WordPress category: blog
AI-generated scams are affecting small businesses through email, phone calls, video meetings, text messages, and collaboration platforms.
Attackers can imitate:
- Business owners
- Executives
- Employees
- Vendors
- Customers
- Financial institutions
- IT support personnel
The request may involve:
- Wire transfers
- Bank account changes
- Payroll updates
- Gift card purchases
- Password resets
- MFA codes
- Remote access
- Sensitive documents
- New shipping addresses
The content may look professional.
The voice may sound familiar.
The video may appear authentic.
Identity must still be verified through an established process.
The Main Risk
Traditional phishing often contained visible warning signs
- Poor grammar
- Generic messaging
- Suspicious formatting
- Unusual sender addresses
AI can remove many of these signs.
Messages can be personalized and grammatically correct.
Voice cloning can imitate a known person.
Synthetic video can be used during a live or recorded meeting.
The attack remains social engineering.
Urgency and authority are used to bypass normal controls.
Small businesses are exposed when approvals depend on informal habits
- “The owner called”
- “The CFO approved it”
- “The vendor changed banks”
- “IT needs the MFA code”
- “This must be completed before close of business”
A familiar voice or face cannot replace verification.
Verification Protocols
Use out-of-band verification
Any request involving money credentials or sensitive data should be verified through a separate channel.
The second channel must already be trusted.
Examples:
- Call the requester using a stored phone number
- Contact the employee through the company directory
- Send a message through an established Teams or Slack account
- Confirm the request in person
- Contact a vendor using information already stored in accounting records
Do not use:
- The phone number in the suspicious message
- A new email address provided in the request
- A link supplied by the sender
- A callback number shown in a caller ID
- A personal communication channel introduced during the request
The attacker may control the original message and its contact details.
CISA recommends avoiding links and phone numbers supplied in suspicious messages. Use contact information from a verified website or existing business records instead. See the CISA phishing guidance.

Require two-person approval
High-risk actions should not depend on one employee.
Use dual control for:
- Wire transfers
- Vendor payment changes
- Payroll account changes
- Banking detail updates
- Large purchases
- New administrator accounts
- Remote access approvals
The second approver should perform an independent verification.
The first employee’s confirmation should not be treated as sufficient.
Define the approval threshold in writing.
Remove single-person exceptions.
Establish a cooling-off period
New payment instructions should not be used immediately.
Require a delay for:
- New vendors
- Changed bank accounts
- Updated payment destinations
- New payroll instructions
- Unusual shipping changes
A 24-hour delay provides time for separate-channel confirmation.
Urgency does not override the delay.
Exceptions create an alternate path for attackers.
Use private verification phrases
Executives and finance personnel can establish private passphrases for sensitive requests.
The phrase should be:
- Agreed to in person
- Excluded from email and public chat
- Changed when exposure is suspected
- Used only for defined high-risk actions
A cloned voice may be convincing.
It will not know a current private phrase that has not been exposed.
Passphrases are one control.
They should not replace MFA or dual approval.
Do not approve transactions by voice or video alone
A phone call or video meeting is not sufficient authorization for a financial change.
After the meeting:
- End the call
- Use a known contact method
- Confirm the request
- Record the confirmation
- Complete the transaction through the normal system
This applies even when:
- The face appears correct
- The voice sounds familiar
- The meeting includes multiple participants
- The request references current business activity
- The person uses an executive title
Security Awareness
Employees need a process.
They do not need to diagnose whether a video is technically fake.
Training should focus on actions and triggers.
Common warning signs
- Requests for immediate action
- Instructions that bypass normal approval
- Changes to payment or banking information
- Requests for MFA codes
- Requests for passwords
- Gift card purchases
- Unusual shipping destinations
- Personal email or messaging accounts
- New phone numbers
- Unexpected remote access requests
- Secrecy requirements
- Pressure not to contact another employee
CISA notes that AI-generated phishing may contain correct grammar and spelling. Staff should focus on sender identity, request context, urgency, links, and verification requirements.
Train on realistic examples
Security awareness training should include:
- AI-written phishing emails
- Synthetic voicemail examples
- Fake executive payment requests
- Vendor impersonation
- MFA approval requests
- Deepfake video scenarios
- Payroll diversion attempts
- IT support impersonation
Training should be repeated.
Quarterly sessions provide more coverage than one annual presentation.
Use short exercises.
Measure whether employees:
- Reported the request
- Avoided links and attachments
- Used the approved verification method
- Escalated the issue
- Preserved the evidence
Create a safe-refusal policy
Employees should be permitted to delay or refuse high-risk requests.
Use a standard response:
For security, this request must be verified through the standard process
The employee should not need executive permission to follow security policy.
No employee should be penalized for requiring verification.
Attackers often use seniority and urgency to discourage questions.
Written policy removes that pressure.
Technical Controls
Verification protocols reduce fraud risk.
Technical controls reduce account and system compromise.
Use phishing-resistant MFA
Deploy MFA for:
- Business email
- Cloud platforms
- Financial systems
- Remote access
- Administrative accounts
- Password managers
- Backup consoles
Use phishing-resistant methods where available, including FIDO2 security keys or passkeys.
SMS-based MFA is better than no MFA.
It should not be the final control for high-value accounts when stronger options are available.
Apply email security controls
Email security should inspect:
- Sender authentication
- Spoofed domains
- Malicious links
- Attachments
- Impersonation indicators
- Display-name abuse
- Unusual sending patterns
Domain controls such as SPF, DKIM, and DMARC should be configured and reviewed.
Finance and executive accounts require additional monitoring.
Protect endpoints
Endpoints should be monitored for:
- Credential theft
- Malware
- Unauthorized remote tools
- Suspicious browser activity
- Unusual login behavior
- Data exfiltration
- Unauthorized software
Updates should be installed on schedule.
Administrative access should be restricted.
Personal devices should not receive unrestricted access to business systems.
Segment business systems
Network segmentation limits the effect of a compromised account or endpoint.
Separate critical systems where practical:
- Finance
- File storage
- Backups
- Servers
- Guest wireless
- VoIP systems
- Administrative devices
Access should be based on business need.
Network design and maintenance are part of X-Tek’s business IT and infrastructure services.

