Imagine this: One of your employees receives an email from a trusted vendor explaining that the company recently changed banks. The message looks professional, uses the vendor’s usual terminology and includes an updated invoice with new payment instructions.
Nothing seems obviously wrong, and that’s exactly what makes today’s AI-enabled fraud risk different.
Artificial intelligence hasn’t necessarily invented entirely new scams, but it is making many common schemes faster, more convincing and more difficult to recognize.
Criminals are using AI tools to create polished emails, personalized phishing messages, synthetic voices and increasingly realistic video and audio impersonations. According to the FBI, in 2025:
- More than 22,000 complaints contained AI-related information
- Adjusted losses exceeded $893 million
- Businesses alone reported over $30 million in losses from business email compromise scams involving AI
For small businesses, the lesson is increasingly clear: You can’t rely solely on whether an email, phone call or payment request looks legitimate. Your procedures for verifying those requests matter more than ever.
Topics Covered
- What Has AI Changed About Business Fraud?
- AI-Enabled Fraud Risks Small Businesses Should Recognize
- Other Common Types of Scams Small Businesses Should Watch For
- Why Small Businesses Are Attractive Targets
- Your Most Important Defense: Verify Before You Send Money
- Build Additional Layers Around Your Verification Process
- What Should You Do After Discovering a Fraudulent Transfer?
- Where Does Cyber Insurance Fit?
- Related Resources
- Make Your Verification Process Harder to Fake
What Has AI Changed About Business Fraud?
Phishing, fake invoices and executive impersonation existed long before generative AI. What’s changed is how easily criminals can make those scams appear more credible than ever.
AI tools can rapidly generate natural-sounding messages without many of the spelling errors, grammatical mistakes or awkward phrasing traditionally associated with phishing. They can also produce personalized conversations, fake profiles and other synthetic content at scale.
According to the FBI, AI-enabled synthetic content is becoming easier to create and increasingly difficult to detect. Criminals are using chat generators to produce official-sounding emails that impersonate company executives, while voice-cloning technology can imitate someone’s voice when requesting a wire transfer.
That changes one of the traditional assumptions behind scam prevention. Training employees to simply “look for suspicious emails” is no longer enough because fraudulent messages may look perfectly normal.
Instead, businesses need procedures that assume a convincing request could still be fraudulent.
AI-Enabled Fraud Risks Small Businesses Should Recognize
1. Fake Vendor Invoices and Payment-Change Requests
Coalition’s 2026 Cyber Claims Report found that business email compromise and funds-transfer fraud represented:
- 58% of cyber claims in 2025
- 71% of funds-transfer-fraud claims were directly caused by social engineering
- More than half of funds-transfer-fraud claims originated as a business email compromise scheme
One particularly dangerous scenario begins with something your accounting department probably handles routinely: a vendor asking you to update payment information.
Criminals impersonate a legitimate vendor or gain access to the vendor’s email account. They then send what appears to be a normal invoice or message explaining that banking information has changed. If your employee follows the instructions, your legitimate payment goes to the criminal instead.
These attacks don’t necessarily require someone to break into your bank account. Social engineering can convince an authorized employee to voluntarily send the money, and that distinction is important.
A request to change payment instructions should therefore be treated as a financial security event, not simply routine administrative work.
2. Business Email Compromise and Executive Impersonation

The FBI received 24,768 BEC complaints in 2025, representing more than $3 billion in reported losses.
Business email compromise, commonly called BEC, occurs when criminals impersonate someone your employees trust or compromise a legitimate email account.
That person might appear to be:
- Your company’s owner or CEO
- An employee’s manager
- Your accountant or bookkeeper
- A customer
- A supplier or vendor
The request may seem ordinary:
- “Can you get this invoice paid today?”
- “I’m traveling. Please wire this before the bank closes.”
- “We switched accounts. Use the attached banking information from now on.”
Generative AI gives criminals another tool for making their requests more convincing. Urgency remains an important warning sign, but don’t assume every fraudulent request will be dramatic or obviously suspicious.
The most effective scam may look like an ordinary transaction your employee has processed dozens of times before.
3. Voice Cloning and Deepfake Impersonation
Email isn’t the only communication channel businesses need to think about because AI can also create synthetic audio that sounds like a real person.
Imagine receiving a phone call that appears to come from your company president. The voice sounds familiar. The caller knows the names of people inside the company and says an important payment needs to be made immediately.
Traditionally, hearing someone’s voice might have provided reassurance that the request was legitimate, but that’s no longer sufficient verification.
This doesn’t mean employees should distrust every phone call or video meeting. It means that a familiar voice should never be the only authorization required for a significant financial transaction.
4. Phishing Emails That Are Much Harder to Spot
For years, one of the most common cybersecurity tips has been to watch for misspelled words, strange grammar or messages that don’t sound quite right.
