff into payments or actions.
- What is double extortion in ransomware?
Answer: Stealing data before encrypting systems and threatening to publish it as well as withholding decryption.
- What is ransomware-as-a-service?
Answer: A model in which ransomware developers rent their tools to affiliates who carry out attacks.
- Name three social engineering channels.
Answer: E-mail (phishing), SMS (smishing) and voice calls (vishing).
- How can pirated software lead to account takeover?
Answer: It may contain information stealers that capture saved passwords and session cookies.
- Why is an internet-exposed remote desktop dangerous?
Answer: Attackers scan for it and guess or reuse passwords to gain direct access.
- Give the five stages of the simplified attack chain.
Answer: Reconnaissance, initial access, establishing control, expansion and impact.
- Do you need to enter a UPI PIN to receive money?
Answer: No, a UPI PIN is needed only to make a payment.
- What simple control stops most bank-detail-change frauds?
Answer: Verifying any change by calling the vendor on a known, previously recorded number.
- What is a supply chain attack?
Answer: An attack that reaches a business through a compromised vendor, software update or service provider.