← All Posts Bahamas Cybersecurity · AI Threat Defence

Bahamian Businesses Face a 230% Rise in Cyberattacks. AI Defence Can Close the Gap.

Adrian Dunkley, the AI Boss September 24, 2026 13 min read

Two numbers landed in The Bahamas within a week of each other, and put side by side they tell the same story from opposite ends. Bahamian businesses have seen a 230% rise in cyberattacks over the past five years, according to Robert Albury, managing director of Waves IT, speaking at an Abaco Business Outlook panel reported on 18 September 2026. The same day, across the water at Margaritaville Beach Resort in Nassau, executives at an AI security conference heard that one company had received 300 individually crafted phishing emails in a single wave, each addressed to a specific employee, each written to look convincing enough to click.

Those two events were not coordinated, and they happened on opposite ends of the country. That they landed on the same day anyway is the part worth sitting with. One measured the damage. The other explained the mechanism.

The Attack Surface Is Growing Faster Than the Defence

Albury's warning to the Abaco panel was specific about where the pressure falls hardest. Phishing emails and ransomware, he said, are the two threats capable of crippling a business outright, and Abaco and the wider Family Islands are targeted particularly aggressively. He made a point that cuts against the instinct to spend the problem away: staff training matters more to a firm's resilience than the size of its software budget. He also noted a pattern familiar to anyone who has watched the country's post-Dorian recovery from outside, that hackers pay closer attention to The Bahamas whenever it draws international media coverage, turning visibility itself into exposure.

That reference to Dorian was not incidental. Albury pointed to the aftermath of the 2019 hurricane as a period when phishing scams exploited the confusion of recovery efforts, preying on residents and businesses trying to access aid and insurance payouts while their own systems and communications were still disrupted. The businesses that recovered fastest afterward, he noted, were the ones that had continuity plans in place before the storm, not after. Quality Star Auto, cited on the panel, had already installed battery backup systems for its fuel pumps, a small operational decision that kept it running when larger competitors without one could not.

Victoria Albury, group assistant vice president for Northern Bahamas at Leno Corporate Services, extended the same argument to everyday recordkeeping. Businesses still relying on what she called "shoe box" methods, paper receipts and informal ledgers instead of structured accounting systems, will lose to competitors who can actually see anomalies in their own operations. She pushed the same audience toward succession planning, framing it as protection rather than a threat, and toward financing options beyond a single bank relationship. None of this was framed as cybersecurity advice specifically. It did not need to be. A business that cannot see its own transactions clearly is a business that will not notice a fraudulent one until the money is gone.

What 300 Phishing Emails in One Wave Actually Looks Like

The Nassau conference, organised by AI specialist Noel Russell in partnership with Professional Business Services, gathered engineers from two of the world's larger security vendors alongside local business leaders to walk through what the Abaco panel's numbers mean in practice. Emmanuel Oscar, Fortinet's senior systems engineering manager, put the imbalance plainly: "The defenders are lagging behind, but it doesn't mean we cannot catch up." Montino Roberts, PBS's executive chairman, described how far the barrier to entry has fallen for an attacker. "Today, all you need is intent and you have access to the sophistication," he said, describing a shift in which a criminal no longer needs technical skill of their own, only the willingness to point an AI model at a target list.

The 300-email case is the clearest illustration of what that shift means for a business the size of most in The Bahamas. Crafting 300 phishing messages that each reference a real employee's role, tone, and likely concerns used to take a criminal crew weeks of manual research through social media and public records. An AI language model can now generate that same volume, personalised at the same depth, in minutes. The email that reaches a bookkeeper does not read like a generic scam anymore. It reads like it came from their actual supplier, referencing their actual invoice cycle, in their actual company's voice.

Frank Gomez, a technical account manager at Kaseya, walked participants through a "breach room" exercise built around that reality: a simulated intrusion that required the room to work through detection, containment, and evidence review together, under time pressure, rather than listen to a lecture about what a breach looks like. Russell framed the broader lesson in a phrase that stuck with the room: businesses should treat an AI system the way they would treat "a zero-trust contractor," assuming no inherent trust, restricting what it can touch, and verifying what it produces before it reaches a customer or a ledger. "AI safety and security is paramount," he told the conference, a warning aimed as much at the AI tools businesses are adopting themselves as at the ones being used against them.

This Fits a Pattern Larger Than One Small Island Nation

What happened in Nassau and Abaco in September is a local instance of a shift security researchers have been tracking globally for over a year. CrowdStrike's 2026 Global Threat Report found that AI-enabled adversary operations, spanning reconnaissance, credential theft, and evasion, rose 89% year over year. The same report recorded the average breakout time for an eCrime intrusion, the gap between an attacker's first foothold and their first move deeper into a network, falling to 29 minutes in 2025. The fastest breakout the firm observed took 27 seconds.

