Two years ago, a finance employee at the engineering firm Arup joined what looked like a routine video call with the company’s CFO and several colleagues. Everyone on the call was a deepfake. The employee wired $25 million before anyone realized it. That happened in Hong Kong in 2024, and it’s the case study every security vendor now points to, because it proves the thing that should worry small businesses most: the “just verify by phone or video” advice that used to catch fraud doesn’t work anymore.

That’s the real shift with AI and cybercrime. The attacks aren’t new — phishing, ransomware, wire fraud, all of it predates AI by decades. What’s changed is the cost of running them well. A convincing phishing email used to take a skilled writer and some research. Now it takes a prompt. A cloned voice used to require studio time. Now it takes a 30-second audio sample pulled from a company’s own YouTube channel or a voicemail greeting.

Phishing emails have lost their tells

The broken English and mismatched logos that used to give phishing away are gone. AI-written emails match a company’s tone, reference real employee names, and land in the right inbox at the right time of day. We still tell clients to “watch for typos” and it’s mostly useless advice now — the emails are clean.

Ransomware doesn’t require a hacker anymore

Ransomware-as-a-service platforms rent out attack infrastructure to anyone with a few hundred dollars in crypto, the same way you’d rent server space. The FBI and CISA have been flagging this shift for a couple of years now: the people launching these attacks increasingly aren’t technical at all, they’re just customers of someone else’s tooling. That’s why the volume keeps climbing even though there aren’t more skilled hackers in the world — there don’t need to be.

Voice and video used to be proof of identity (not anymore)

The Arup case wasn’t an outlier; it’s the template. If your wire transfer approval process still relies on “I heard their voice” or “I saw them on the call,” that process has a hole in it right now.

Why small businesses specifically

Attackers don’t pick targets by company size, they pick targets by resistance. A business with one part-time IT contact and no formal incident response plan is easier to hit than a bank, even if there’s less money to take, because the attacker’s odds are so much better. Most of the SMBs we work with in Central Texas don’t have a written policy for what happens if someone gets a call that sounds exactly like the owner asking for an urgent wire transfer. That gap is exactly what these attacks are built to exploit.

What actually helps

Out-of-band verification for anything involving money or credentials — meaning if a request comes in by phone, video, or email asking to move money or reset an account, someone confirms it through a different channel before acting, even if the voice on the phone sounded completely normal. It feels like overkill until the day it isn’t.

Beyond that: monitoring that’s actually watching in real time rather than generating a report you read next week, a written policy for what your team can and can’t paste into AI tools, and a look at what third-party AI tools and browser extensions already have access to your systems, because most businesses have more of these installed than anyone realizes.

None of this requires becoming a security expert. It requires someone whose job is to actually stay on top of it — which, if you’re running a business, generally isn’t you.

If you want a second set of eyes on your current setup, book a free consultation and we’ll walk through where the gaps actually are.

Not sure where your IT actually stands? Score your business in about 3 minutes on security, backup, support, and Texas compliance. Free, anonymous, no signup.

Take the free assessment