How small businesses can stop AI phishing and payment fraud
AI makes fraudulent messages faster to produce and easier to personalize, but it does not change the central weakness criminals exploit: a rushed person approving a sensitive action through an untrusted channel.
Assume polished messages can be fake
Grammar, logos and a familiar writing style are no longer useful proof. Treat every request to change banking details, buy gift cards, disclose a code, reset access or send confidential files as a high-risk transaction—even when it appears to come from an executive or supplier.
Separate the request from the approval
Create a written rule: sensitive requests received by email, chat or voicemail must be confirmed through a second, independently selected channel. Call a known number from your records, open the supplier portal directly or speak face to face. Never use the phone number or link supplied in the suspicious message.
Put controls around money movement
- Require two people to approve new payees and bank-detail changes.
- Set transfer limits and bank alerts appropriate to normal activity.
- Maintain verified payment details outside the email inbox.
- Pause when a request adds secrecy, urgency or an unusual exception.
Harden the accounts attackers imitate
Use phishing-resistant multifactor authentication or passkeys where available, unique passwords stored in a business password manager and separate administrator accounts for privileged work. Remove access promptly when roles change. Configure email authentication and watch for suspicious forwarding rules, unfamiliar sign-ins and newly registered lookalike domains.
Train with decisions, not trivia
Awareness training should rehearse the actions employees must take: identify a protected request, stop, verify it independently and report it quickly. Use examples drawn from payroll, invoices, password resets, shared documents and executive requests. A five-minute exercise repeated quarterly is more useful than an annual slideshow nobody remembers.
Prepare the first 30 minutes
If money or credentials may have been exposed, speed matters. Employees should know one internal reporting route. The response owner should be able to contact the bank, revoke sessions, reset affected credentials, preserve evidence and notify the appropriate insurer or authorities. Write those contacts down before an incident.