The cybersecurity landscape for small and medium-sized businesses has undergone a radical transformation in 2025, as hackers increasingly exploit the mass adoption of AI and collaboration tools to execute sophisticated attacks.
See also: Hackers abuse Microsoft ClickOnce and AWS for attacks

The emergence of AI-powered platforms such as ChatGPT and DeepSeek, combined with the continued reliance on remote collaboration tools, has created an unprecedented opportunity for malicious actors to leverage well-known and trusted brands to mislead unsuspecting business users.
These attacks mark a fundamental shift in how cybercriminals approach their targets, moving away from traditional phishing tactics and exploiting the trust users place in key business applications.
From January to April 2025 alone, approximately 8,500 users from small and medium-sized businesses fell victim to cyberattacks, where malicious or potentially unwanted software was disguised as legitimate business tools.
This alarming statistic highlights the ever-increasing sophistication of cybercriminals, who have recognized that SMEs often lack the robust security infrastructure that larger businesses have, making them attractive targets for opportunistic attacks as well as organized criminal networks.
See also: Citrix: NetScaler vulnerability used for DoS attacks
The use of popular business applications as an attack tool is a methodical strategy that aims to exploit the relationship of trust between users and the tools they rely on daily for their productivity and communication.

Securelist analysts have identified a significant development in the threat landscape, noting that attackers have strategically shifted to exploiting the AI explosion that is now sweeping the business world.
The research revealed that malicious files pretending to be ChatGPT saw an impressive 115%, with 177 unique files detected in the first four months of 2025, representing a 3 percentage point increase in the overall threat distribution.
This sharp rise reflects the rapid integration of AI tools into business workflows and the corresponding opportunity for cybercriminals to exploit users’ familiarity and trust in these emerging technologies.
See also: US Homeland Security: Warns of attacks by Iranian hackers
Based on the above, it is now clear that the spread of artificial intelligence is not only accompanied by innovation and ease of work, but also by new, more sophisticated cyber threats. Cybercriminals are quickly adapting to technological developments, creating attacks that exploit precisely the tools in which users have the most trust — such as AI platforms and collaboration applications.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
