Two years ago, a finance employee at the engineering firm Arup joined what looked like a routine video call with the company's CFO and several colleagues. Everyone on the call was a deepfake. The employee wired $25 million before anyone realized it. That happened in Hong Kong in 2024, and it's the case study every security vendor now points to, because it proves the thing that should worry small businesses most: the "just verify by phone or video" advice that used to catch fraud doesn't work anymore.
That's the shift with AI and cybercrime. The attacks themselves are old. Phishing, ransomware, wire fraud: all of it predates AI by decades. What's changed is the cost of running them well. A convincing phishing email used to take a skilled writer and some research. Now it takes a prompt. A cloned voice used to require studio time. Now it takes a 30-second audio sample pulled from a company's own YouTube channel or a voicemail greeting.
Phishing emails have lost their tells
The broken English and mismatched logos that used to give phishing away are gone. AI-written emails match a company's tone, reference real employee names, and land in the right inbox at the right time of day. We still tell clients to "watch for typos" and it's mostly useless advice now. The emails are clean.
Ransomware doesn't require a hacker anymore
Ransomware-as-a-service platforms rent out attack infrastructure to anyone with a few hundred dollars in crypto, the same way you'd rent server space. The FBI and CISA have been flagging this shift for a couple of years now: the people launching these attacks increasingly aren't technical at all, they're just customers of someone else's tooling. That's why the volume keeps climbing even though there aren't more skilled hackers in the world. There don't need to be.
Voice and video used to be proof of identity (not anymore)
The Arup case is the template rather than an outlier. If your wire transfer approval process still relies on "I heard their voice" or "I saw them on the call," that process has a hole in it right now.
Why small businesses specifically
Attackers pick targets by resistance rather than by company size. A business with one part-time IT contact and no formal incident response plan is easier to hit than a bank, even if there's less money to take, because the attacker's odds are so much better. Most of the SMBs we work with in Central Texas don't have a written policy for what happens if someone gets a call that sounds exactly like the owner asking for an urgent wire transfer. That gap is exactly what these attacks are built to exploit.
What helps
Out-of-band verification for anything involving money or credentials: if a request comes in by phone, video, or email asking to move money or reset an account, someone confirms it through a different channel before acting, even if the voice on the phone sounded completely normal. It feels like overkill until the day it isn't.
Beyond that, a few more things. Monitoring that's watching in real time rather than generating a report you read next week. A written policy for what your team can and can't paste into AI tools. And an inventory of which third-party AI tools and browser extensions already have access to your systems, because most businesses have more of these installed than anyone realizes.
You don't need to become a security expert for any of this. You need someone whose job is to stay on top of it, and if you're running a business, that generally isn't you.
If you want a second set of eyes on your current setup, book a free consultation and we'll walk through where the gaps are.
Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.
Book a 10-Minute Discovery Call →Frequently asked questions
How has AI changed phishing emails?
The broken English and mismatched logos that used to give phishing away are gone. AI-written emails match a company's tone, reference real employee names, and land at the right time of day. "Watch for typos" is mostly useless advice now.
Can a phone or video call still verify a wire transfer request?
Not on its own. In the 2024 Arup case, a finance employee joined a video call where everyone, including the CFO, was a deepfake, and wired $25 million. A cloned voice now takes a 30-second audio sample. If your approval process relies on "I heard their voice," it has a hole in it.
Why do cybercriminals go after small businesses?
Attackers pick targets by resistance rather than size. A business with one part-time IT contact and no incident response plan is easier to hit than a bank, so the odds are better even if there is less money to take. Ransomware-as-a-service means the person launching the attack doesn't need to be technical at all.
What is out-of-band verification?
When a request to move money or reset an account comes in by phone, video, or email, someone confirms it through a different channel before acting, even if the voice on the phone sounded normal. It feels like overkill until the day it isn't.
Can safemode IT handle this for us?
Yes. Real-time monitoring, a written policy for what your team can paste into AI tools, and a review of which third-party tools and browser extensions have access to your systems are the kind of work we do for small businesses in Central Texas. Learn more about our cybersecurity services or book a free consultation.
Last updated: August 30, 2026

