KSG-ADV-2026-005 Critical
Pay or We Publish: What Small Businesses Need to Know About Data Theft and Extortion

AI has made data theft and extortion attacks faster, cheaper, and accessible to operators who previously lacked the skills to conduct them. Small businesses are now viable targets. The complete attack lifecycle — from credential theft to pay-or-leak demand.

Read advisory →
September 2026
KSG-ADV-2026-001 High
Protecting Your AI API Keys: What Small Businesses Need to Know About Credential Theft

Organised criminal groups are systematically stealing AI API keys from small businesses — then using those credentials to run attack operations at the victim's expense. One group downloaded 1.8 million apps specifically to scan for exposed keys.

Read advisory →
September 2026
KSG-ADV-2026-002 High
The Fake AI Reseller Trap: How Criminals Are Stealing Credentials Through Discounted AI Offers

A documented criminal operation offered "cheap Claude access" that was actually credential theft dressed up as a service. Customers got responses from a different model while their credentials were stolen and sold onward.

Read advisory →
September 2026
KSG-ADV-2026-003 High
Supply Chain Attacks on the AI Tools Your Business Uses

Criminals are targeting the AI tools and integration services your business relies on — not to attack you directly, but to steal the API keys those services hold on your behalf. A breach of one AI vendor can expose the credentials of all their customers.

Read advisory →
September 2026
KSG-ADV-2026-004 High
You Didn't Do Anything Wrong — But Your Account Was Used to Attack Political Organisations

A documented hacktivist ran a month-long campaign attacking political parties and media organisations using stolen API keys from businesses that had nothing to do with the targets. Your account becomes the platform — creating risks of suspension and legal exposure.

Read advisory →
September 2026
KSG-ADV-2026-006 High
The Hotel WiFi Threat: What Business Travellers Need to Know

A state-linked operation compromised hotel WiFi management vendors, hijacked DNS records across multiple hotels, and delivered malware to guests through convincing fake update prompts. Anyone who connected was exposed — including to your business email and financial accounts.

Read advisory →
September 2026