For most of the last decade, the businesses targeted by sophisticated impersonation fraud were large ones. A convincing scam took research, writing skill, a plausible accent on the phone, and the patience to work one target for weeks — effort that only paid off against a company with a treasury function. If you had eleven staff and a bookkeeper, you were protected by not being worth the trouble.
Generative AI has removed that protection. Cloning a voice now takes a few seconds of audio from a podcast appearance or a voicemail greeting, and costs roughly the price of a coffee. Writing a flawless email in your supplier's house style takes one prompt. Faking a face on a video call is no longer a research project. The attacks that used to be reserved for multinationals now scale down to a ten-person agency, because the marginal cost of attempting one has collapsed to almost nothing.
This guide covers what those attacks look like in 2026, why the defences most small businesses rely on no longer hold, and the verification habits that stop them. None of it requires new software or a security budget.
How AI changed the economics of small-business fraud
It helps to think about fraud the way you think about your own marketing funnel: an attacker has a cost per attempt and a conversion rate. Cost per attempt used to be high — manual research, hand-written emails, a human on the phone — so attackers needed a large payout to justify it, which meant large targets.
AI pushed that cost towards zero while pushing conversion up. One operator can research two hundred companies from LinkedIn and your own website, generate two hundred emails that reference your actual clients and invoicing cycle, clone two hundred directors' voices from public audio, and run the campaign in an afternoon. At that cost base, a €4,000 invoice redirect is a perfectly good outcome. Your business does not need to be rich to be worth attacking — only reachable.
The second shift is harder to accept: the quality tells are gone. Owners spent twenty years learning to spot fraud by its texture — clumsy grammar, odd formatting, a stilted phone manner. Those were never security controls. They were artefacts of an attacker working at scale in a second language. AI removed the artefacts and left the attack.
The five attacks hitting SMBs right now
1. Voice-cloned authority calls. Your bookkeeper gets a call that sounds exactly like you, from a number that looks plausible, saying you are in a meeting and need a payment released today. The audio source was probably a webinar you did, a radio interview, or thirty seconds of your outgoing voicemail. This is the single most effective attack against businesses with fewer than fifty staff, because small firms run on trusted voices rather than process.
2. Deepfake video calls. In the most widely reported case to date, a finance employee at a large engineering firm joined what looked like a routine call with several colleagues, including the CFO. Every participant was synthetic, and tens of millions were transferred. What matters to a small business is not the amount — it is that a video call has stopped being proof of identity.
3. Supplier and invoice redirection. An attacker who has read your case studies and your suppliers' websites can write an email that names the right account manager, references the right project, attaches an invoice in the right template — and announces new bank details. It is the highest-volume attack and the most expensive in aggregate, precisely because it does not feel like an attack. It feels like admin.
4. Fake candidates and fake contractors. Remote hiring is now a fraud vector: AI-generated CVs, interview answers fed in real time, and in some cases a synthetic face on the call, used to reach systems and payroll. For a small agency that hires contractors quickly and onboards them with broad permissions, this is a serious and underrated exposure.
5. Your own AI tools as the entry point. The less dramatic risk, and the more common one: staff pasting client data into free consumer AI accounts, connecting unvetted AI browser extensions to the company inbox, or wiring an automation to a shared drive without anyone reviewing its permissions. No impersonation is needed. The data simply leaves. Our guide to AI data security for small business covers that side in detail.
Why your current defences do not work any more
Three defences that most small businesses still rely on have quietly stopped working.
"I would recognise their voice." You would recognise a clone too. Voice is no longer an identity credential, and once you accept that, a surprising amount of your approval process turns out to rest on it.
"We are too small to be a target." This was true when attacks were manual. It is now the equivalent of saying your shop is too small to receive spam.
"Our staff are trained to spot phishing." Training based on spotting bad writing trains people on a signal that no longer exists. Worse, it creates false confidence: a team that believes it can spot fraud by feel is less likely to follow a verification step that feels unnecessary.
The replacement for all three is the same, and it is deliberately boring: stop authenticating people by how they seem, and start authenticating requests by the channel they arrive through.
