How small businesses can stop AI phishing and payment fraud

AI makes fraudulent messages faster to produce and easier to personalize, but it does not change the central weakness criminals exploit: a rushed person approving a sensitive action through an untrusted channel.

Assume polished messages can be fake

Grammar, logos and a familiar writing style are no longer useful proof. Treat every request to change banking details, buy gift cards, disclose a code, reset access or send confidential files as a high-risk transaction—even when it appears to come from an executive or supplier.

Separate the request from the approval

Create a written rule: sensitive requests received by email, chat or voicemail must be confirmed through a second, independently selected channel. Call a known number from your records, open the supplier portal directly or speak face to face. Never use the phone number or link supplied in the suspicious message.

Put controls around money movement

Harden the accounts attackers imitate

Use phishing-resistant multifactor authentication or passkeys where available, unique passwords stored in a business password manager and separate administrator accounts for privileged work. Remove access promptly when roles change. Configure email authentication and watch for suspicious forwarding rules, unfamiliar sign-ins and newly registered lookalike domains.

Train with decisions, not trivia

Awareness training should rehearse the actions employees must take: identify a protected request, stop, verify it independently and report it quickly. Use examples drawn from payroll, invoices, password resets, shared documents and executive requests. A five-minute exercise repeated quarterly is more useful than an annual slideshow nobody remembers.

Prepare the first 30 minutes

If money or credentials may have been exposed, speed matters. Employees should know one internal reporting route. The response owner should be able to contact the bank, revoke sessions, reset affected credentials, preserve evidence and notify the appropriate insurer or authorities. Write those contacts down before an incident.