Twenty-nine minutes is not a window most small Bahamian businesses, or most small businesses anywhere, are staffed to respond inside. A firm that reviews its security logs once a week, or once a month, is not competing against a human attacker probing for an opening. It is competing against a system that finds the opening, exploits it, and has already moved on before a human would have opened the relevant dashboard. A 230% rise in attacks on Bahamian businesses over five years is not a local anomaly sitting apart from that global curve. It is the same curve, measured from Abaco.

The Core Argument

AI did not create the appetite for fraud that already existed in The Bahamas. It removed the labour cost of acting on it, turning weeks of manual targeting into minutes of automated output. Closing that gap does not mean outspending the attacker. It means deploying a comparable class of tool, AI-driven detection instead of AI-driven attack, at a price small and mid-sized businesses can actually afford.

How AI Can Close the Gap It Opened

Every capability described at the Nassau conference exists to catch what the attack side of the same technology now produces at scale. None of it requires a Bahamian business to build a security operations centre from scratch.

1. AI-Driven Email and Behavioural Threat Detection

A rule-based spam filter looks for known bad senders and obvious red flags, the kind of filter a personalised AI phishing email is specifically designed to pass. Behavioural detection systems instead learn what normal communication looks like for a given business, its regular suppliers, its typical invoice language, the hours its staff usually send email, and flag messages that deviate from that pattern even when nothing about the message itself looks technically malicious. This is the direct answer to the 300-email problem: catching the anomaly in behaviour rather than trying to catch the forgery in content.

2. Managed AI-Assisted Detection and Response for Smaller Firms

Fortinet and Kaseya both build tools that give a business continuous, AI-assisted monitoring without requiring an in-house security analyst on staff around the clock, the exact resource gap Albury described in Abaco and the Family Islands. A managed detection and response contract puts that monitoring within reach of a business the size of a car dealership or an accounting firm, not just a bank. The barrier is not the technology. It is whether local providers extend that kind of service, and at what price, beyond Nassau's larger commercial clients.

3. AI-Run Breach Simulations as Standard Staff Training

Albury's point that staff training outweighs software spending has a direct AI answer: simulated phishing and breach exercises, generated and scored by AI rather than run manually once a year, can test and retrain staff on a rolling basis against attack patterns that update as fast as the real ones do. Gomez's breach room exercise at the Nassau conference is the model. A Bahamian business does not need a live incident to teach its bookkeeper what a convincing fake invoice request looks like. It needs a simulation realistic enough to fail against safely, repeated often enough that the lesson sticks.

4. Zero-Trust Governance for the AI a Business Adopts Itself

Russell's warning cuts both ways. As Bahamian businesses bring in AI tools of their own for customer service, bookkeeping, or marketing, the same contractor-style scrutiny he described needs to apply internally: limiting what data a new AI system can access, logging what it does, and reviewing its output before it reaches a customer or a financial record. A business that adopts AI without that discipline is not closing the gap between attacker and defender. It is widening its own surface for the next version of the problem.

What Family Islands Businesses Need That Nassau Does Not

Albury's warning about the Family Islands deserves to be taken on its own terms, not folded into a general Bahamas story. A business in Marsh Harbour or Governor's Harbour is working with thinner connectivity, fewer dedicated IT staff, and, as Victoria Albury's comments made plain, often still running on paper records that make an intrusion harder to even notice, let alone respond to quickly. These are the same businesses that took longest to recover after Dorian, and the same ones a rising tide of AI-personalised phishing will find easiest to reach.

Extending events like the Nassau AI security conference, and the managed detection services vendors like Fortinet and Kaseya sell through local partners, beyond the capital is not a charitable gesture. It is the part of the defensive picture that determines whether the national 230% figure keeps climbing or starts to bend.

What the Rest of the Region Should Take From This

Nothing about The Bahamas's exposure is unique to it. Every Caribbean territory with a tourism-facing business sector, a banking system, and an internet connection carries the same shape of risk, and CrowdStrike's global numbers say the acceleration is not slowing down anywhere. Two things would move other Caribbean markets from reading about this as a Bahamas story to acting on it as a regional one. Territories with an active technology or business association should convene the same kind of joint vendor and local-leader conference PBS organised in Nassau, instead of leaving small firms to research AI threats on their own. And every jurisdiction's version of the Family Islands, the outer parishes, the smaller sister islands, the towns furthest from the capital, needs its own version of the outreach Albury and Victoria Albury delivered in Abaco, before its own 230% figure becomes public at a business panel two years from now.

