78% of South African Small Businesses Hit by Cyber Incidents as AI Apps Spread

By

October 9, 2026

Most small businesses in South Africa have faced a cyber attack or security problem in the past year, according to research by Kaspersky. Now more of these businesses are using AI to build their own apps, often without checking if those apps are safe.

Kaspersky released the research in August. It found that 78% of South African small and medium-sized enterprises (SMEs) had a cybersecurity incident in the past year. Weak or stolen login details caused 18% of these incidents.

“AI will build what you ask it to build, but if security isn’t part of the brief, you can’t assume it has been taken care of,” said Anton Moulder, Head of Product at HyperDev AI, according to Lifestyle & Tech.

Moulder said a business owner can now use AI to make a working app in a few days. Many of these owners do not have the skills to spot security weak points in the code.

Small firms are using AI to create booking systems, customer portals and online shops without hiring a team of developers. This means keeping that software safe is now their own job.

Moulder said such apps could hold customer names, phone numbers and booking details. In some cases, they could also hold payment information.

The AI tools themselves also carry risks. Kaspersky recorded a tenfold rise in security weak points in AI services in the first half of 2026. Most of these problems were in access controls and in the way users log in.

A separate report from Veracode, released in July, looked at code written by leading AI models. It found that the code had a known security flaw in 44% of tasks where security mattered.

Moulder said an app can work perfectly while a security problem goes unnoticed in the background. He said business owners should question their AI tool about security before they let customers use an app.

“None of these questions requires a business owner to become a software developer,” Moulder said. “The time to ask them is before launch, while fixing a problem still costs you nothing but time.”

If a business thinks its app has been breached, Moulder said it should act at once. He said owners should change passwords and connection codes. They should take the affected part of the app offline if needed, and keep a record of what happened and when.

Under the Protection of Personal Information Act (POPIA), a business must tell the Information Regulator when it is reasonably sure customer data has been exposed. It must also tell the affected customers as soon as possible. Reports to the Regulator must be made on its online eServices portal.

Moulder said the risks should not stop small businesses from building apps. “AI has put tools within reach that used to cost a development team and months of work,” he said. “For a small business, that’s a real advantage over bigger competitors.”

Source: this article is based on reporting by Lifestyle & Tech. Image: Lifestyle & Tech. Written with the help of AI and published by the Tzaneen Voice Technology desk. See our Editorial Standards.