Those clues can still matter, but they aren’t enough anymore.
AI can help criminals quickly create polished, industry-specific messages. Instead of a generic phishing email sent to thousands of people, an attacker can potentially tailor messages to your company, your employees or a specific transaction.
That makes employee awareness important but also illustrates why businesses shouldn’t make employees responsible for simply “spotting the scam.”
Your security process should still work even when the message looks real.
Other Common Types of Scams Small Businesses Should Watch For
AI-enabled fraud takes many forms, and several types of scams often overlap. A phishing email may lead to stolen credentials, for example, which can then be used to launch a business email compromise or fake-invoice scheme.
Knowing what these scams look like can help keep your business safe.
| Type of Scam | What It May Look Like | What to Do |
| Deepfake video scams | Synthetic video is used to impersonate a trusted person during a video call or recorded message. | Verify important requests through a separate, trusted communication channel. |
| Credential theft | An employee is tricked into revealing usernames, passwords or authentication codes. | Use MFA and never share login or verification codes in response to unsolicited requests. |
| Smishing | Phishing attempts arrive through text messages instead of email. | Avoid clicking unexpected links and verify the sender independently. |
| Quishing | A fraudulent QR code sends employees to a fake login, payment or credential-harvesting website. | Treat unexpected QR codes like suspicious links and verify their source before scanning. |
| Tech-support scams | Someone poses as an IT provider, software company or support technician and asks for system access or credentials. | Confirm support requests directly with your known IT provider or vendor. |
| Payroll or direct-deposit scams | A criminal impersonates an employee and asks payroll to change direct-deposit information. | Verify payroll changes directly with the employee using existing contact information. |
These scams may look different, but they often rely on the same basic strategy: convincing someone inside your business to trust the wrong message, person or request.
Knowing the warning signs helps, but strong verification procedures and cybersecurity safeguards are what make it harder for a fraudulent attempt to turn into a financial loss.
Why Small Businesses Are Attractive Targets
Cybercriminals don’t exclusively target large corporations. In fact, small businesses often have fewer resources dedicated to cybersecurity and fraud prevention, yet they handle many of the same things larger companies do:
- Customer information
- Payroll
- Bank transfers
- Vendor payments
- Sensitive employee data
One employee might manage invoices, communicate with vendors and authorize payments. A business owner might routinely text employees asking them to take care of financial tasks, and smaller organizations may not have dedicated cybersecurity or IT staff.
Those efficiencies can create vulnerabilities.
The solution isn’t necessarily building the kind of security operation a large corporation would have. Instead, small businesses can put a handful of repeatable safeguards around the transactions that create the most risk.
Your Most Important Defense: Verify Before You Send Money
One of the simplest protections against AI-enabled financial fraud doesn’t involve AI at all. You can create a company rule requiring independent verification whenever someone asks you to:
- Change bank account information
- Update ACH or wire instructions
- Make an unusual or unexpected payment
- Send money urgently
- Establish payment information for a new vendor
- Provide sensitive financial credentials
The key is how you verify the request. If updated banking instructions arrive by email, don’t reply to that email and ask if they’re legitimate, and don’t call the telephone number included in the message.
Instead, contact the person or business through information you already know and trust. For example, call your vendor using the phone number already saved in your accounting system or existing company records.
Travelers recommends exactly this type of “out-of-band authentication (OOBA)” for funds transfers: verify payment requests using a separate communication channel and a known, trusted phone number rather than contact information included in the original request.
For significant transactions, consider adding another safeguard: require approval from a second employee or manager before money is transferred or banking information is changed.
Most importantly, make verification a part of your company culture. Employees shouldn’t worry that they’re being difficult by double-checking the boss’s request. If verifying unusual financial transactions is company policy, nobody needs to decide whether something “seems suspicious enough.”
Build Additional Layers Around Your Verification Process
Verification procedures are especially important for payment fraud, but businesses should also maintain basic cybersecurity protections.
Consider these safeguards:
- Use multifactor authentication (MFA). Protect email, financial accounts, administrative accounts and other sensitive systems with more than a password whenever possible.
- Keep software updated. Install security patches and updates for operating systems, applications and security tools.
- Train employees regularly. Employees should understand phishing, BEC, fake invoices, credential theft and other AI-enabled impersonation techniques.
- Limit access when possible. Employees should have access only to the systems and financial functions necessary for their jobs.
- Back up important business data. Maintain secure backups and periodically confirm that your business can restore them.
- Create an incident-response plan. Employees should know whom to contact if they suspect fraud, account compromise or another cyber incident.
Travelers also recommends employee security awareness training, MFA on email accounts and formal response procedures for funds-transfer fraud.
Think of these protections as layers. No single security tool eliminates fraud risk. The goal is to make it harder for one compromised email account, convincing phone call or employee mistake to result in a major financial loss.
