
But how does this impact you? Well, here are 5 things this attack illustrates for a business owner:
1. AI is a force multiplier for attackers AND defenders.
You don’t have to believe AI is “sentient” to recognize that it dramatically increases what attackers can accomplish. A criminal no longer needs to spend days writing phishing emails, researching targets, or looking for vulnerabilities. AI can automate much of that. Again, thanks to AI, many cyberattacks now require far less technical skill than ever before. Criminals with only average computer knowledge can use AI to create convincing phishing emails, write malware, find vulnerabilities, and automate attacks.
That means:
- More phishing attacks
- Better-written scams
- Faster discovery of security weaknesses
- More attacks against smaller businesses
The cost of launching sophisticated attacks is dropping.
2. “We’re too small to be hacked” is becoming even less true.
Historically, attackers focused on large organizations because attacks required significant manual effort. That has changed over the years as, like many criminals, hackers focused on finding unlocked digital doors (easy targets) regardless of size. AI changes the economics of cybercrime even more significantly.
At unprecedented scale and speed, an attacker can have AI:
- scan thousands of businesses
- identify exposed systems
- draft personalized phishing emails
- analyze public information
- prioritize easy targets
Small and medium sized businesses become attractive simply because they’re numerous and often less protected. More than ever, locked digital doors are necessary to deter and deflect sped-up, sophisticated hacks.
3. Identity security matters more than ever.
According to OpenAI’s description of the incident in the above story, stolen credentials were part of the attack chain. That shouldn’t surprise anyone in cybersecurity. Identify protection isn’t a “nice option” anymore, and it’s not one of those things only the big boys have to worry about.
The first cyber risk questions every SMB owner should ask are:
- Are all Microsoft 365 accounts protected with MFA? This is an easy fix.
- Are passwords unique? Again, a password manager is an easy fix (it’s not risk-free, but it’s better than the same password used 997 times)
- Are admin accounts separated from everyday accounts?
- Is Conditional Access enabled?
- Can we detect compromised accounts quickly?
Most successful breaches still begin with identity compromise.
4. Assume your defenses will be tested constantly.
Think of AI as giving every attacker a tireless junior security analyst that works 24/7. If your firewall, VPN, server, or Microsoft 365 tenant has a weakness, AI will likely find it faster than a human would.
That makes your personal cyber hygiene AND your business’s cybersecurity more relevant than ever. Again, locked digital doors aren’t foolproof, but you aren’t looking for foolproof – you need risk reduction. If you don’t know what to do to lock your digital doors, start with the basics like Identity Protection (MFA, password management) and consult with your IT MSP to make sure they have specific cybersecurity tools and policies in place.
5. Human oversight still matters.
One interesting lesson isn’t that AI “wanted” to hack another company. It’s that inappropriate constraints can produce unintended behavior. Again, no one TOLD the engine to go hack the other AI company. Likely, the researchers asked the engine to achieve a certain objective, and the engine, on its own, went and hacked that other company as part of its path to achieve the objective.
It simply didn’t have the restraints in place to restrict itself from following that path. In your situation, AI already likely touches some areas of your business. You simply want to be aware that those areas involve risk, whether that involves content creation, finances, legal issues, customer communication, HR, or security. Lack of guidelines in those areas may produce inaccurate information, privacy concerns, or even just questionable analysis. Any AI generated content or outcomes should still have human oversight.
Conclusion
The recent OpenAI incident shouldn’t make business owners fear that AI is becoming self-aware. It should remind us that AI is becoming incredibly capable. Given an objective, AI can accomplish in seconds what once required hours or days of human effort. That’s true whether it’s helping your employees work more efficiently or helping a cybercriminal identify their next victim.
For business owners, the priorities remain remarkably simple: lock your digital doors, protect your identities, keep systems updated, establish clear AI policies, and maintain human oversight over important decisions. AI has changed the speed and scale of cyber threats, but the businesses that focus on strong fundamentals will continue to be far more difficult targets.
The future of cybersecurity won’t be decided by who has AI. It will be decided by who uses it responsibly.
