The article warns that small and mid-size businesses are facing a squeeze: new risks from AI agents connected to company systems, and faster, more effective versions of familiar scams like phishing. It highlights real-world trends such as QR-code phishing and “ClickFix,” where fake error pages trick users into pasting commands into their own devices. It also notes that attackers can hide malicious instructions in content AI agents retrieve (like web pages or emails), potentially causing data exposure without a user clicking a link.
How the attack works
Attackers are combining familiar social-engineering tactics with AI to make old scams faster and more convincing. Two patterns stand out. First, QR code phishing asks employees to scan a code embedded in an email, often framed as a need to verify or restore access after a supposed login issue, which leads to a fake sign-in page designed to capture credentials. Second, ClickFix scams present a fake error message that instructs a user to paste a command into their own terminal, a tactic now frequently dressed up as AI troubleshooting and hosted on public AI sharing pages to appear legitimate.
Why it succeeds
These scams work because they exploit trust in routine workflows: verifying access, fixing a technical error, or following AI-generated guidance. QR codes sidestep the usual scrutiny given to links, since the scan happens on a phone rather than in a browser where hover-over checks are common. ClickFix relies on urgency and technical framing to get users to act before questioning the source. AI is compounding the problem by making phishing emails significantly more effective, with automated phishing reportedly achieving a much higher click-through rate than standard attempts, letting attackers scale these techniques with less manual effort.
What to watch for
- Emails that push QR code scanning instead of a normal login link, especially paired with urgent or pressured language
- Web pages or pop-ups instructing you to copy and paste a command into a terminal, particularly when framed as an AI or system fix
- Instructions hosted on public sharing pages rather than official IT or vendor support channels
- Login pages reached after scanning a QR code that don't match the company's real sign-in URL
A less visible risk involves AI agents connected to business systems. Because these agents act through permissions granted by their owner, they are vulnerable to indirect prompt injection, where an attacker hides commands in a webpage, email, or other resource the agent is instructed to fetch. This can potentially expose data without any employee clicking a malicious link.
How to build resistance
- Treat QR codes in emails as suspicious and verify requests through a known, trusted path such as a bookmarked URL or internal portal
- Never paste commands into a terminal because a web page or AI troubleshooting message tells you to; confirm with IT or official vendor support first
- Assume AI-connected tools can be manipulated and restrict what agents can access and send out
- Establish basic AI governance, including a written policy and visibility into which agents and AI services are running, who connected them, and what permissions they hold, since many SMBs currently lack this oversight
Key findings
- Many SMBs lack AI governance: the cited survey found “40 percent of the businesses didn’t even have an AI policy.”
- ESET reports a growing AI-agent supply chain risk: scanning “almost 900,000 unique skills,” it found “more than 25,000… suspicious and more than 3,000 outright malicious,” linked to “credential theft, data exfiltration and remote code execution.”
- Attackers are using AI to scale proven social-engineering: “AI-automated phishing emails achieve a 54-percent click-through rate versus 12 percent for standard attempts.”
- “QR code phishing is soaring,” and “ClickFix… asks a user to paste a command into their own terminal,” now “often dressed up as AI troubleshooting.”
- Indirect prompt injection is highlighted as a practical risk: attackers can “hide commands in a webpage, email or another resource that the agent is instructed to fetch.”
Who’s being targeted
- Commonly targeted roles: All employees, IT, Engineering, Helpdesk/Service desk, Security/IT management.
- Affected industries: Small and mid-size businesses (cross-industry).
- Attack channels: email, website.
- Impersonated: A trusted business service (e.g., Microsoft 365 / internal file portal), AI support/troubleshooting guidance (hosted on a public AI sharing page).
Red flags to watch for
- Email pushes QR scanning instead of a normal login link
- Urgent/pressured language to act quickly
- Login page after scanning doesn’t match the company’s real sign-in URL
- A web page instructs you to paste commands into a terminal
- “Fix” steps are not from an official IT/helpdesk channel
- Instructions are hosted on a public sharing page rather than an official support site
Frequently asked questions
What is ClickFix and how does it target SMBs?
ClickFix is a scam where a fake error message tricks a user into pasting a command into their own terminal, and it is now often disguised as AI troubleshooting hosted on public AI sharing pages.
Why is QR code phishing effective against small businesses?
QR code phishing bypasses normal link scrutiny because employees scan a code with a phone instead of clicking a link, often under pressure from urgent language claiming a login issue needs fixing.
How does AI increase the risk of phishing for SMBs?
AI-automated phishing emails reportedly achieve a 54 percent click-through rate compared to 12 percent for standard attempts, meaning attackers can scale proven social-engineering tactics more effectively.
What risk do AI agents connected to business systems create?
AI agents can be manipulated through indirect prompt injection, where an attacker hides commands in a webpage, email, or other resource the agent is instructed to fetch, potentially exposing data without a user clicking anything.
Read the video transcript
AI scams are getting sneaky. The new trick? They make YOU do the dangerous part yourself. First, the email: 'Scan this QR code to verify your Microsoft 365 access.' You scan it, a login page pops up, looks normal, but the URL isn’t your real company sign-in. That’s QR code phishing, and it’s soaring. Then there’s ClickFix: a web page says, 'Error: Your session failed. Fix it by running this command in your terminal.' It’s dressed up as AI troubleshooting, hosted on a public AI sharing page, and the command can quietly install malware. Here’s the move: if an email wants you to scan a QR code, or any web page tells you to paste a command, stop and go through our official IT or portal instead, do not follow those on-screen instructions.