AI Scams Targeting Small Businesses: The Anatomy of a Modern Attack, and the One Rule That Stops It

AI did not invent a new crime. It deleted the tells you were taught to watch for, and it made a personalized con cheap enough to aim at a nine-person company in Buffalo.

The modern version of the scam has no typos, no strange greeting, and no obvious tell. What it still needs is for somebody to act without checking on a second channel.

For years, the advice given to small business owners was basically a spelling test. Watch for bad grammar. Watch for the odd greeting. Watch for the vendor who suddenly writes like a stranger.

That advice worked because criminals were sloppy, not because sloppiness was the attack. Generative AI removed the sloppiness. What is left underneath is the same con that has been running for a decade: somebody you appear to know asks you to move money or hand over a login, and gives you a reason it cannot wait until tomorrow.

The rest of this post covers how that attack gets assembled against a small company, what your real exposure looks like in the primary data, which scary headlines do not apply to you, and the free house rule that closes most of the risk. For background on synthetic voices and video, see combatting phishing in the era of AI and deepfakes.

What Actually Changed, and What Did Not

Three things make this a 2026 story rather than a rerun.

The attack moved from your inbox to your phone. Verizon's 2026 Data Breach Investigations Report states that phishing delivered by text or phone call succeeds at a rate 40% higher than traditional email phishing. Your spam filter has no jurisdiction over a phone call. Neither does your firewall, and neither does the security software on the machine.

The pretext now wears a security costume. Google's Threat Intelligence Group published research on August 6, 2026 about a group it tracks as UNC6671. Its callers reach employees on their personal mobile numbers, and in at least some recent cases the group has spoofed the company's legitimate helpdesk phone number to add an air of legitimacy. The story they tell is that you need to enable FIDO2 passkeys or re-enroll your multifactor authentication, urgently. Read that again: the scam is now dressed as the exact security upgrade you were told to do.

The money still leaves the boring way. No crypto, no ransomware, no malware. The FBI's 2025 Internet Crime Report shows business email compromise as the second largest crime type by loss, at $3,046,598,558 across 24,768 complaints, and its transaction chart puts 86% of BEC money movement on wire transfer or ACH. That averages out to roughly $123,000 per complaint. These attacks land inside ordinary banking workflows, which is exactly why an ordinary process fix works against them.

For scale, the FBI logged $20.877 billion in total reported losses in 2025, the first year past $20 billion, and cyber-enabled fraud was 85% of that.

The Anatomy of an Attack on a Small Company

Here is the shape of it, stage by stage. None of the stages require a genius. That is the point.

Stage one: fifteen minutes of research

Your team page names the office manager. LinkedIn names the bookkeeper and shows that she has been there four years. A press release names the general contractor you just partnered with. A Facebook post shows the owner is at a trade show in Cleveland until Thursday. Your own website, which you paid to make findable, is a briefing document.

Security vendors describe attackers feeding this material into an AI model to generate messages that match a company's voice and reference real projects. No primary research measures how often that happens, so treat any percentage attached to it as marketing. The FBI does confirm criminals are using AI-generated text, images, video and cloned voices, and it recommends limiting online content of your image or voice and keeping personal social accounts private.

Stage two: a message that reads like it belongs

The message arrives from a vendor address that is off by one character, or from a real mailbox at a supplier that got compromised last month. It references the actual job, the actual invoice number, and the actual person who normally sends it. There is no urgency in the first message at all. Sometimes there is a short, friendly exchange first, purely to establish that this is a normal conversation.

KnowBe4, a company that sells phishing training and therefore has an interest in the number, reports that 86% of phishing attacks it observed over six months were AI-driven, and that 30% of first-quarter 2026 attacks impersonated an internal team member. That is vendor telemetry, not independent fact, but the direction matches what the FBI describes.

Stage three: the ask

Only one of two things is ever really being requested.