The verification protocol that actually stops this
Every attack above has one structural weakness. It needs a payment, a credential, or a data transfer to be approved inside the channel the attacker controls. Break that, and the attack fails regardless of how convincing it was.
Four rules. Write them down, put them on one page, and make them non-negotiable.
- Callback on a stored number, never a supplied one. Any request to change bank details, release an unusual payment, or reset access gets verified by hanging up and calling the number already in your records. Not the number that called you, not the number in the email signature. This one rule defeats voice cloning and invoice redirection outright.
- A shared passphrase for urgent money. Agree a word with anyone who can authorise or request payments — you, your bookkeeper, your office manager. Any urgent financial request made by voice or video requires it. It costs nothing and cannot be cloned, because it was never published.
- Two humans above a threshold. Pick a number that would genuinely hurt — for most SMBs somewhere between €1,000 and €5,000 — and require a second person's approval above it, in a different channel from the request. Urgency is not an exemption. Urgency is the tell.
- Bank-detail changes have a fixed cooling-off period. Twenty-four hours, verified by callback, no exceptions for a supplier you have used for a decade. Genuine suppliers are never harmed by this. Attackers depend entirely on speed.
Notice that none of these rules asks anyone to detect anything. That is the point. Detection is the part AI has broken; process is the part it cannot touch.
One addition is worth making. Most successful authority fraud works because a junior employee suspected something and did not want to appear to doubt the boss. Say out loud that nobody will ever be criticised for verifying a request from you, and put that sentence in writing — our walkthrough on how to write an AI policy for your small business has a place for it.
A 90-minute rollout for a team of ten
This does not need a project. Block out an afternoon and do it in five steps.
Minutes 0–15: list who can move money. Everyone who can initiate, approve, or change a payment, including external bookkeepers and virtual assistants. For most SMBs this is three to five people, and writing the list down is often the first time anyone has seen it.
Minutes 15–30: set the threshold and the passphrase. Pick both, tell exactly the people on that list, and store the passphrase nowhere digital that an attacker could reach — not the shared drive, not the group chat.
Minutes 30–50: fix the supplier record. One file with each supplier's verified phone number, taken from an old invoice or a known contact, never from the most recent email. Without this file, rule one is decorative.
Minutes 50–70: brief the team in plain language. No slides. Explain what voice cloning is, scare nobody, and give them the four rules plus explicit permission to apply them to you.
Minutes 70–90: audit your AI tool access. List every AI tool anyone uses with company data, who pays for it, and what it can read. You can run this as a simple prompt in whatever assistant you already use:
"Act as a security reviewer for a small business. I will list our AI tools and what data each one can access. For each, identify what an attacker could obtain if that account were compromised, rank the tools by blast radius, and tell me which three permissions to remove first. Be concrete and brief."
Then feed it your list. It is no substitute for judgement, but it reliably surfaces the integration nobody remembered authorising.
What to do in the first hour after a suspected attack
Speed matters more than diagnosis. In order: call your bank's fraud line and ask for a recall — funds are sometimes recoverable within hours and almost never after days. Freeze the account or revoke the credential before investigating why. Tell the real counterparty through a verified channel, because they are probably being attacked too. Capture timestamps, numbers and screenshots while they exist. Report it to your national fraud body, then your insurer.
Then check your cover before you need it. Many standard policies exclude voluntary transfers — money you were tricked into sending — which is exactly what these attacks produce. Read AI liability and insurance for small businesses, then ask your broker directly: does this policy pay out if an employee was deceived into authorising a payment?
Deciding all of this during an incident is how small businesses lose money twice. Decide it now, on a page, while nothing is on fire.
The bottom line
AI has not invented a new category of fraud. It removed the cost and the clumsiness from an old one, which means the protection that came from being small and unremarkable is gone. The countermeasure is unglamorous and cheap: a callback rule, a passphrase, a second pair of eyes above a threshold, a cooling-off period on bank details. Four rules, one page, ninety minutes.
Businesses that get hit in 2026 will not be the ones that failed to buy a tool. They will be the ones still authenticating people by how convincing they sound.
Where does your business stand on AI?
Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.
Take the Free Quiz →