What Is Actually at Stake

A 230% rise in attacks over five years is already the story of businesses that survived. The ones that did not are not on a panel describing what happened to them. Roberts's line at the Nassau conference, that intent alone now buys access to real sophistication, is the fact that should reorder how Bahamian business owners budget for the next year. The tools that generated 300 convincing phishing emails in one wave are available to anyone with a grievance and a laptop. The tools that can catch them are equally available, and considerably cheaper than the alternative. The Bahamas has already had the conversation this month, in two rooms, on the same day. What happens between now and the next wave of emails is whether that conversation turned into anything a defender could actually use.

Frequently Asked Questions

How much have cyberattacks on Bahamian businesses increased?

Robert Albury, managing director of Waves IT, told an Abaco Business Outlook panel reported on 18 September 2026 that Bahamian businesses have seen a 230% increase in cyberattacks over the past five years. He said the Family Islands, including Abaco, are targeted particularly hard, and that phishing emails and ransomware are the two threats most capable of crippling a small business outright. He also noted that staff training matters more to resilience than the size of a firm's software budget, and that The Bahamas draws disproportionate attention from hackers whenever it appears in international media.

What did the AI security conference in Nassau reveal about AI-powered phishing?

At an AI security conference held at Margaritaville Beach Resort on 18 September 2026, organised by AI specialist Noel Russell and Professional Business Services, speakers described a company that received 300 individually personalised phishing emails in a single wave. PBS executive chairman Montino Roberts said the work of crafting that many convincing, targeted messages once took a criminal team weeks and now takes an AI model minutes, a shift he summarised by saying that today, intent alone buys access to that level of sophistication.

Are AI-powered cyberattacks actually increasing globally, or is this just a Bahamas problem?

It is a global pattern that the Bahamas is now living through locally. CrowdStrike's 2026 Global Threat Report found that AI-enabled adversary operations, covering reconnaissance, credential theft, and evasion, rose 89% year over year. The same report found the average breakout time for an eCrime intrusion, the time between initial access and lateral movement inside a network, fell to 29 minutes in 2025, with the fastest observed breakout at just 27 seconds. A 230% rise in attacks on Bahamian businesses over five years sits inside that same acceleration, not apart from it.

How can AI actually help defend a small Bahamian business against AI-powered attacks?

The same category of tool doing the attacking can do the defending. AI-driven email and behavioural detection systems learn a business's normal communication patterns and flag messages that deviate from them, catching personalised phishing that a rule-based spam filter waves through. Managed detection and response services, of the kind Fortinet and Kaseya specialists discussed at the Nassau conference, give small firms access to continuous AI-assisted monitoring without needing an in-house security team. Neither requires a business to out-build the attacker's budget. It requires deploying a comparable class of tool.

Why do the Family Islands face a higher cyberattack risk than Nassau?

Robert Albury told the Abaco panel that attacks concentrate on Abaco and the wider Family Islands, where businesses typically run leaner IT budgets, share fewer dedicated security staff, and often still rely on the kind of informal, paper-based record keeping that Leno Corporate Services executive Victoria Albury urged the same audience to abandon. Smaller firms with weaker continuity planning were also the ones that struggled most to recover after Hurricane Dorian, a pattern that predicts how the same businesses would fare against a ransomware attack that locks their systems instead of a storm that floods them.

What is a zero-trust approach to AI, and why does it matter for Bahamian businesses?

AI specialist Noel Russell told the Nassau conference that organisations should treat an AI system the way they would treat a contractor with no history at the firm: assume it needs supervision, limit what data and systems it can touch, and verify its output before it earns any trust. For a Bahamian business adopting AI tools for customer service, bookkeeping, or marketing, this means restricting an AI system's access to only the data it needs for its specific task, logging what it does, and reviewing its outputs before they reach a customer or a financial system, the same discipline applied to a new employee's first ninety days.

What should Bahamian business owners do right now to reduce their cyber risk?

Panellists at both the Abaco and Nassau events converged on the same starting point regardless of a firm's size. Build a written risk management and continuity plan before an incident forces one into existence. Train staff to spot personalised phishing on sight instead of leaning on software alone. Move off informal record keeping and onto accounting systems that can flag anomalies. Treat any new AI tool the business adopts as something to be supervised, not trusted on day one. None of it requires a large budget. It requires a decision to start before the next wave of 300 emails arrives.

Get the Weekly Post

New thinking on Caribbean AI, governance, and technology, delivered every week.