  • Move money. Our bank changed. Here are the new remittance details for this month's payment. Please update the record on file.
  • Change access. This is the helpdesk, we need you to re-enroll your multifactor authentication. Read me the code. Approve the prompt on your phone. Log in at this address so we can confirm.

The second one is what the calling crews are after. Google documented UNC6671 pushing victims to lookalike domains built on patterns like createssopasskey and passkeyhelpdesk, then capturing both the password and the multifactor token in real time before deploying automated scripts to pull data out of Microsoft 365 and Okta. The FBI and CISA advisory on Scattered Spider describes the same playbook in government language: actors posed as employees to convince IT or helpdesk staff to provide sensitive information, reset the employee's password, and transfer the employee's multifactor authentication to a device they control.

Side by side comparison of the two requests every business scam ends with, a message asking to update vendor bank details for a wire payment and a phone caller asking an employee to re-enroll multifactor authentication and read back a code
Every version of this fraud narrows to one of two requests: move money somewhere new, or change who can log in. Both are answerable with the same callback.

What This Honestly Means for a Small Business

This is the part most security articles skip, and skipping it is why owners tune the whole subject out. Some of the headlines above genuinely do not apply to a twelve-person company in Western New York.

What is a real risk to you

Invoice fraud and payment redirection. This is not theoretical and it is not aimed only at the Fortune 500. Coalition, a cyber insurer covering more than 100,000 policyholders across the US, Canada, the UK, Australia and Germany, reported that business email compromise and funds transfer fraud together made up 58% of all claims in 2025. It also found that 71% of all funds transfer fraud claims came directly from social engineering, that 52% of those claims started as a BEC with an average loss of $112,000, and that funds transfer fraud overall averaged $141,000 per claim.

Behind that sits email account takeover, because a real message from a real mailbox is what makes the invoice believable. Verizon's 2026 report is widely read as showing credential abuse falling to 13% as the initial way into a breach while software vulnerability exploitation rose to 31%. That headline is a little misleading on its own, though: analysts reading the same report note credential abuse still appears at some point in 39% of all breaches, which makes it the single most pervasive technique in the chain. Stolen logins did not stop mattering. They just stopped being the front door as often.

What is probably not a real risk to you

Be skeptical of anyone selling you protection against these.

  • The organized calling crews are not coming for a nine-person shop. Google describes UNC6671's victims as mature, large-scale enterprises, and by July 2026 its targeting had narrowed to private equity firms, law firms and financial rating agencies. Initial ransom demands run from $1 million to over $3 million, with final payments averaging $750,000. That business model simply does not work against a company with $2 million in revenue.
  • The helpdesk attack needs a helpdesk. The FBI and CISA advisory on Scattered Spider says outright that the group targets large companies and their contracted IT help desks. Most small businesses do not have an internal helpdesk to socially engineer, which removes the entire path.
  • The deepfake video call is not your 2026 problem. The one well-documented case remains Arup, the global engineering firm, in Hong Kong in 2024, where a finance employee joined a video call on which the other participants including the CFO were AI-generated and made 15 transfers totaling about $25 million. Arup confirmed publicly that fake voices and images were used and that its own systems were not compromised. That attack needed an employee who had never met the executives and a transfer size that looked normal. If your CFO is your spouse and a $40,000 wire would stop your heart, a synthetic video call has very little to work with.
  • Most of the scary AI dollar figures being quoted at small businesses have no primary source. The circulating totals for deepfake fraud losses, the enormous percentage surges, the average deepfake loss figures: those trace back to vendor blogs with nothing behind them. The FBI's real number is more useful and less dramatic. Of the $3.05 billion in 2025 BEC losses, only $30,256,592 across 135 complaints carried an AI tag, roughly 1% of BEC losses. IC3 recorded 22,364 AI-related complaints in total, with $893,346,472 in adjusted losses.

Is Your Website Handing Attackers the Script?

Team pages, contact forms, PDFs and an outdated content management system all give a stranger material to work with. AldoMedia builds and maintains business sites in Buffalo and Western New York with security and upkeep built into the plan, not bolted on afterward.

