For years, the advice for spotting scams was simple: look for bad spelling, strange greetings and urgent requests from people who don’t sound like themselves. AI has broken most of those tells. Phishing emails are now fluent and personalized, voices can be cloned from a short clip, and video calls can be faked convincingly enough to fool trained staff.
The good news: the defenses that work best aren’t expensive or technical. They’re mostly process, simple habits that make a convincing fake fail anyway. This guide explains what’s changed and what every business should put in place.
Key takeaways
- Spotting fakes by how they look or sound is no longer reliable. Verify through a second channel instead.
- The most damaging attacks target money and logins: payment changes, wire transfers, gift cards and password resets.
- A callback rule and multi-factor authentication stop most of them cold.
- Train people with real examples, and make it safe to say “let me verify that.”
What AI changed for attackers
Phishing
Flawless, personalized emails
AI writes in perfect English (or any language), mimics a company’s tone, and can tailor messages using details scraped from LinkedIn and your website.
Voice
Cloned voices on the phone
A few seconds of audio from a video or voicemail can be enough to imitate someone’s voice, often used to add urgency to a payment request.
Video
Deepfake meetings
Attackers can impersonate executives on video calls. Live deepfakes still have glitches, but under pressure people rarely look closely.
Scale
More attacks, less effort
Work that used to take a skilled scammer hours now takes minutes, so small businesses get targeted with techniques once reserved for large companies.
Spot the scam
Here are four realistic scenarios. Decide what you’d do, then reveal the answer.
Interactive
Would your team fall for these?
1. An email from your regular supplier, in their usual format and tone, says they’ve changed banks and asks you to update their payment details before Friday’s invoice.
2. Your CEO calls your cell. It’s definitely their voice, and they sound stressed. They’re in a meeting and need you to buy $2,000 in gift cards for a client right now.
3. You get a Microsoft 365 alert: “Unusual sign-in activity. Review your account within 24 hours.” It’s well written and the link looks like a Microsoft address.
4. A video call invite from your CFO includes two other executives. On the call, they ask you to process an urgent, confidential acquisition payment today.
The defenses that actually work
Since you can’t reliably spot a good fake, build habits that make the fake irrelevant. These five do the most:
1. A callback rule for money and data
Any request to send money, change payment details, buy gift cards, or share sensitive data gets verified through a different channel, using contact details you already have, not ones in the message. Write it down, and make it apply to everyone, including the owner.
2. Multi-factor authentication everywhere
MFA means a stolen password alone isn’t enough to get in. Turn it on for email, banking, accounting, payroll and remote access first. Where possible, use an authenticator app or security keys rather than text messages, and teach people to deny any MFA prompt they didn’t trigger.
3. Two-person approval for payments
Payments above a threshold you choose, and every change to vendor bank details, need a second person to approve. It’s the single most effective control against payment fraud, and your bank can often enforce it for you.
4. A code word for emergencies
Leaders and finance staff agree on a verbal code word that’s never written in email or chat. If “the boss” calls with an urgent request and can’t give it, the request stops. It’s low-tech, and it defeats voice cloning.
5. Training with real examples, and no blame
Short, regular training with current examples beats an annual slideshow. Just as important: people must feel safe saying “I need to verify this,” even to the CEO, and reporting mistakes quickly. A clicked link reported in five minutes is a minor event. One hidden for a week can be a disaster.
How protected is your business?
Self-check
AI-era scam readiness
0 of 8 in place
If you ticked fewer than five, start with the first two items. They’re free, take a day to put in place, and block the most common attacks. If the email security item made no sense, ask whoever manages your IT. It’s a quick check for them, and it makes it much harder for scammers to send email pretending to be your company.
Frequently asked questions
Can software detect deepfakes for us?
Detection tools exist and are improving, but none are reliable enough to be your main defense, and attackers adapt quickly. Treat detection as a bonus. Process controls like callbacks and dual approval work no matter how good the fake is.
We’re a small business. Would anyone really target us?
Yes. AI has made targeted attacks cheap, and small businesses often have fewer controls and faster payment processes, which makes them attractive. Many attacks are automated and don’t care how big you are.
What should we do if we’ve already sent a payment to a scammer?
Call your bank immediately and ask them to recall or freeze the transfer. Speed matters most. In the U.S., also report it to the FBI’s Internet Crime Complaint Center (ic3.gov), secure any compromised email accounts, and check whether your cyber insurance requires prompt notification.
Does cyber insurance cover AI-driven fraud?
Sometimes. Coverage for “social engineering” or funds-transfer fraud is often limited or excluded unless specifically added. Many insurers now also require MFA and verification procedures. Review your policy with your broker.
Next step
Put your rules in writing
An AI acceptable use policy covers what data can go into AI tools and how staff should handle AI-powered scams. Get our free, editable template.


