Ransomware at SMBtech

Why ‘Spot The Typo’ Is No Longer A Viable Cyber Security Strategy For Aussie SMBs

Surprisingly Useful AI Article Enhancements

For years, we’ve been telling Australian businesses that they can spot a scam if they just look hard enough, for example they can take a closer look at spelling, inspecting the logo and looking for major red flags. It was decent advice in previous years, but today, it’s a dangerous distraction. The reality is that the obvious scam has evolved. If your cyber security strategy relies on your staff acting as human scanners to catch a manual mistake, you’ve already lost the battle.

The New Economics Of Deception

Historically, an attacker’s greatest hurdle was human error. AI has removed that friction, designing today’s lures to bypass the very visual checks we’ve spent a decade teaching our teams to rely on. Today, Australian businesses are no longer up against lone actors with poor grammar but are faced with precision-engineered, high-fidelity deception at an industrial scale.

According to Kaseya’s 2026 INKY Email Security Report, we’ve entered a new era where polished, context-aware attacks are the norm. 83 per cent of phishing emails now include AI-generated or AI-assisted content, and these campaigns are significantly more effective than the generic attacks we’ve seen before.

This fundamentally shifts the economics of cybercrime. In the past, an attacker needed a specific set of skills, including design, native-level fluency and, most importantly, time. Generative AI provides all of that instantly. It has removed the traditional trade-off between scale and realism. Attackers are now hitting thousands of targets with highly tailored, professional-grade messages at volume that look as legitimate as any internal updates.

This is why watching out for bad grammar has moved from a helpful tip to a dangerous liability. It builds a false sense of security. If your staff is conditioned to look for spelling mistakes as their primary defence, you are essentially training them to trust any email that’s well-written.

Beyond The Inbox

Modern phishing has also moved past suspicious links into the daily rhythm of work. We are seeing a surge in attacks that use trusted infrastructure and impersonate brands that people interact with every day. In the second half of 2025 alone, Kaseya detected more than 6.6 million brand impersonation emails, spanning 281 different brands, with Microsoft being the most impersonated.

We’re also seeing the rise of no-payload phishing. Attackers are bypassing automated filters by omitting links entirely, opting instead for QR codes or hiding malicious invites inside calendar notifications. Because these appear in a trusted context, like a scheduled meeting, they bypass the scepticism we’ve spent years building.

For an Australian SMB, this creates a direct business risk. Our report shows that 82 per cent of ransomware attacks now target organisations with fewer than 1,000 employees. For many smaller businesses, a single incident is not just disruptive but existential. The median loss following a business email compromise event is US$50,000, and 60 per cent of small businesses close within six months of a cyberattack.

The Path Forward

To navigate this shift, organisations must move beyond visual inspection toward AI-driven contextual verification. Because the human firewall was never designed to compete with industrial-scale AI, we have to stop blaming careless clicks and instead address the systemic gaps in legacy cyber strategies.

On a technical level, resilience in 2026 requires businesses – particularly SMBs – to prioritise modern security stacks that evaluate intent and behaviour rather than just hunting for bad indicators. By deploying AI to fight AI, companies can detect operational anomalies in real-time and ensure that high-risk requests, such as urgent payments or credential resets, are met with automated, second-channel validation.

Ultimately, the path forward lies in replacing legacy thinking with technical infrastructure that guarantees business continuity. Resilience in 2026 is no longer about spotting visual red flags, but about deploying the right tools to intercept underlying intent. By modernising these strategies and leveraging AI-driven defences, organisations can protect their bottom line and remain secure against an increasingly adaptive threat landscape.

Daniel Garcia is Vice President and General Manager for APAC, Kaseya.

Last Updated on April 17, 2026 by Daniel Garcia

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.