Talk to AldoMedia Run a Free Site Risk Scan

The Rule That Beats All of It

The single most effective control here costs nothing, and almost nobody puts it in writing, because it is a process problem rather than a software problem. There is no product that fixes the sentence "our bookkeeper trusted an email."

The rule, in one line:

Any request that changes where money goes, or who can log in, gets confirmed on a channel the requester did not choose, using a phone number you already had.

Not the number in the email signature. Not the number the caller reads out to you. The number in your own vendor file, on the last paper invoice, or on the back of the card. This is not a clever trick invented by a blogger. The FBI states it in writing across multiple public service announcements. On payment and account changes: use secondary channels and/or two-factor authentication to verify requests for changes in account information. On suspicious calls: verify the identity of the person calling you by hanging up the phone, researching the contact of the bank or organization purporting to call you, and call the phone number directly. A May 2025 FBI announcement repeats the same callback advice for AI-generated voice messages impersonating people you trust.

It takes about thirty seconds. It works against a perfect email, a spoofed caller ID and a cloned voice equally well, because it does not depend on you detecting anything. You are not being asked to spot the fake. You are being asked to change the channel.

The part most articles leave out

The reason the Arup employee paid is not that the deepfake was flawless. It is that nobody had ever given that person permission to slow a senior executive down.

So the policy is the product, and the callback is just the mechanism. Write it down. Say it out loud in a staff meeting. Tell your people they will never be in trouble for calling back to verify a request, including one that appears to come from you, including when you sound annoyed. An employee afraid of looking paranoid in front of the boss is exactly who a good pretext is built for.

A Staff Training Checklist You Can Finish This Week

None of this needs a consultant, a budget line, or new software.

  • Write the one sentence. "No bank detail change, no new payee, and no password or login code is handed over without a callback to a number already in our records." Put it in the employee handbook or, if you do not have one, in an email everyone keeps.
  • Say the no-blame part explicitly. In a meeting, out loud: slowing a request down is the correct behavior and will never be held against you.
  • Build the known-good contact list. One document with the verified phone number for each vendor, your bank's fraud line, your payroll provider and your IT support. Verified means you called it or read it off a signed contract, not off an email.
  • Set a dollar threshold with two sets of eyes. Pick a number that would hurt. Above it, two people confirm before it goes out, and a text message counts.
  • Turn on phishing-resistant multifactor authentication. Passkeys, FIDO or WebAuthn on email and banking first. Both the FBI and CISA advisory and Google's threat researchers recommend this specifically because it resists push bombing and SIM swap attacks in a way that text message codes do not.
  • Teach the two triggers, not a list of tells. Staff do not need to identify AI writing. They need to notice that a request involves money moving or access changing, and then reach for the phone.
  • Never approve a login prompt you did not personally start. Not once, not to make it stop. If prompts keep arriving, that is the incident.
  • Run one drill. Send your own bookkeeper a fake bank-change request from a lookalike address. Whatever happens, treat it as information rather than a test somebody failed.
  • Check whether your insurance actually covers funds transfer fraud. Many owners assume it does. Coalition clawed back $21.8 million in stolen funds for policyholders, averaging $202,000 per recovery, and 64% of its closed claims ended with no out-of-pocket loss. Recovery is genuinely possible, but it depends on reporting fast, which depends on noticing fast.
  • Tighten the surrounding basics. Keep the website platform patched, since an unmaintained WordPress install is a standing invitation, and keep visitor devices off the network your accounting machine lives on with a properly configured guest WiFi network.

If Money Already Left

Speed is the whole game. Wire and ACH transfers can sometimes be recalled, and the odds fall by the hour.

