Deepfakes and Phishing: Protecting Your Business From AI-Generated Scams

WordPress category: blog

AI-generated scams are affecting small businesses through email, phone calls, video meetings, text messages, and collaboration platforms.

Attackers can imitate:

  • Business owners
  • Executives
  • Employees
  • Vendors
  • Customers
  • Financial institutions
  • IT support personnel

The request may involve:

  • Wire transfers
  • Bank account changes
  • Payroll updates
  • Gift card purchases
  • Password resets
  • MFA codes
  • Remote access
  • Sensitive documents
  • New shipping addresses

The content may look professional.

The voice may sound familiar.

The video may appear authentic.

Identity must still be verified through an established process.

The Main Risk

Traditional phishing often contained visible warning signs

  • Poor grammar
  • Generic messaging
  • Suspicious formatting
  • Unusual sender addresses

AI can remove many of these signs.

Messages can be personalized and grammatically correct.

Voice cloning can imitate a known person.

Synthetic video can be used during a live or recorded meeting.

The attack remains social engineering.

Urgency and authority are used to bypass normal controls.

Small businesses are exposed when approvals depend on informal habits

  • “The owner called”
  • “The CFO approved it”
  • “The vendor changed banks”
  • “IT needs the MFA code”
  • “This must be completed before close of business”

A familiar voice or face cannot replace verification.

Verification Protocols

Use out-of-band verification

Any request involving money credentials or sensitive data should be verified through a separate channel.

The second channel must already be trusted.

Examples:

  • Call the requester using a stored phone number
  • Contact the employee through the company directory
  • Send a message through an established Teams or Slack account
  • Confirm the request in person
  • Contact a vendor using information already stored in accounting records

Do not use:

  • The phone number in the suspicious message
  • A new email address provided in the request
  • A link supplied by the sender
  • A callback number shown in a caller ID
  • A personal communication channel introduced during the request

The attacker may control the original message and its contact details.

CISA recommends avoiding links and phone numbers supplied in suspicious messages. Use contact information from a verified website or existing business records instead. See the CISA phishing guidance.

Cybersecurity illustration showing independent communication channels connected by a verification shield

Require two-person approval

High-risk actions should not depend on one employee.

Use dual control for:

  • Wire transfers
  • Vendor payment changes
  • Payroll account changes
  • Banking detail updates
  • Large purchases
  • New administrator accounts
  • Remote access approvals

The second approver should perform an independent verification.

The first employee’s confirmation should not be treated as sufficient.

Define the approval threshold in writing.

Remove single-person exceptions.

Establish a cooling-off period

New payment instructions should not be used immediately.

Require a delay for:

  • New vendors
  • Changed bank accounts
  • Updated payment destinations
  • New payroll instructions
  • Unusual shipping changes

A 24-hour delay provides time for separate-channel confirmation.

Urgency does not override the delay.

Exceptions create an alternate path for attackers.

Use private verification phrases

Executives and finance personnel can establish private passphrases for sensitive requests.

The phrase should be:

  • Agreed to in person
  • Excluded from email and public chat
  • Changed when exposure is suspected
  • Used only for defined high-risk actions

A cloned voice may be convincing.

It will not know a current private phrase that has not been exposed.

Passphrases are one control.

They should not replace MFA or dual approval.

Do not approve transactions by voice or video alone

A phone call or video meeting is not sufficient authorization for a financial change.

After the meeting:

  1. End the call
  2. Use a known contact method
  3. Confirm the request
  4. Record the confirmation
  5. Complete the transaction through the normal system

This applies even when:

  • The face appears correct
  • The voice sounds familiar
  • The meeting includes multiple participants
  • The request references current business activity
  • The person uses an executive title

Security Awareness

Employees need a process.

They do not need to diagnose whether a video is technically fake.

Training should focus on actions and triggers.

Common warning signs

  • Requests for immediate action
  • Instructions that bypass normal approval
  • Changes to payment or banking information
  • Requests for MFA codes
  • Requests for passwords
  • Gift card purchases
  • Unusual shipping destinations
  • Personal email or messaging accounts
  • New phone numbers
  • Unexpected remote access requests
  • Secrecy requirements
  • Pressure not to contact another employee

CISA notes that AI-generated phishing may contain correct grammar and spelling. Staff should focus on sender identity, request context, urgency, links, and verification requirements.

Train on realistic examples

Security awareness training should include:

  • AI-written phishing emails
  • Synthetic voicemail examples
  • Fake executive payment requests
  • Vendor impersonation
  • MFA approval requests
  • Deepfake video scenarios
  • Payroll diversion attempts
  • IT support impersonation

Training should be repeated.

