You may be on vacation – but not so data crooks who may be scheming to attack your small business or organisation.Cyberattacks targeting Finnish victims have increased by 35 percent compared to June last year, according to a report released by the cybersecurity company Check Point Software Technologies on Friday.Anssi Kärkkäinen, Director General of National Cyber Security Centre Finland (NCSC-FI), is sceptical of that figure, but says that there are plenty of bad actors at work 24/7."We haven't seen that cyberattacks have risen that sharply, but rather that cyber threats remain at a persistently high level and that organisations are facing a growing volume of malicious activity, especially phishing, ransomware, account compromises and supply-chain related attacks."Anssi Kärkkäinen, Director General of National Cyber Security Centre Finland (NCSC-FI) Image: Selma Rita / YleIn June, NCSC-FI said that it recorded seven serious cyber incidents in the first five months of this year, compared with 18 each in all of 2025 and 2024, up from 12 in 2023. In general, the number of serious data breaches and attempted breaches has been steadily increasing since 2022, the agency says.Hyppönen: "AI writes better Finnish than most Finns"However, the use of generative artificial intelligence (AI) is turbocharging the volume of cyberattacks in Finland and the rest of the world, says Mikko Hyppönen, Chief Research Officer at Sensofusion, who gained a global reputation as a data security guru during his many years at Finnish companies F-Secure and WithSecure."Attackers – of course – use generative AI, just like everyone else," he tells Yle News."Malware is coded with AI, the campaigns are run with AI, the targeting is done with AI, the phishing emails are written with AI," Hyppönen says."AI writes better Finnish than most Finns," he adds – refuting an old assumption that the little-known, complex Finnish language would provide a layer of protection from malicious emails and messages, for instance.Kärkkäinen agrees that "AI is making cyberattacks easier, cheaper and more convincing, particularly phishing and impersonation attempts".It also helps attackers identify vulnerabilities faster and automate parts of the attack process, he notes."However, AI is primarily a force multiplier rather than a root cause of the threat. These include financial or other incentives, weak cyber-hygiene and the increasing attack surface due to digitalisation," he says.Organisations need AI-powered tools to fight backJarno Ahlström, senior security analyst at the Espoo-based Check Point Software and co-author of Friday's report, said that the latest data from June "reflects a broad-based resurgence in cyber activity". The largest number of attacks targeted the education and research sectors, public administration and telecoms, it said.Jarno Ahlström, senior security analyst at Check Point Software Image: Antti Kolppo / Yle"Attackers are expanding their reach, and ransomware groups are reorganising and increasing their scale. Organisations need proactive, AI-powered security that protects networks, users, data, and AI environments before attacks can cause damage," Ahlström warned.At the same time, the Check Point report points to significant risks associated with the use of generative AI, as companies also feed AI ​​with sensitive material. Its study found that most companies are regularly sharing personal, financial and legal information with AI interfaces.What if your firm or association comes under attack?Besides "proactive, AI-powered security", how should small businesses and other groups protect themselves – even during the sleepy weeks of summer?"It’s important to maintain visibility of all devices and systems in use, apply updates as quickly as possible when vulnerabilities are identified, and ensure that the organisation has a clear process and operating model in place for responding to potential cyber incidents," says Roni Kokkola, an information security specialist at NCSC-FI.Robust backup systems and regular backups can significantly support recovery efforts in the event of a cyberattack, he adds.NCSC-FI information security specialist Roni Kokkola Image: Milena Hackman / YleIn the event of a suspected attack, "the most important first step is to isolate the affected environments from the network in order to stop the attack and prevent unauthorised parties from maintaining access to the environment", Kokkola advises.After this – before any systems are wiped or restored from backups – he recommends creating disk images and capturing memory copies to support further investigation and forensic analysis."If devices are restored to a clean state before disk images and memory dumps are collected, it becomes significantly more difficult for authorities and external cybersecurity investigators to determine what occurred and how the compromise happened," he points out.The environment can be reconnected to the network once the affected systems have been restored to a clean state and it’s been verified that the attacker no longer has a foothold within it, advises Kokkola.He and Kärkkäinen stress that all cyberattacks – and attempted attacks – should be reported to the NCSC-FI, which can help with investigations, recovery efforts and communications."If there’s reason to suspect that a crime has been committed," says Kokkola, "the incident should also be reported to the police" immediately – even if it's the middle of the holiday season.