Call your bank's fraud department immediately and ask for a recall or a SWIFT indemnity request, then file a complaint with the FBI at ic3.gov the same day, including the amount, the receiving bank and the account details. Notify your insurance carrier, and preserve the emails rather than deleting them. Then change the password on the mailbox involved and review its forwarding rules, because attackers routinely leave a hidden rule behind so they can keep reading replies. If a computer in the office is behaving strangely, our sister site handles computer repair and virus removal, and the same logic applies at home, which we walked through in our guide to AI-driven attacks on home networks.

The Short Version

AI made fraud fluent and cheap, and cheap is what put small businesses on the list. It did not make the fraud smarter, and it did not change where the money goes or how it gets there. The tools attackers use keep getting easier to reach, something we wrote about after researchers found compromised models on Hugging Face.

A business that adopts one written rule, confirms every money or access request on a second channel using a number it already had, and tells staff they are allowed to use it, has closed most of its realistic exposure for zero dollars. A business that buys AI detection software and skips the rule has bought nothing at all.

Start with the sentence. Then the contact list. Then passkeys. That is a week's work, and it is worth more than anything you can subscribe to.

Buffalo Businesses: Let Us Look at Your Setup

AldoMedia builds, hosts and maintains websites for small businesses across Western New York, and keeps the pieces around them current: platform updates, contact forms, hosting and email. If you want a second opinion on where your business is exposed, ask.

Contact AldoMedia Buffalo Web Design & SEO

Sources

Frequently Asked Questions

What is business email compromise?

Business email compromise is a scam where somebody poses as a person you already trust, a vendor, a manager, a bank, and asks you to send money or to change where money gets sent. The FBI Internet Crime Complaint Center logged 24,768 BEC complaints in 2025 with $3,046,598,558 in reported losses, which works out to roughly $123,000 per complaint. There is often no malware and no hacking involved at all. It is a conversation that ends with a wire transfer.

Are AI scams really aimed at small businesses, or is that vendor marketing?

Both things are true at once. The fraud that actually hits small businesses is invoice and payment fraud, and the cyber insurer Coalition, which covers more than 100,000 policyholders, reported that business email compromise and funds transfer fraud together accounted for 58% of all claims in 2025. The organized AI calling crews documented by Google and the FBI are a different story, because they go after large enterprises with ransom demands in the millions. Plan for the payment fraud, not the movie plot.

What is the second channel rule?

Any request that moves money or changes who can log in gets confirmed on a channel the requester did not choose, using contact details you already had. Not the phone number printed in the email. Not the number the caller reads out to you. The one already sitting in your own records. The FBI puts it plainly in its own guidance: use secondary channels and/or two-factor authentication to verify requests for changes in account information.

How can I tell whether a call from our bank or IT provider is real?

Usually you cannot tell from the call itself, and caller ID is not proof, because attackers have been observed spoofing a company's own real helpdesk number. The FBI advice is to hang up and call back: verify the identity of the person calling you by hanging up the phone, researching the contact of the bank or organization purporting to call you, and call the phone number directly. A real bank or a real vendor will never have a problem with that.

Should a small business worry about deepfake video calls?

Not as a first priority. The best documented case is still the 2024 incident at the engineering firm Arup in Hong Kong, where a finance employee joined a video call on which the other colleagues were AI-generated and made transfers totaling about $25 million. That worked at a global firm where an employee had never met the executives in person. The FBI numbers keep it in proportion: out of $3.05 billion in 2025 BEC losses, only $30.3 million across 135 complaints carried an AI tag.

What is the cheapest thing I can do this week to reduce the risk?

Write one sentence down and tell your staff it is policy: no bank detail change, no new payee, and no password or login code handed over without a callback to a number already in our records. Then say out loud that nobody will ever be in trouble for slowing a request down, including a request that appears to come from the owner. After that, turn on phishing-resistant multifactor authentication such as passkeys on email and banking.

Find our articles helpful? Add us on Google so more of our posts show up for you.

Add AldoMedia as a Preferred Source on Google

Are you ready to meet us? make an appointment today.

We have a comfortable office and conference room built to get our conversation going and our creative juices flowing.