X-Tek Managed Security
Small businesses may not have internal staff available to review alerts, enforce controls, and respond to incidents.
X-Tek managed support can be used to support a layered security program that includes:
- 24/7 security monitoring
- Backup monitoring
- Endpoint protection
- MFA configuration
- Email security
- Network security review
- Patch management
- Access control
- Security awareness support
- Incident escalation
- Recovery coordination
Monitoring should not be limited to business hours.
Suspicious activity may occur at night or during a weekend.
Alerts should be reviewed.
Threats should be contained.
Accounts should be secured.
Evidence should be preserved.
X-Tek’s managed IT services information provides additional context for ongoing support and monitoring.
The company’s AI-powered attack readiness guidance covers network controls, segmentation, backups, monitoring, and policy requirements.
Incident Response
If a suspected deepfake or phishing request is received:
- Stop the requested action
- Do not reply
- Do not click links or attachments
- Do not provide credentials or MFA codes
- Contact the supposed requester through a known channel
- Notify IT or the managed security provider
- Preserve emails, recordings, messages, and call details
- Contact the bank immediately if funds were transferred
- Reset affected credentials
- Review sign-in and endpoint activity
- Report cyber-enabled crime through the FBI Internet Crime Complaint Center
If an account may have been compromised, isolate the device when instructed.
Do not delete evidence before it has been reviewed.
If an employee followed the request, report it immediately.
Delayed reporting increases recovery time and may reduce the chance of stopping a payment.

Small Business Baseline
Implement these controls first:
- Written verification process for financial and account changes
- Out-of-band confirmation using known contact information
- Two-person approval for high-value transactions
- Cooling-off period for changed payment instructions
- Phishing-resistant MFA for critical accounts
- Email authentication and impersonation protection
- Endpoint monitoring
- Network segmentation
- Quarterly security awareness training
- Annual phishing or social engineering exercise
- Documented incident response contacts
- 24/7 security and backup monitoring
- Regular review of public executive information
The objective is not to determine whether every voice or video is genuine.
The objective is to prevent an unverified request from producing a business impact.
Verification protocols, security awareness, and managed security controls should operate together.
Request an assessment through the X-Tek Business Solutions Information Request.
Contact Information
Business Solutions Information Request:
https://xtekit.com/business-solutions-information-request/
815-516-8075

