
AI Phishing & Deepfake Scams: How to Protect Your Business in 2026
Adam Gleason
Founder & President
May 22, 2026
8 min read
Yes — AI phishing and deepfake scams are a real, present threat to small businesses, not a future one. The good news is that the defenses haven't changed as much as the attacks have: a written verification rule, mandatory MFA, and a callback policy stop the overwhelming majority of these scams, and you can put all three in place this week. The hard part isn't buying expensive tools. It's deciding the rules in advance and actually following them when a message feels urgent.
What changed — and what didn't
For thirty years the advice on phishing was "look for the typos, check the grammar, trust your gut." That advice is now obsolete. Generative AI writes clean, fluent, context-aware messages in any language and at any volume. One report tracking the period right after ChatGPT launched logged a 1,265% increase in malicious phishing emails — and whatever the exact figure, the direction is not in dispute: the cost of producing a convincing scam dropped to near zero.
Here's what didn't change: the attacker still needs you to do something — move money, hand over a password, change banking details. Every one of these scams ends with an action. That's the point you defend. The message can be flawless and the voice can sound exactly like your boss; if the action requires an out-of-band verification that the attacker can't fake, the scam dies at the last step.
AI-written phishing
The classic phishing email is now polished, personalized, and often scraped from your own public footprint — LinkedIn, your website's team page, a press release. The attacker knows your CFO's name, your vendors, your billing cycle. The email references a real project. It arrives the week a real invoice is due.
These almost always funnel toward business email compromise (BEC) — the quiet, expensive cousin of ransomware. The FBI's Internet Crime Complaint Center reported roughly $2.77 billion in BEC losses in 2024 alone, and nearly $8.5 billion over 2022–2024. BEC doesn't make headlines like ransomware, but it drains more money out of more businesses, and SMBs are squarely in the target set.
The tell isn't the writing anymore. It's the request. Any message asking you to change payment details, rush a wire, or "keep this confidential for now" deserves suspicion regardless of how clean it reads.
Voice-clone vishing — the "IT support" and "CEO wire" calls
This is the one catching businesses off guard right now. With a few seconds of audio — a podcast clip, a webinar, a voicemail greeting — an attacker can clone a voice well enough to fool people who know it. Two patterns dominate:
The CEO wire-transfer call. Someone in finance gets a call (or a voicemail, or a voice note on a messaging app) that sounds like the owner: "I'm in a closing, I need you to wire $48,000 to this account today, I'll explain later." The urgency and the authority are the weapon. The voice is just the delivery.
The "IT support" call. Someone calls an employee claiming to be from IT — sometimes claiming to be us, your provider — and walks them through "verifying" their account, reading back an MFA code, or installing a "support tool." Real IT departments don't cold-call you for your MFA code. Ever.
The hard truth: you cannot reliably tell a cloned voice from a real one anymore. Stop trying to. The defense is procedural, not perceptual.
Deepfake video — yes, it's reached SMBs
The landmark case is the engineering firm Arup, where an employee in the Hong Kong office wired roughly $25 million after joining a video call in which the CFO and other colleagues were all AI-generated deepfakes. That was a large enterprise — but the tooling that did it is now cheap and widely available, and similar fabricated-meeting scams have since hit smaller companies. A live video call is no longer proof that the people on it are real.
You don't need to defend against Hollywood-grade fakes. You need one rule: a video call is not authorization. Money moves and credentials change only through a verified channel, never because of what someone said on a screen.
Why SMBs are now the soft target
For years small businesses assumed they were too small to bother with. AI flipped that math.
- The attacks are now cheap to scale. When a convincing, personalized scam costs almost nothing to produce, going after a hundred 20-person companies beats going after one fortified enterprise.
- SMBs have real money and thin controls. A 30-person company can move five or six figures on one person's say-so, often with no second approver and no written verification policy.
- No security staff to slow things down. Enterprises have a security team whose whole job is friction. In a small business, the person who approves the wire is also the person who's slammed and wants the email out of their inbox.
