Logo

Small Clinic, Big Lesson: How 8 PCs Became a Hacker's Botnet

It’s easy to assume that cybercriminals only go after big banks, government departments, or Fortune 500 companies. A recent discovery proves otherwise: security researchers found that a lone hacker had quietly taken over just eight computers belonging to a small dental clinic and turned them into a working botnet. Not a hospital chain, not a corporate head office – eight PCs at a single small healthcare business, the kind of setup you’d find in any regional Victorian town.

What makes this case particularly interesting isn’t just who was targeted, but how the attack was run. According to reporting from The Hacker News, the hacker used Google’s Gemini command-line AI tool to help automate parts of the operation, including cracking passwords and setting up infrastructure to control the compromised machines remotely. In other words, artificial intelligence is now lowering the skill bar for criminals to build and manage attacks that used to require a team of experienced hackers.

What is a botnet, and why should a small business care?

A botnet is a network of infected computers that a criminal controls remotely, usually without the owners knowing anything is wrong. Each infected machine, or “bot,” quietly follows instructions sent from the attacker’s command centre. Botnets are used for all sorts of criminal activity: sending spam and phishing emails, mining cryptocurrency, running distributed denial-of-service (DDoS) attacks against other targets, or acting as a hidden relay point so the attacker’s real identity and location stay hidden.

For the business whose computers are infected, the damage is often subtle at first. Machines might run slower, internet usage might spike, and staff might notice odd pop-ups or unfamiliar programs. But the real risk is what else the attacker can do once they have a foothold: steal client data, access banking details, deploy ransomware, or use the compromised network as a launching pad to attack your suppliers or customers.

Why small businesses are attractive targets

It might seem odd that a hacker would bother with eight PCs at a small clinic rather than targeting a large corporation. But that’s precisely the point – small businesses are often easier to compromise and less likely to notice quickly.

  • Fewer defences. Many small businesses don’t have dedicated IT security staff monitoring their network around the clock.
  • Outdated software. Without a managed patching schedule, operating systems and applications can go months without critical security updates.
  • Reused or weak passwords. Attackers often start by testing common or previously leaked passwords, which AI tools can now do faster and more efficiently.
  • Valuable data with weak protection. Clinics, accountants, real estate agents, and trades businesses all hold sensitive client information but rarely have enterprise-grade security tools protecting it.
  • Low visibility. A handful of infected machines at a small business can operate undetected for weeks or months, unlike a large company with security monitoring in place.

The AI angle: what’s actually changed

Using AI tools to help run a botnet isn’t just a technical curiosity – it signals a genuine shift in the threat landscape. Tools originally built for legitimate developers and IT teams, like AI command-line assistants, can be repurposed by criminals to speed up tasks that used to take real skill and time: writing malicious scripts, automating password attacks, and managing infected machines. This means attacks that once required a skilled hacking crew can increasingly be run by a single individual, or a small group, at a fraction of the previous cost and effort.

For small business owners, this trend matters because it means the volume and sophistication of attacks aimed at smaller, less-defended targets is likely to increase, not decrease. The days of thinking “we’re too small to be worth attacking” are well and truly over.

Practical steps to protect your business

You don’t need an enterprise security budget to significantly reduce your risk. Most botnet infections start with simple, preventable weaknesses. Here’s where to focus your attention:

  • Keep everything patched. Enable automatic updates for operating systems, browsers, and business software wherever possible. Most infections exploit known vulnerabilities that already have a fix available.
  • Use strong, unique passwords everywhere. Every login, from email to your practice management or point-of-sale software, should have a unique password. A password manager makes this manageable for staff.
  • Turn on multi-factor authentication (MFA). Even if a password is stolen or guessed, MFA stops most automated attacks in their tracks.
  • Install reputable endpoint protection. Modern antivirus and endpoint detection tools can catch unusual behaviour, like a machine suddenly trying to connect to unfamiliar servers.
  • Monitor your network traffic. Unexplained spikes in outbound internet traffic, especially overnight, are a classic sign of a botnet infection.
  • Limit admin privileges. Staff accounts should only have the access they need for their day-to-day work, not full administrator rights across every machine.
  • Back up your data regularly. If a machine is compromised, having clean, tested backups means you can recover without paying a ransom or losing critical records.
  • Have someone watching your systems. Whether that’s an in-house IT person or a managed IT provider, ongoing monitoring is what catches infections in week one instead of month three.

The takeaway

The dental clinic in this story didn’t do anything unusually careless – it’s a scenario that could play out at any small business office, retail store, or trade business across regional Victoria. What protected larger organisations in the past was often simply having more eyes on the network and faster patching cycles. As AI tools make it cheaper and easier for criminals to run these kinds of attacks at scale, small businesses need to close that gap with straightforward, consistent security habits rather than expensive, complicated tools.

Cybersecurity for a small business doesn’t have to be overwhelming. Getting the basics right – patching, strong authentication, monitoring, and backups – stops the vast majority of these opportunistic attacks before they ever get a foothold.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions