The AI Scam Patterns I'm Seeing Move From Individuals to Small Businesses

Sep 02, 2026By Jay Kells
Jay Kells

The AI Scam Patterns I'm Seeing Move From Individuals to Small Businesses

For a long time the AI scam stories I heard were all personal: a cloned voice on a phone call, a message that sounded a little too convincing. What I'm seeing now is the same technology showing up in a completely different context, aimed at small businesses rather than individuals, and it worries me more, because the money involved is bigger and the people making payment decisions often have less time to stop and question what's in front of them. If you run even a small operation, this is worth understanding on its own terms rather than assuming the family-scam warnings you've already heard cover it.

Why AI Scams Aren't Just a Personal-Target Problem Anymore

The economics of this shift make sense once you think about it. A scammer cloning a voice to target one family member might get a few hundred pounds if it works. A scammer impersonating a supplier or a director to authorise a business payment can be targeting thousands in a single message, and a small business often has fewer checks in place than a large one with a dedicated finance team. AI has made the impersonation itself cheap and convincing enough that the extra effort of targeting a business instead of a person barely costs the scammer anything more, while the potential payout is far higher. That's the shift I think a lot of small business owners haven't clocked yet, because the warnings they've seen are still framed around grandparents and voice clones rather than invoices and video calls.

The Fake Video Call That's Replacing the Fake Phone Call

A phone call used to be the gold standard for verifying something felt suspicious, because at least you could hear a real person's tone even if the details were fake. AI video generation has started to close that gap. I've heard from other small business owners about video calls that looked and sounded like a real supplier or colleague on a brief connection, just convincing enough to get an urgent instruction across before anything felt off. It's not yet common enough to panic about, but it's common enough that I no longer treat "I saw them on a call" as proof of anything on its own, especially when the call is short, the connection is poor, or the request is unusually time-pressured.

Invoice Fraud That Now Mimics a Supplier's Exact Tone

Invoice fraud isn't new, but AI has made it far more convincing than the slightly-off emails that used to give it away. A scammer can now feed a genuine supplier's previous emails into a tool and get back a message that matches their actual writing style, their usual phrasing, even inside jokes or references to a real ongoing project. The old advice to look for spelling mistakes or a strange tone is close to useless against this. What still works is having a separate verification step for any change to payment details specifically, a phone call to a number you already have on file rather than one in the email, before a changed account number is ever used. That single habit, kept completely separate from how convincing the message reads, is the thing I'd actually recommend over trying to spot the fake by feel.

Professional resume with clean formatting and organized sections on wooden desk with natural light

The Job Applicant Who Never Actually Existed

This is the one that surprised me most when I first heard about it. Small businesses hiring remotely have started encountering job applicants using AI-generated photos, AI-written CVs, and in some cases AI-assisted video interviews, sometimes to get access to company systems and sensitive data under a fake identity rather than to actually work the job. It's a specific and growing enough problem that some recruitment platforms have started building in detection tools for it. If you're hiring for any role with access to financial systems, client data, or admin-level accounts, a basic identity verification step before onboarding isn't excessive caution anymore, it's a reasonable baseline, in the same category as a password manager keeping every account's login genuinely unique rather than assuming a strong-looking application speaks for itself.

Building Verification Into the Process, Not Just Into Suspicion

The thread running through all of this is that suspicion alone doesn't scale the way a business needs it to. I can't rely on a gut feeling catching every convincing fake video call or every well-mimicked supplier email, especially on a busy day when someone is trying to get a payment out quickly. What actually works is building a verification step into the process itself, a callback to a trusted number before any payment detail changes, a second person's sign-off on anything above a set amount, an identity check before systems access is granted, so that the check happens automatically rather than depending on someone noticing something felt wrong in the moment. I've written separately about the verification habits I rely on personally whenever I suspect an AI scam, and the same principle underneath is even more important here: build the check into the process, not into your ability to spot a fake in real time. The specific AI scam techniques I think are actually getting harder to spot keep evolving on their own, but a verification step that doesn't depend on spotting anything holds up regardless of how convincing the fake gets. The NCSC has guidance aimed specifically at small businesses if you want a second source to build a process around, and my free Safety Toolkit covers the account-level basics worth having in place before you even get to business-specific verification steps. None of this needs to be complicated. It just needs to happen every time, not just on the days something feels off.