You're not too small. You're the right size — enough money to be worth it, not enough process to stop it. That second half is fixable, and it's cheap to fix.
The defense playbook — start this week
None of this requires a six-figure security budget. After 30+ years of building and hardening SMB infrastructure, the pattern is always the same: the businesses that don't get hit aren't the ones with the most tools. They're the ones with the clearest rules.
-
Write a money-movement verification rule — today. Any new payee, any change to existing banking details, or any wire above a set threshold requires verification through a second, known channel. Email confirmation does not count — the email may be the attack. This single rule stops most BEC and CEO-fraud losses.
-
Adopt a callback policy on a number you already have. When a request to move money or change details comes by email, call, or video, hang up and call back on the number already in your contacts — never a number from the message itself. The attacker controls the inbound channel; they don't control your existing records.
-
Turn on MFA everywhere — and prefer phishing-resistant kinds. Email and accounting first. Use an authenticator app or, better, hardware security keys (YubiKey or similar) for executives and finance. Push-approval and SMS codes can be socially engineered; passkeys and hardware keys largely can't.
-
Set a verbal code word for urgent requests. A simple shared phrase between owners and finance staff defeats voice clones instantly. If the "CEO" on the phone can't produce it, the request stops. Low-tech, nearly free, and brutally effective against vishing.
-
Train people to slow down — and give them permission to. Most scams work on time pressure. Tell your team explicitly: "You will never be punished for verifying a payment request, even if it turns out to be real and the boss is waiting." Urgency plus confidentiality is the signature of fraud — name it so people recognize it.
-
Lock down the public audio and authority signals. You can't scrub the internet, but know that voice clips and org-chart details are raw material. The fix isn't going dark; it's assuming the attacker already has them and building rules that don't rely on secrecy.
-
Tighten email authentication. Make sure SPF, DKIM, and DMARC are configured and enforcing on your domain. This blocks a large share of look-alike and spoofed-sender mail before a human ever has to judge it.
-
Run a real incident drill. Tabletop one scenario: "Finance gets a call from the owner's cloned voice asking for a same-day wire." Walk through exactly who does what. The first time you practice the callback rule should not be during a live attack.
What we don't recommend
You don't need a deepfake-detection AI product, a dedicated security operations center, or an expensive "AI threat platform" to handle this. For a business under about 50 people, those are capability you can't operate and won't maintain. The controls above are mostly process and configuration, and process is what actually holds when the urgent message lands. Anyone selling you a single product that "detects all deepfakes" is selling you a vibe — detection is an arms race, and verification rules aren't.
FAQ
Can employees still spot AI phishing by looking for bad grammar? No, and that advice is now dangerous. AI-written phishing is clean and personalized. Train people to scrutinize the request — money, credentials, urgency, secrecy — not the spelling.
Someone called and the voice was definitely my boss. Doesn't that prove it's real? No. Voice cloning needs only a few seconds of audio and is good enough to fool people who know the voice well. Treat voice — and even live video — as unverified. Confirm any money or access request through a known, separate channel.
We're a 15-person company. Are we really a target? Yes, more than ever. AI makes it cheap to run convincing scams at scale, and small businesses tend to move real money with few approval controls. You're worth the attacker's time precisely because the safeguards are usually thin.
What's the single most important thing to do first? Write and enforce a money-movement verification rule with an out-of-band callback. If money can't move on one person's word from one channel, the most expensive version of these scams simply stops working.
The bottom line
AI didn't invent these scams — it made them cheap, clean, and scalable, and pointed them at businesses your size. The defense is calm and concrete: decide your verification rules before you're under pressure, then follow them every time. If you want a second set of eyes, G8 IT runs a security assessment that usually finds an open gap in the first ten minutes — and tells you the few changes that actually matter. Get in touch and we'll give you the straight take.

Adam Gleason
Founder & President
With 27+ years in the IT industry, Adam founded G8 IT to deliver the kind of proactive, reliable, and personal technology support businesses truly deserve. He leads our managed IT, cloud, and cybersecurity engagements.
Talk to a human about this.
We do the work the article describes. Two ways in: