+44 (0) 203 695 7554

[email protected]

Helpdesk Mon–Fri 8:00–18:00 · Sales 9:00–17:00

For years, the advice for spotting a scam email was simple: look for poor spelling, odd formatting and a generic greeting. AI has changed that. Criminals now use the same tools as everyone else to write flawless emails, produce convincing invoices and even clone a director’s voice. AI scams are one of the fastest-growing threats facing UK businesses, and small organisations are firmly in the firing line.

Person holding a smartphone

Key takeaways

  • Always confirm changes to bank details by phone, using a number you already hold.
  • Require two people to approve larger payments.
  • Agree a call-back rule for unusual requests from directors.
  • Protect email with MFA, SPF, DKIM and DMARC.

Three AI scams to watch for

1. Deepfake voice and video calls

With just a few minutes of audio from a webinar, podcast or social media video, attackers can clone someone’s voice. In one widely reported case, an engineering group lost around $25 million after staff joined a video call with what appeared to be their CFO and colleagues. Every other person on the call was a deepfake.

For a smaller business, the version is usually simpler: a phone call or voice note from “the MD” asking finance to make an urgent payment before the end of the day.

2. AI-generated invoices and payment diversion

AI makes it easy to copy a supplier’s branding, layout and tone of voice. Fake invoices, or genuine-looking emails announcing “new bank details”, are now very hard to spot by eye. Often they’re sent from a real supplier’s compromised mailbox, in the middle of a genuine email thread.

3. Highly personalised phishing

Attackers use AI to research your organisation and write messages that reference real projects, colleagues and clients. Phishing remains the most common type of attack reported in the UK Government’s Cyber Security Breaches Survey, and AI is making it more effective.

How to protect your business from AI scams

The good news is that the strongest defences aren’t technical. They’re simple processes that work however convincing the scam is.

  • Verify every change of bank details by phone. Use a number you already hold, never one from the email or invoice.
  • Require two people to approve payments over an agreed amount, and never skip it because something is “urgent”.
  • Agree a safe word or call-back rule for any unusual request from a director, especially by phone, voice note or messaging app.
  • Secure your email. Multi-factor authentication stops most mailbox takeovers, and SPF, DKIM and DMARC make it harder for criminals to send email that appears to come from your domain.
  • Train your team regularly. Short, practical sessions on current scams work far better than an annual box-ticking course. Make it easy, and blame-free, to report something suspicious.
  • Know what to do if it happens. Contact your bank immediately and report fraud to Action Fraud. Speed makes a real difference to recovering funds.

The NCSC’s phishing guidance is also a useful resource for staff training.

Check your defences

Our free SME cyber security checklist includes a full section on email and payment fraud, with the controls that stop the most common scams. If you’d like help putting them in place, find out more about our cyber security services or talk to our team.