Skip to content
Security Updated Noah Stegman

AI Phishing, Voice Cloning and Deepfakes: What Still Works

How AI-written emails, cloned voices, and deepfake video change phishing for small businesses, and which defenses still work when a fake looks perfect.

AI has changed how convincing a scam looks, not what the scam wants. Criminals now use AI tools to write error-free emails, clone a voice from a short recording, and fake a face on a video meeting. The goal is still a password, a payment, or access. So the defenses that still work are the ones that never depended on spotting a clumsy fake: verifying requests through a second channel, sign-in methods that cannot be phished, and firm payment rules.

What Has Actually Changed With AI?

Three things, according to the agencies that track this.

The writing is clean. The FBI warned in a December 2024 public service announcement that criminals use generative AI (software that produces text, images, audio, or video on request) to write messages faster, reach more people, and translate them with fewer grammar and spelling errors. The old advice to look for awkward English has lost most of its value.

Voices and faces can be copied. The same FBI notice describes cloned audio of a real person’s voice and fabricated video used in live video chats with supposed company executives. The FBI’s 2025 annual report adds that voice cloning can be used to request wire payments as part of business email compromise.

AI is a helper, not a new kind of attack. Verizon’s 2026 Data Breach Investigations Report found attackers using generative AI at several stages, including targeting and initial access, but mostly to do familiar things faster. Phishing was the way in for 16% of breaches in that report, the same share as the year before.

How Big Is the Problem for Small Businesses?

Measured numbers are still modest next to fraud overall, and they come with a caveat. In 2025 the FBI’s Internet Crime Complaint Center received more than 22,000 complaints that mentioned AI, with losses above $893 million. Most of that was investment fraud aimed at individuals. Businesses reported a little over $30 million in losses to business email compromise scams that involved AI, out of roughly $3 billion in business email compromise losses overall.

The caveat is the FBI’s own: many victims never learn whether AI was involved, so these figures undercount. The practical reading for a small office is that AI has not created a separate threat to budget for. It has made the existing ones (fake invoices, fake sign-in pages, fake requests from the owner) harder to recognize on sight.

The Three Forms It Takes

AI-Written Email and Text Messages

A language model can produce a message that matches a vendor’s tone, references a real project, and contains no mistakes. Information for that personalization is usually public: your website’s staff page, social media profiles, and online reviews.

What this breaks: judging a message by its polish. What it does not break: checking the real sender address, checking where a link goes, and asking whether the request makes sense. Our phishing checklist for staff is built around those checks for this reason.

Cloned Voices on the Phone

A recording of someone’s voice, such as a voicemail greeting or a video posted online, can be used to generate speech that sounds like them. The typical use is a phone request that seems to come from an owner or manager: send a payment, buy gift cards, reset a password, read back a sign-in code.

Verizon’s report notes that pretexting (building a false story to win trust, frequently by voice) has become a more common way into ransomware and extortion attacks, and that click rates in phishing simulations ran 40% higher for voice and text message lures than for email.

Deepfake Video

A deepfake is fabricated video or audio of a real person. The FBI lists real-time video chats with fake executives among current techniques. This takes more effort than email, so it tends to appear where a single payment is large. For most small offices it is the least likely of the three, but it matters for one reason: “I saw them on video” no longer counts as verification.

Which Defenses Still Work?

DefenseStill works against AI-made lures?Why
Looking for typos and odd phrasingRarelyAI removes those errors
Recognizing a voice or faceNoBoth can be fabricated
Checking the real sender address and link destinationYesAI does not change where a message comes from or where a link goes
Calling back on a number you already haveYesThe attacker does not control your saved contact
A shared verification phraseYesIt is never published, so it cannot be scraped
Passkeys and security keysYesThey will not sign in to a fake site, however convincing it looks
Payment rules (two people, callback on bank changes)YesThey apply regardless of how real the request seems
Email filtering and sender authenticationPartlyThey stop a large share of messages but not ones from a genuinely compromised account

Verify Through a Second Channel

Any request involving money, bank details, passwords, sign-in codes, or remote access gets confirmed another way before anyone acts. The FBI’s advice for suspicious calls is to hang up and contact the person directly using a number you already have. Do not use a number that came with the request.

