Small businesses make up 96% of ransomware victims. Is your Salesforce part of the problem?

By Intelligent Solutions LLC · · 2 min read

Small businesses make up 96% of ransomware victims. Is your Salesforce part of the problem?

The 2026 Verizon Data Breach Investigations Report is out, and one number stands out: SMBs accounted for 96% of all ransomware victims with known victim size. Not 96% of a niche category — 96% of every confirmed ransomware victim. Attackers know where the easy targets are, and they're not wasting time on the Fortune 500.

The reason is straightforward. Small businesses tend to have unpatched systems, limited recovery resources, and teams that haven't been trained to recognize the warning signs. That combination makes them the path of least resistance.

How the attacks actually happen

The DBIR identifies three breach patterns that collectively account for 100% of SMB incidents: system intrusion through exploited edge devices, basic web application attacks using compromised credentials, and social engineering. The human element — phishing, pretexting, manipulation — drives 62% of incidents industry-wide. Third-party involvement shows up in 55% of SMB breaches, meaning many small businesses are compromised through a vendor or software tool they trusted, not through a direct attack on their own network.

None of these require sophisticated exploits. They require an undertrained employee, a weak password, or a connected app with more access than it needs.

What this means for your Salesforce

Salesforce is a web application that runs entirely on credentials — which puts it squarely in two of the three breach patterns above. Compromised credentials get into Salesforce when MFA isn't enforced for every user. Social engineering works when your team hasn't been trained to spot a suspicious login request. Third-party exposure happens when a connected integration has broader permissions than it should.

These aren't edge cases. They're the exact patterns the DBIR is documenting, playing out against businesses like yours right now.

Four things you can do right now

You don't need a security team to close the most common gaps. Start here:

  • Enforce MFA on every profile — no exceptions. Compromised credentials are the entry point for a huge share of web application attacks. Turning MFA on for most users but not all is the same as not having it.
  • Audit your connected apps. Go to Setup → Connected Apps and look at what has access to your org. Remove anything your team no longer uses, and tighten OAuth scopes on everything that remains. Third-party exposure accounts for 55% of SMB breaches — this is where it starts.
  • Disable departed employees immediately. Former employee logins are one of the most overlooked attack surfaces in Salesforce. Make deactivation a standard part of your offboarding checklist, not an afterthought.
  • Train your team to recognize phishing. The human element drives 62% of incidents. A 30-minute session on what suspicious emails and login requests look like is more effective than most technical controls you can put in place.

If you want to go deeper

At Intelligent Solutions, we audit both the technical setup and the people using it — finding the gaps that aren't obvious until something goes wrong. Security isn't a one-time configuration, and most teams don't know what they're missing until we show them.

Book a free audit and we'll give you a clear picture of where your Salesforce stands against the breach patterns the 2026 DBIR identified.

Sources