For years, small and mid-sized businesses got away with a comfortable assumption: the attackers capable of real damage, the ones who could find a zero-day, write custom malware, or breach a well-defended network, needed serious resources. A state budget. A trained team. Months of runway.

That assumption doesn’t hold anymore, and the evidence for why is uncomfortably specific.

What actually happened

Anthropic’s September 2026 threat intelligence report disclosed a case involving a financially motivated group affiliated with the ShinyHunters collective. Using AI agents, the group downloaded and decompiled 1.8 million Android apps, scanning the code for hardcoded secrets: API keys, credentials, and tokens developers had accidentally left in plain sight.

The scale isn’t even the part that should worry you. It’s the speed. In one documented case, the group went from initial access to full administrative control of a target’s systems in about three hours. One compromise alone pulled over a terabyte of data out the door. The stolen AI API keys were then reused to fund further attacks, a self-financing loop of compromise that never needed a human to slow it down.

None of that required a nation-state budget. It required an agent, a task list, and time.

Why the old math stopped working

The old risk model was crude but functional: attackers with real skill went after large, valuable targets, and smaller businesses got ignored simply because they weren’t worth a skilled human’s time.

AI took that filter away. An agent doesn’t get bored decompiling app number 1.7 million. It doesn’t care whether the next target is a multinational or a 40-person company, because checking one more costs it almost nothing. The report’s own phrase says it plainly: sophisticated attacks no longer require sophisticated attackers.

For a lot of businesses here in Nigeria, the ones that have quietly told themselves “we’ll deal with security once we’re bigger,” this is the moment that logic runs out.

What actually reduces this risk

Nothing about the fix is exotic. It’s the same fundamentals that have always mattered, just newly urgent.

Hardcoded secrets sitting in app code and repositories need to be found and rotated before an automated scan finds them first. Multi-factor authentication should be non-negotiable, so a leaked password alone doesn’t open the door. Short-lived, narrowly scoped API keys beat long-lived ones, since a stolen key does far less damage if it expires quickly. And a real posture review tells you where you’re exposed today, instead of leaving it to guesswork.

Where GressTech fits in

We built our cybersecurity consulting and posture review service around this exact gap. We look at your systems the way an automated attacker would, methodically, without assuming anything is too small to matter, and hand you a clear, prioritized list of what to fix first.

Good software should be invisible. A breach shouldn’t be the reason it becomes visible.

Ready to know where you actually stand? Book a posture review with GressTech Solutions before an AI agent finds out for you.


Source: Anthropic Threat Intelligence Report, September 2026