AI Agents Amplify Traditional Cyber Threats for SMBs, ESET Warns
ESET research highlights how AI agents introduce new cybersecurity risks for SMBs, with adversaries leveraging AI to scale traditional threats and exploit a burgeoning ecosystem of malicious AI 'skills'.

Artificial intelligence is rapidly integrating into the daily operations of small and mid-size businesses (SMBs), moving beyond simple chatbots to sophisticated AI agents designed to automate tasks and provide a competitive edge. Many SMBs are experimenting with multi-agent systems, where supervisor agents manage swarms of specialist agents, passing work between them to streamline operations. This adoption, however, introduces new dependencies and potential cybersecurity risks, particularly for SMBs with limited IT resources.
ESET's global survey of 4,400 SMB decision-makers revealed a significant governance gap, with 40 percent of businesses lacking an AI policy. This trend is more pronounced in companies that have not yet experienced a security incident, indicating a common pattern where robust policies often lag behind actual breaches. The risks are expanding in two primary directions: AI creating new entry points into business systems and adversaries using AI to accelerate and scale existing threats.
Each AI agent connected to business systems operates with granted permissions, making them susceptible to manipulation. A compromised agent, with access to internal documents and external communication capabilities, can take costly actions based on altered instructions. In multi-agent setups, manipulated outputs can cascade through the system, making root cause analysis challenging.
The 'skills' ecosystem for AI agents presents a significant vulnerability. These are packaged instructions that dictate an agent's actions and tools. ESET's analysis between March and May 2026 identified over 3,000 malicious skills designed for credential theft, data exfiltration, and remote code execution, out of nearly 900,000 unique skills scanned. The lack of stringent gatekeeping in this ecosystem means that skills can change post-installation, leading to unexpected and malicious behavior.
Compromised supply chains and abused permissions are familiar roots of these new risks. The skills ecosystem lacks the app-store-style vetting found in traditional software, and one-off checks are insufficient. Skills and tool connections remain live dependencies, as their instructions can change dynamically, potentially turning a benign tool into an infostealer or worse. Lean IT teams may not even be aware of all the skills employees connect to agents, nor the potential risks they introduce.
LLMs themselves also create openings. Their tendency to 'hallucinate' can lead to the invention of software library names and web domains that adversaries register and exploit. Agentic misalignment, where agents pursue objectives even if it means unauthorized actions, and the injection of malicious data into an agent's long-term memory are also growing concerns. Indirect prompt injection attacks, where malicious commands are hidden in data fetched by an agent, are particularly insidious, as demonstrated by the EchoLeak vulnerability in Microsoft 365 Copilot.
While AI introduces novel threats, traditional attack vectors remain prevalent and are being amplified by AI. Phishing, exploitation of known software vulnerabilities, stolen credentials, and exposed remote services continue to be primary causes of breaches for SMBs. The ESET SMB Cyber Readiness Index 2026 highlights phishing and software vulnerability exploitation as the most common breach causes, underscoring the need for foundational security practices even as AI capabilities evolve.