What Should You Do After Discovering a Fraudulent Transfer?
Speed matters.
If you discover that money was transferred to a criminal, you need to act immediately. Don’t wait to figure out exactly how the scam happened.
Start by contacting your bank or financial institution, explaining that the transaction was fraudulent and asking whether the transfer can be stopped, recalled or frozen.
Then:
- Notify the appropriate people inside your company, including your IT provider or cybersecurity team if applicable.
- Preserve emails, invoices, text messages, call information and transaction records related to the incident.
- Change compromised credentials and secure affected accounts.
- Report cyber-enabled fraud and BEC to the FBI through its Internet Crime Complaint Center at IC3.gov.
- Contact your insurance agent or carrier promptly if the incident may involve an insured loss.
There may be only a limited window in which stolen funds can be recovered.
Where Does Cyber Insurance Fit?
Strong security practices can reduce your risk, but they can’t eliminate it.
Insurance can provide another layer of financial protection. However, don’t assume that every cyber-related or fraud-related loss is automatically covered by your existing business insurance.
Cyber policies can address risks such as data loss, business interruption, cyber extortion, liability and costs associated with responding to certain cyber incidents. Some business owners policies may provide limited protection for certain types of cyber events, while broader protection may require separate cyber insurance.
Coverage involving fraudulent payments can be particularly important to review carefully.
Depending on your policy, losses involving computer fraud, funds-transfer fraud or social engineering may be handled differently or subject to specific limits, conditions or exclusions. That’s why it’s worth talking with your local insurance agent before something happens.
Ask specifically how your current insurance addresses:
- Cyberattacks
- Business email compromise
- Social-engineering fraud
- Fraudulent funds transfers
- Data breaches
- Cyber-related business interruption
Insurance policies and coverage vary, so your agent can help you understand what protection you currently have and where gaps may exist.
Related Resources
AI-enabled fraud is only one part of the broader cybercrime and identity-theft landscape. For more information on protecting yourself and your business, explore these related resources:
- Are You Insured Against Cybercrime? Probably Not.
Learn why traditional insurance may not cover every cyber-related loss and why reviewing your coverage matters. - Modern Scams, Real Losses: What Every Small Business Owner Needs to Know
Explore common scams targeting businesses and practical steps you can take to reduce your risk. - How to Protect Yourself from Identity Theft – Part 1
Learn the fundamentals of identity theft, common warning signs and ways to protect your personal and financial information. - How to Protect Yourself from Identity Theft – Part 2
- Continue with additional identity-theft warning signs, prevention strategies and practical steps you can take if your information is compromised.
Make Your Verification Process Harder to Fake
AI is changing what fraudulent communication looks and sounds like.
A professional email isn’t proof that the sender is legitimate. A familiar voice isn’t proof that you’re talking to the person you think you are. And a vendor invoice that looks identical to previous invoices may still contain fraudulent payment instructions.
Small businesses don’t need to become AI experts to respond to that risk, but they do need procedures that don’t depend entirely on recognizing a scam:
- Verify unexpected financial requests independently.
- Require additional approval for important transactions.
- Use multifactor authentication (MFA) and other basic cybersecurity safeguards.
- Train employees.
- Know how you’ll respond if something goes wrong.
- Review your insurance protection before you need to use it.
As fraud becomes more convincing, those simple layers of verification can make your business much harder to fool.
Need to learn more about insurance for your business?
Our agents are ready to help, so contact us to learn how we can customize your insurance policies to meet your needs.
*Disclaimer: We offer content for informational purposes; Co-operative Insurance Companies may not provide all the services or products listed here. Please get in touch with your local agent to learn how we can help with your insurance needs.
Sources
Coalition. Ransom demands surged 47% yet most went unpaid. https://www.coalitioninc.com/claims-report/2026
Federal Bureau of Investigation. FBI Internet Crime Report 2025. https://www.fbi.gov/file-repository/2025_ic3report.pdf
Federal Bureau of Investigation. Business Email Compromise. https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise
Insurance Information Institute. RiskScan 2026 Survey Reveals Increasingly Complex Risk Landscape as Insurance Protection Gaps Persist: Triple-I/Munich Re US. https://www.iii.org/press-release/riskscan-2026-survey-reveals-increasingly-complex-risk-landscape-as-insurance-protection-gaps-persist-triple-i-munich-re-us-060826
Insurance Information Institute. Cyber Liability Risks. https://www.iii.org/article/cyber-liability-risks
Travelers. Securing Funds Transfers (Out-of-Band Authentication and Other Considerations). https://www.travelers.com/cyber-knowledge/cybersecurity-best-practices/securing-funds-transfers-out-of-band-authentication-and-other-considerations
Travelers. Prepare Your Small Business Against Cyberattacks.https://www.travelers.com/resources/business-industries/small-business/cyber-risks-to-small-business