Agree on a Verification Phrase

The FBI suggests a secret word or phrase for families. The same idea works in an office: a phrase agreed in person, never written in email or chat, that the owner and the people who handle money can ask for on any unusual request. It costs nothing and takes five minutes to set up.

Use Sign-In Methods That Cannot Be Phished

A perfect fake sign-in page defeats a password and also defeats a texted or app-generated code, because the victim types both into the fake page. CISA, the federal cybersecurity agency, calls phishing-resistant multi-factor authentication the gold standard, meaning passkeys and security keys built on the FIDO standard. These check the website’s real address automatically and will not respond to a lookalike. Microsoft makes the same point: codes and push approvals are prone to remote phishing attacks that use social engineering and AI-driven tools.

Our guide to multi-factor authentication methods ranks the options and shows where to turn them on in Microsoft 365 and Google Workspace.

Put Payment Rules in Writing

Most of the money lost to these scams leaves through a normal payment that someone was talked into. A written rule that bank detail changes always require a callback, and that payments over a set amount need two people, works no matter how good the fake is. The full procedure is in our post on business email compromise.

Keep the Technical Layers On

Email filtering, and the sender authentication records known as SPF, DKIM, and DMARC, still remove a large share of fraudulent mail before anyone reads it. They are covered in our posts on spam filtering and email deliverability.

Reduce What Can Be Copied

The FBI recommends limiting public recordings of your voice and image where practical. For a business that means thinking about whether a full staff directory with roles and direct emails needs to be public, and keeping personal voicemail greetings short. This lowers the quality of the raw material. It does not remove the risk, so treat it as a minor step.

What AI Does Not Change

AI-made lures do not get past a locked process. A cloned voice cannot complete a callback to the real person. A flawless email cannot make a passkey sign in to the wrong site. A deepfake cannot supply a phrase that was only ever spoken in person. If a control depends on a person noticing that something looks wrong, assume AI weakens it. If it depends on a rule or on cryptography, it holds.

This is also why you do not need a special “AI security” product. The controls above work whether or not anyone detects that a message was machine-made. The spending that pays off is the ordinary kind: multi-factor authentication, filtering, payment procedures, and practice.

Common Mistakes

  • Training staff only on typos and generic greetings.
  • Treating a familiar voice, or a face on a video meeting, as proof of identity.
  • Verifying a request by replying to the same email or using the number in its signature.
  • Relying on texted codes for the email accounts that approve payments.
  • Assuming a small business is of no interest. The work of personalizing a scam is now largely automated, so size offers little protection.

Common Questions

Can staff learn to hear the difference between a real and a cloned voice?

Not reliably. The FBI suggests listening to tone and word choice, and that can catch a poor attempt. It should not be the control you depend on. A callback on a saved number and a verification phrase work regardless of how good the audio is.

Do AI-written phishing emails get past spam filters more easily?

Some do, because filters that score poor wording have less to work with. Filters also judge the sender’s reputation, authentication results, and link destinations, and those signals are unchanged by AI. Expect filtering to remain useful and imperfect, and keep the Report button in use so missed messages are flagged.

Are deepfake video meetings a realistic risk for a ten person office?

They are possible and currently uncommon at that size, since they take more effort than email. The defense is the same as for a voice request and costs nothing: no payment or bank detail change is approved on the strength of a video meeting alone.

Should we stop posting videos or staff names online?

That is a business decision. Marketing has value and the FBI’s advice is to limit exposure, not eliminate it. Assume anything public can be used to personalize a scam, and make sure your verification steps do not rely on information an outsider could find.

How We Can Help

Coastal Growth Co. helps small businesses in Orange County put these pieces in place: phishing-resistant sign-in for the accounts that matter most, email filtering and sender authentication, a written payment verification procedure, and staff training that covers voice and video impersonation. To talk through where your office stands, see our managed IT services or get in touch. Scope and price are agreed before any paid work begins.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.