The Email That Would Have Fooled Me Wasn't Even Trying to Sell Me Anything
A few months ago someone in my extended network almost transferred money to what he was certain was his usual supplier, because the email looked exactly right, same tone, same signature format, even a reference to a real invoice number from a previous order. It wasn't the supplier. He caught it at the last second because something about the bank details felt slightly off and he made one phone call before hitting send. That phone call is the only reason this story doesn't end with him explaining a missing payment to his accountant.
That near miss is becoming the normal story now, not the exception, and the reason is almost entirely AI. It's worth understanding exactly how, because the advice that used to work, look for bad grammar, watch for a weird sender address, mostly doesn't anymore.
Why the old advice stopped working
The classic phishing email had tells. Spelling mistakes, awkward phrasing, a sender address that didn't quite match, an urgency that felt manufactured. Those tells existed because a scammer, often not a native English speaker, was writing at scale and cutting corners. AI removed almost all of that friction. A scammer can now generate a flawless, perfectly toned email in seconds, one that reads exactly like it came from a real colleague or supplier, because it was written by a model trained on exactly that kind of writing.
It goes further than text now too. Voice cloning has gotten good enough that a scammer can call someone, using a voice cloned from a few seconds of publicly available audio, a video posted online, a voicemail greeting, and sound convincingly like a real person's boss or business partner asking for an urgent transfer. There are documented cases of fake video calls being used the same way, not just audio.
The scale of what this is actually costing people
The dollar figures here are large enough that they're worth sitting with rather than skimming past. Business email compromise, the specific category of scam where someone impersonates a real contact to redirect a payment, moved more than six billion dollars out of victims' accounts in a single recent year according to FBI reporting. Ransomware has shifted too, attackers increasingly steal a copy of a company's data before encrypting anything, which means having backups isn't enough protection anymore, because the threat isn't just losing access to your files, it's the threat of your data being published or sold regardless of whether you pay. Average ransom demands aimed at small and mid-sized businesses now reportedly run well past a hundred thousand dollars, before counting the cost of the actual downtime.
And small businesses aren't collateral damage in all this, they're a specific target. Roughly four in ten cyberattacks now hit businesses with under 250 employees, not because those businesses have anything more valuable to steal, but because attackers correctly assume they have thinner defenses, smaller security budgets, and often nobody whose full-time job is watching for this.
What actually helps, and it's less complicated than it sounds
The good news buried in all this research is that the defenses that work best aren't expensive or technical in a way that requires hiring a security team. They're mostly about habits.
The single biggest one is verifying anything unusual through a second, separate channel before acting on it. If an email asks you to change payment details or wire money somewhere new, even if it looks completely legitimate, even if it references real details about your actual business, call the person using a phone number you already had on file, not one provided in the email itself. That one habit alone would have stopped the near miss I mentioned at the start, and it stops the overwhelming majority of these scams, because the fake version almost never survives a phone call to a number the scammer doesn't control.
Multi-factor authentication matters more now than it used to, because even a flawless phishing email is trying to get someone to hand over a password or click a link, and a second layer of verification breaks that chain even if the first step succeeds. Basic email filtering catches a real chunk of this before it even reaches an inbox. And ongoing, casual training, not a boring annual seminar nobody remembers, but occasionally just talking through a real example as a team, keeps the instinct to pause and double check somewhere near the front of people's minds instead of buried under everything else they're dealing with that day.
The mindset shift that actually matters most
I think the hardest part of adjusting to this isn't learning new tools, it's unlearning the old assumption that a scam email looks obviously wrong. It doesn't anymore. It can look exactly right, reference real information, sound exactly like the person it's pretending to be, and still be completely fake. The instinct to trust something because it looks and sounds correct is precisely the instinct AI has gotten good enough to exploit.
The businesses handling this well right now aren't the ones with the most expensive security software. They're the ones that built one simple rule into how they operate: anything involving money or sensitive information gets verified a second way before it happens, no matter how legitimate it looks the first time. It's a small habit that costs nothing and takes thirty extra seconds, which is a fairly reasonable trade against a mistake that, for a lot of small businesses, wouldn't just be expensive. It would be the kind of loss some of them don't come back from.