1 in 4 small businesses got hacked last year. Here’s what the 2026 data says about yours.
AI-written phishing emails now get clicked more than half the time, ransomware recovery can run past half a million dollars, and most small business sites are protected by nothing more than a reused password. Here’s what the 2026 numbers actually say about the risk sitting on your login screen.
Ask a small business owner if their website could get hacked, and most will say some version of “why would anyone bother with a site like mine.” It’s a fair assumption, and it’s the wrong one. Most attacks aren’t personal. They’re automated, they don’t care how big you are, and in 2026 a growing share of them are written by AI that never gets tired of trying.
The data backs this up in a way that’s hard to shrug off. Here’s what actually happened to small businesses last year, and what it means for the site you’re running right now.
The numbers are worse than “it won’t happen to me”
1 in 4 small businesses were breached in the past year — and 92% of them already had some kind of security tool in place when it happened. Having antivirus software or a firewall isn’t the same as being protected. It’s one layer, and attackers only need to find the layer that’s missing.
Small businesses aren’t flying under the radar, either. They’re targeted roughly four times more often than larger companies, mostly because attackers know smaller teams are less likely to have someone dedicated to watching for problems.
Most attacks don’t look like “hacking” at all
Forget the movie version of a hack — someone typing furiously to break through a firewall. 79% of detected attacks were malware-free. No virus, no obvious red flag. Just a stolen password, a convincing email, or a phone call that talked someone into handing over access.
That shift is exactly where AI has changed the game. AI-generated phishing emails now get clicked 54% of the time, compared to 12% for the clumsier, human-written kind most people have learned to spot. 46% of small businesses encountered AI-written phishing in the past year, and voice-based scams — a caller impersonating your bank, your host, or “Squarespace support” — grew 442% over the same period. These aren’t obviously fake anymore. They’re well-written, personalized, and built to sound exactly like the real thing.
What it actually costs when it goes wrong
The financial range is wide, but none of it is small. 67% of breached small businesses reported losses between $10,000 and $100,000, and another 14% went over $100,000 once recovery, downtime, and damage control were added up. For context, the average cost of a breach across companies of all sizes — factoring in downtime and reputational damage — has climbed past $4.9 million. Small businesses obviously aren’t absorbing numbers like that, which is exactly why a much smaller hit can still be the one that ends things.
That’s not an exaggeration. 40% of small business owners say a cyberattack costing $100,000 or less would put them out of business entirely — up from 32% who said the same about a $10,000 loss just a year earlier. The threshold for “this could end us” keeps dropping, not rising.
The businesses that get hit rarely saw it coming. They just never got around to the boring stuff — the password, the login list, the two-factor prompt they kept skipping.
What Squarespace actually protects (and what it doesn’t)
If your site runs on Squarespace, some of this is already handled for you. Squarespace manages hosting-level security: SSL/TLS encryption on every site, infrastructure-level protection against denial-of-service attacks, and platform updates you never have to think about. That’s genuinely valuable, and it’s more than most small businesses had ten years ago.
What Squarespace can’t do is protect your account from you. The login screen — your password, who else has access, whether you click the wrong email — sits entirely outside what the platform secures automatically. That’s also exactly where most of the incidents above actually start.
The fixes that actually matter (none of them need a developer)
Every one of these takes minutes, not hours, and together they cover the gap Squarespace leaves open:
Turn on two-factor authentication. Squarespace calls it the best line of defense against unauthorized access, and it’s the single biggest thing on this list. Use a passkey or an authenticator app over a text code if you can.
Stop sharing one login. Add anyone who needs access as their own contributor instead of handing out the same password. Then actually remove contributors once they stop working with you — an old freelancer’s still-active login is a door nobody’s watching.
Use a real password, and change it occasionally. A mix of letters, numbers, and symbols — not your business name plus a birth year. Every few months is a reasonable rhythm, not a paranoid one.
Turn on two-factor authentication everywhere else, too. Your email, your payment processor, and whoever manages your domain name are all connected to your site whether you think of them that way or not. A compromised email is often how someone gets into everything downstream of it.
Slow down on urgent emails. Anything asking you to log in immediately, verify your account, or “avoid suspension” — especially if it sounds like Squarespace, your bank, or your host — is worth a second look before you click. When in doubt, go to the site directly instead of using the link in the email.
None of this requires rebuilding anything or hiring a security firm. It requires about fifteen minutes and the discipline to actually do it this week, not after something happens.
If you’d rather have someone else keep an eye on this permanently, that’s exactly what our monthly care plan is for — ongoing monitoring, updates, and a second set of eyes on your site so this isn’t one more thing on your list. Book a free call if you want us to take a look at where your site actually stands.
Ready to build something real?
Book a free 30-minute discovery call. Tell us about your business. We’ll tell you honestly whether we’re the right fit — and what we’d build for you if we are.
Book a Free Call →