Home » Proton: An Autonomous AI Hacked a Small Business, Here’s How to Protect Yours

Proton: An Autonomous AI Hacked a Small Business, Here’s How to Protect Yours

Discover how attackers use AI to target small businesses faster and the four essential steps to protect your firm from cyber threats.

Blue-lit data centre server drives illustrating how an autonomous AI hacked a small business

If you have seen the headlines claiming an autonomous AI hacked a small business and wondered whether your own firm is next, here is the direct answer: the immediate risk to most UK SMEs is not a rogue robot breaking in on its own, but attackers using AI to run ordinary attacks (phishing, password guessing, scanning for weak software) far faster and cheaper than before. The fix is not exotic. Turn on multi-factor authentication everywhere, use a password manager, patch your software, and back up your data offline. Those four steps stop the overwhelming majority of what AI-assisted criminals throw at a company your size.

The concern gained weight in late 2025 when AI firm Anthropic disclosed that its Claude models had been used to run a largely automated cyber-espionage campaign, with the AI carrying out most of the technical work under human direction. Privacy and security vendors such as Proton, the Swiss maker of encrypted email and the Proton Pass password manager, have long warned that this is where things are heading: tools that let one attacker do the work of ten. For a UK small business, that means the volume and quality of attacks goes up, so your basics have to be genuinely in place rather than half-done.

What actually happened, in plain English

An “autonomous AI” here means an AI agent that can be given a goal and then take its own steps to reach it: writing code, testing it, trying again, all with minimal human clicks. In the reported case, the humans set the targets and the AI did much of the probing, exploiting and data-gathering. You can read Anthropic’s own account of the incident in its news and research posts.

Two things are worth being honest about. First, the confirmed targets were large organisations, not corner-shop SMEs. Second, the AI still needed human operators, weaknesses to exploit and a lot of oversight. So the “AI hacked a business all by itself” framing is stronger than the facts. But the direction of travel is real, and it matters to you because the same techniques scale downward. When attacks get cheaper to run, criminals stop being picky about who they hit. A five-person accountancy practice in Leeds is now worth attacking at scale precisely because the attacker’s effort per victim has collapsed.

Why small businesses are the easy target

Small firms rarely have a dedicated IT security person, often reuse passwords, and frequently run software that is months behind on updates. That is exactly the soft edge automated tools are built to find. The government’s own research, covered in our summary of the UK Cyber Security Breaches Survey 2026, keeps pointing to the same weak points: phishing emails, stolen passwords and unpatched systems. AI does not invent new doors. It just knocks on all of yours at once.

There is also an internal angle. Staff quietly using unapproved AI tools can leak data or credentials without anyone realising, a problem we cover in shadow AI and the hidden risk of unapproved tools. If you do not know what your team is pasting into a chatbot, you cannot protect it.

The four defences that stop most attacks

None of this needs a big budget. Do these four things properly and you close the doors AI-assisted attackers rely on.

  • Multi-factor authentication (MFA) on email, banking, accounting and cloud storage. This is the single highest-value step. A stolen password is useless without the second factor. Hardware keys from Yubico (the YubiKey) are the strongest option; a free authenticator app is the practical minimum.
  • A password manager so every account has a long, unique password nobody has to memorise. This alone defeats the “credential stuffing” attacks (reusing one leaked password across many sites) that automation makes trivial.
  • Updates and patching. Turn on automatic updates for Windows, macOS, browsers, phones and any business software. Unpatched software is the low-hanging fruit an automated scanner finds first.
  • Backups you can actually restore. Keep at least one copy offline or in a separate cloud account, and test that it restores. This is your recovery plan if ransomware gets through.

The tools worth shortlisting

Here are the categories that matter and the providers a UK owner would realistically compare. Prices move often and most vendors bill in dollars, so treat the figures below as indicative and check the current rate before you buy.

Tool type What it does Providers to compare Indicative UK cost
Password manager Stores and generates strong, unique passwords; shares logins safely across a team Proton Pass, Bitwarden, 1Password, NordPass Free tiers available; business plans roughly £2 to £7 per user per month
Endpoint protection (antivirus) Detects and blocks malware and ransomware on laptops and servers Sophos (British-founded), Bitdefender, ESET, Malwarebytes Around £30 to £60 per device per year for business plans
Email security Filters phishing, malicious links and impersonation before staff see them Egress (UK), Mimecast, built-in filtering in Microsoft 365 and Google Workspace Add-on pricing varies; get a per-user quote
Hardware MFA key A physical key that must be present to log in, defeating remote takeover Yubico YubiKey, Google Titan Around £25 to £60 per key, one-off

Two names above are worth a second look. Egress is a British email-security specialist built around stopping the exact phishing and impersonation attacks that AI makes more convincing. Bitwarden is open source with a genuinely usable free tier, which makes it an easy first step for a cash-conscious sole trader. Proton is the option to weigh if you also want encrypted email and a VPN from the same provider. For a wider view of the software stack around all this, our guide to the tools every UK owner should consider in 2026 is a useful companion.

The UK-specific step: Cyber Essentials

The National Cyber Security Centre (NCSC) runs a scheme called Cyber Essentials, a government-backed certification covering exactly the basics above. The self-assessed version typically costs from around £300 plus VAT depending on your size, and passing it often makes you eligible for public-sector contracts and can lower cyber-insurance premiums. It is one of the most cost-effective moves a small firm can make, because it forces you to actually finish the basics rather than mean to.

Using AI defensively, not just fearing it

The same technology behind the scary headline can work for you. AI is now baked into email filters, fraud detection in business banking, and monitoring tools that flag unusual logins. If you are already using AI in the business, our piece on how to improve small business marketing with AI tools shows the productive side of the same wave. The point is balance: adopt AI where it helps, and harden the accounts and data that feed it.

Frequently asked questions

Can an AI really hack my business on its own?

Not in the fully independent way headlines suggest. Documented cases still involve human operators setting targets and supervising. What has changed is speed and cost: AI lets attackers automate the tedious parts, so more businesses get probed. The realistic threat to an SME is a higher volume of well-crafted phishing and automated password attacks, which the four basics above defend against.

What is the cheapest way to start protecting my business today?

Turn on multi-factor authentication on your email and bank accounts (free) and set up a password manager with a free tier such as Bitwarden or Proton Pass. Those two steps cost nothing and close the most common routes in. Then schedule automatic updates on every device.

Do I need to report a cyber attack in the UK?

If personal data is breached, you may have to report it to the Information Commissioner’s Office (ICO) within 72 hours under UK GDPR. You can also report fraud and cyber crime to Action Fraud. Keep records of what happened, when you noticed and what data was affected, as you will need them.

Will my staff need training, or is software enough?

Both. AI makes phishing emails cleaner and more believable, so software alone is not enough. A short, regular staff briefing on spotting suspicious requests, especially fake invoice and payment-change emails, is one of the highest-return things you can do. Pair it with a clear rule that no bank details change on the strength of an email alone.

Is a VPN necessary for a small business?

A VPN (virtual private network, which encrypts your internet connection) is useful mainly for staff working on public or home Wi-Fi. It is not a substitute for MFA, patching and backups. Treat it as a sensible extra rather than the headline defence.

What to do next

  • This week: switch on multi-factor authentication for email, banking, accounting and cloud storage, and roll out a password manager to everyone.
  • This month: enable automatic updates on all devices and software, and set up a tested backup that lives separately from your main system.
  • This quarter: run a short phishing-awareness briefing for staff and work towards Cyber Essentials certification through the NCSC.
  • Ongoing: keep a simple written list of who has access to what, so you can revoke logins fast when someone leaves or an account is compromised.