AI Scams Are Now Aimed at Businesses Like Yours — Here's the Playbook That Stops Them

shape
shape
shape
shape
shape
shape
shape
shape
A gold real-voice waveform that splits into a jagged red AI voice clone, with the line 'It's me. I need a wire today.' — your boss never said it, a model did

For as long as there have been telephones, the defense against a con artist was your gut. Something about the voice sounded off. The email had a typo. The story didn’t quite add up. Your ears and eyes were the security system.

In 2026 that system is offline. AI now writes flawless emails in perfect Brooklyn-English or your vendor’s native language, clones a voice from a three-second voicemail greeting, and puts your boss’s face in a live video call. The gut is no longer a sensor — and every small business in Brooklyn is getting the calls.

We’re a repair and networking shop on Lincoln Place. We see the machines after the worst day — the ones whose owners wired the money, clicked the invoice, gave up the login. Almost every one of those losses traces back to the same handful of scams, and every one of them is stoppable with cheap, boring process. Here’s the whole playbook.

The $25 Million Video Call

Start with the most instructive case on record. In early 2024, an accountant at the engineering firm Arup joined a video call with what looked and sounded like the company’s chief financial officer and several colleagues. Every participant was a deepfake. Believing the transaction was legitimate, the accountant transferred about $25 million to the criminals. Arup is a 15,000-person engineering giant with real security staff. If it can happen to them on a video call, it can happen on a phone call to a ten-person office in Sunset Park.

The FBI’s Internet Crime Complaint Center logged $16.6 billion in reported cybercrime losses in 2024, up 33% in a single year. AI didn’t invent these scams — it removed the two things that used to limit them: the skill to sound convincing and the hours needed to hand-craft each attempt.

The New Scam Toolkit

Voice cloning — the three-second theft

A few seconds of audio is enough to build a passable clone; a minute of a podcast, a Zoom recording, or a voicemail builds a good one. The classic play: the “owner” calls the bookkeeper from an unfamiliar number, apologetic, in a hurry — new bank, vendor deadline, please handle it quietly. The voice is right. The only thing real about the call is the money leaving.

AI-written spear phishing — personalized at scale

The typo-ridden prince email is dead. Today’s lures quote your real vendor names, your real invoice numbers scraped from a breached portal, your real staff’s names from LinkedIn — and agents can generate thousands of variants an hour, each tuned to its target. This is the automation shift we explain in cybersecurity in the age of agentic AI: the recon that used to take a criminal weeks now takes a script minutes.

The fake invoice, upgraded

A real-looking PDF arrives from a real-looking vendor with updated bank details — often timed to a genuine payment cycle the attacker learned from a compromised email thread. Nobody gets yelled at or rushed; the payment just quietly reroutes. Companies discover it when the real vendor calls about the overdue balance.

Deepfake video — for when they need you to look

Reserved for the expensive plays: the approval meeting, the “let’s get on a quick call” verification. Arup proved it works. The takeaway is not “distrust video” — it’s that no medium is proof of identity anymore. Proof comes from process now, not from senses.

Red Flags That Still Survive the AI Era

The fake is better every month, but the shapeof the scam hasn’t changed. Watch for these — they matter more than any technical detail:

  • Urgency plus secrecy.“Don’t tell anyone yet” + “it has to clear today” is not how real business works. It is exactly how fraud works.
  • A channel change.The thread moves from your accounting portal to a personal Gmail, or a call comes from an unknown number right when the boss is “traveling.”
  • New bank details. Ever.For anything. The single most profitable sentence in fraud is “we’ve switched banks — here are the new wire instructions.”
  • The request skips the process. No purchase order, no second approver, no paper trail — just this once, just handle it.
  • Refusal of a callback. A legitimate counterpart never minds a thirty-second verification call. A scammer cannot survive one.

