Why individuals and small businesses are targets
By the end of this lesson
Explain why individuals and small businesses are targeted online, and what attackers want.
Last reviewed: October 3, 2026 General information, not legal or tax advice.
Many people think, "Nobody would bother hacking me. I'm too small." Criminals think the opposite. Small businesses and ordinary people are attractive precisely because they usually have weaker protection than banks and big companies, and most attacks are automated: a program sends the same scam to thousands of people and waits for someone to fall for it.
What attackers want
- Money: your banking login, card details, or a payment you are tricked into making to the wrong account.
- Accounts: your email, WhatsApp or social media, to scam your contacts or customers in your name.
- Information: customer lists, ID numbers and contact details to sell or use for fraud.
- Your devices: to use your computer's power, or to lock your files and demand payment (ransomware).
- Your phone number: in a SIM swap, criminals move your number to their SIM to receive your one-time PINs.
How most attacks actually happen
Very few attacks involve a genius hacker breaking through clever defences. Most rely on:
- Tricking a person into clicking a link, sharing a PIN or making a payment (lesson 3).
- Weak or reused passwords that criminals already have from other data leaks (lesson 2).
- Out-of-date software with known holes that have already been fixed in an update (lesson 4).
- Lost or stolen devices with no screen lock or backup (lesson 4).
- Unsafe Wi-Fi and payments (lesson 5).
The good news: the same small set of habits blocks most of these.
The cost for a small business
An attack can mean money stolen from your account, days without access to your email or WhatsApp, lost customer records, and customers who stop trusting you. If customers' personal information is exposed, you also have legal duties under POPIA (lesson 6).
Security is a habit, not a product
Antivirus and backups help, but no product protects someone who reads a PIN aloud to a "bank official" on the phone. The rest of this course is about habits: strong sign-ins, recognising scams, keeping devices updated and backed up, and knowing exactly what to do if something goes wrong.
A South African example
A small travel agency in Pietermaritzburg believed it was too small to interest criminals. A staff member's email password, reused from a shopping site that had been breached, let criminals into the agency's inbox. They watched for a week, then sent a client a convincing invoice with "updated banking details". The client paid the criminals. Two habits would have stopped it: a unique password with two-factor authentication, and a rule that banking details are never changed by email alone.
Do it now
List the five accounts and devices that would hurt most if someone else got into them (for example your banking app, email, WhatsApp, business phone and laptop). You will protect these first in the next lessons.
Track your progress
Log in or create a free account to take the knowledge check and save your progress.
Log in