Quarterly sessions provide more coverage than one annual presentation.

Use short exercises.

Measure whether employees:

  • Reported the request
  • Avoided links and attachments
  • Used the approved verification method
  • Escalated the issue
  • Preserved the evidence

Create a safe-refusal policy

Employees should be permitted to delay or refuse high-risk requests.

Use a standard response:

For security, this request must be verified through the standard process

The employee should not need executive permission to follow security policy.

No employee should be penalized for requiring verification.

Attackers often use seniority and urgency to discourage questions.

Written policy removes that pressure.

Technical Controls

Verification protocols reduce fraud risk.

Technical controls reduce account and system compromise.

Use phishing-resistant MFA

Deploy MFA for:

  • Business email
  • Cloud platforms
  • Financial systems
  • Remote access
  • Administrative accounts
  • Password managers
  • Backup consoles

Use phishing-resistant methods where available, including FIDO2 security keys or passkeys.

SMS-based MFA is better than no MFA.

It should not be the final control for high-value accounts when stronger options are available.

Apply email security controls

Email security should inspect:

  • Sender authentication
  • Spoofed domains
  • Malicious links
  • Attachments
  • Impersonation indicators
  • Display-name abuse
  • Unusual sending patterns

Domain controls such as SPF, DKIM, and DMARC should be configured and reviewed.

Finance and executive accounts require additional monitoring.

Protect endpoints

Endpoints should be monitored for:

  • Credential theft
  • Malware
  • Unauthorized remote tools
  • Suspicious browser activity
  • Unusual login behavior
  • Data exfiltration
  • Unauthorized software

Updates should be installed on schedule.

Administrative access should be restricted.

Personal devices should not receive unrestricted access to business systems.

Segment business systems

Network segmentation limits the effect of a compromised account or endpoint.

Separate critical systems where practical:

  • Finance
  • File storage
  • Backups
  • Servers
  • Guest wireless
  • VoIP systems
  • Administrative devices

Access should be based on business need.

Network design and maintenance are part of X-Tek’s business IT and infrastructure services.

Layered security illustration showing cloud email, endpoints, MFA, monitoring, and network protection

X-Tek Managed Security

Small businesses may not have internal staff available to review alerts, enforce controls, and respond to incidents.

X-Tek managed support can be used to support a layered security program that includes:

  • 24/7 security monitoring
  • Backup monitoring
  • Endpoint protection
  • MFA configuration
  • Email security
  • Network security review
  • Patch management
  • Access control
  • Security awareness support
  • Incident escalation
  • Recovery coordination

Monitoring should not be limited to business hours.

Suspicious activity may occur at night or during a weekend.

Alerts should be reviewed.

Threats should be contained.

Accounts should be secured.

Evidence should be preserved.

X-Tek’s managed IT services information provides additional context for ongoing support and monitoring.

The company’s AI-powered attack readiness guidance covers network controls, segmentation, backups, monitoring, and policy requirements.

Incident Response

If a suspected deepfake or phishing request is received:

  1. Stop the requested action
  2. Do not reply
  3. Do not click links or attachments
  4. Do not provide credentials or MFA codes
  5. Contact the supposed requester through a known channel
  6. Notify IT or the managed security provider
  7. Preserve emails, recordings, messages, and call details
  8. Contact the bank immediately if funds were transferred
  9. Reset affected credentials
  10. Review sign-in and endpoint activity
  11. Report cyber-enabled crime through the FBI Internet Crime Complaint Center

If an account may have been compromised, isolate the device when instructed.

Do not delete evidence before it has been reviewed.

If an employee followed the request, report it immediately.

Delayed reporting increases recovery time and may reduce the chance of stopping a payment.

Incident response illustration showing a paused payment, evidence file, alert console, and escalation workflow

Small Business Baseline

Implement these controls first:

  • Written verification process for financial and account changes
  • Out-of-band confirmation using known contact information
  • Two-person approval for high-value transactions
  • Cooling-off period for changed payment instructions
  • Phishing-resistant MFA for critical accounts
  • Email authentication and impersonation protection
  • Endpoint monitoring
  • Network segmentation
  • Quarterly security awareness training
  • Annual phishing or social engineering exercise
  • Documented incident response contacts
  • 24/7 security and backup monitoring
  • Regular review of public executive information

The objective is not to determine whether every voice or video is genuine.

The objective is to prevent an unverified request from producing a business impact.

Verification protocols, security awareness, and managed security controls should operate together.

Request an assessment through the X-Tek Business Solutions Information Request.

Contact Information
Business Solutions Information Request:
https://xtekit.com/business-solutions-information-request/
815-516-8075