The 60-Second Verification Protocol

Checklist graphic titled 'The 60-second verification protocol': hang up and call back on a known number; no money moves on voice or text alone; new bank details require confirmation by two people; agree on a code word for urgent money requests

Print this. Tape it near the phone and the register. Walk every employee through it once — it defeats every scam in this article, voice clones included:

  1. Hang up. Call back on a number you already have — from your vendor list, your contract, the back of the card. Never the number in the email, text, or voicemail that made the request.
  2. No money moves on voice or text alone. Wire changes, gift cards, crypto, “urgent invoices” — confirmed live, in person or on video, by someone with authority to say no.
  3. New bank details require two humans. One calls the old number on file; a second signs off before the first payment clears on the new one.
  4. Agree on a code word for urgent money requests from the owner. Thirty seconds at the next staff meeting beats a five-figure loss forever.

Technical Guardrails We Install So You Don’t Have to Think About It

Process stops the individual scam. These stop the campaign:

  • SPF, DKIM, and DMARCon your domain, tuned so criminals can’t impersonate you to your own clients and their forgeries to your staff land in junk. Most Brooklyn businesses we survey have none of the three.
  • Mail filtering with attachment detonation so a malicious invoice opens in a sandbox, not on your bookkeeper’s desktop.
  • MFA on every account, including email and the bank — so a phished password alone opens nothing.
  • DNS filtering so a clicked link never reaches its fake login page.
  • Segmented, monitored network so when something does get through, it lands in a VLAN with nowhere to go — see what that looks like in our guide to business network security installation in Brooklyn.

If It Already Happened: The First 24 Hours

  1. Call your bank now. Request a recall or freeze on the transfer — success rates collapse after the first hours.
  2. Report it. FBI at ic3.gov and your local precinct. Insurers and banks ask for these reports.
  3. Preserve everything— emails, the invoice, call logs, the transaction record. Don’t “clean up” anything.
  4. Disconnect the affected machinefrom the network (pull the cable / kill Wi-Fi — don’t power it off) so nothing spreads.
  5. Then call us: (929) 487-3802. We scope what the attacker touched, rotate every credential that could be in their hands, and rebuild the doors they came through — properly this time.

Related reading: dental and medical offices carry the sharpest liability of anyone — we wrote up why hackers target dental offices and what the FBI recommends.

Frequently Asked Questions

Can someone really clone my voice from a short voicemail?

Yes. Modern tools produce a convincing clone from as little as three seconds of audio — a voicemail greeting, a social media video, or a minute of a recorded meeting is more than enough. That clone can then say anything, in your voice, in a live phone call.

What is CEO fraud or business email compromise?

A scam where an attacker impersonates an owner, manager, or vendor — by email, phone, or deepfake video — to push an employee into sending money, gift cards, or sensitive data. With AI, the impersonation is flawless in grammar, accent, and now face and voice. The FBI logged $16.6 billion in reported cybercrime losses in 2024, and this category remains among the costliest per incident.

How do I verify a suspicious call without insulting a real client?

Hang up and call back on a number you already have — the one on your vendor list or website, never the one the caller or an email provides. A legitimate client or vendor will never object to a thirty-second callback; a scammer always will. Any urgency, secrecy, or pressure around money is itself the red flag.

What technical settings stop AI phishing at the door?

SPF, DKIM, and DMARC email authentication so criminals cannot spoof your domain to your own staff and clients; aggressive spam and attachment filtering; multi-factor authentication on every account so a stolen password alone is useless; and DNS filtering so a clicked link never reaches its landing page. We install and maintain all four for Brooklyn businesses.

We already sent money to a scammer. What now?

Call your bank immediately and request a recall or freeze on the transfer — minutes matter. Then report it to the FBI at ic3.gov and to the NYPD, preserve every email, invoice, and phone record, and disconnect the affected machine before it spreads anything. Then call us at (929) 487-3802: we scope the compromise, check what else the attacker touched, and lock the doors they came through.

Sources

Contact Us

Want SPF/DMARC set up properly, the network segmented, and your staff briefed on the protocol — without becoming a security expert yourself? Talk to us here or call (929) 487-3802. Brooklyn businesses only need apply: we’re around the corner at 1339 Lincoln Place.

Stop the next AI scam before it wires $25k
Free Brooklyn walkthrough — verification protocol, email auth, firewall & Wi-Fi segmented the right way.

We Accept Donations

Send your crypto donations to Maxiaxxx.sol. All funds help towards moving our site to decentralized.