How AI Is Changing Cybercrime: What Small Business Owners Need to Know

Sep 21, 2026

If you think of phishing as “that suspicious email with bad grammar,” it’s time to update your mental model. Since around 2024, AI has made it cheaper and easier for criminals to fake voices, write convincing messages and impersonate real people. These scams are also increasingly reaching people beyond email, including through phone calls, text messages, QR codes and messaging apps. That shift matters for a small business without a dedicated IT security team, because these channels are exactly the ones your staff are least trained to be suspicious of.

Phone Scams Sound More Convincing Than Ever

Voice-cloning tools can now recreate someone’s voice from just a few seconds of audio, sourced from a video, a voicemail greeting, or even a conference call recording. Criminals use this to impersonate a boss, a bank, or an IT vendor on a live phone call, often demanding an urgent payment or asking an employee to “confirm” account details. Voice phishing (“vishing”) attacks jumped 442% between the first and second half of 2024 alone, and by the first half of 2025, vishing volume had already exceeded the entire prior year’s total. In May 2025, the FBI issued a formal warning about AI-generated voice messages, and provided guidance on how to identify fake messages and prevent fraud.

What to do: Establish a simple verification rule for your business. Any request for a payment, a wire transfer, or sensitive information made by phone must be verified through a second channel, like calling the person back on a known number (not one given during the call).

Phishing Has Moved to Your Text Messages

Text-based scams (“smishing”) have surged since 2024, and are increasingly combined with phone scams: a text primes the victim, then a follow-up call from a “familiar” voice closes the deal. Common lures include fake delivery notices, toll-road payment demands, and bank alerts. The Federal Trade Commission reported that Americans lost $470 million to text scams in 2024 alone, and the FBI’s Internet Crime Complaint Center logged more than 59,000 complaints that same year tied to smishing messages impersonating toll agencies such as E-ZPass and SunPass. As recently as November 2025, Google filed a lawsuit alleging that a single text-phishing operation had created nearly 200,000 fraudulent websites impersonating major brands in just 20 days. Despite how common these scams have become, only 36% of Americans can accurately define what smishing is. This means your employees likely can’t, either.

What to do: Train staff to treat unexpected texts with links the same way they’d treat a suspicious email: don’t click, and verify directly with the company or person through an official number or website.

QR Codes Are a Blind Spot for Filters

QR codes are popular precisely because they’re convenient, but that convenience is also why they’re dangerous. A malicious QR code can hide a phishing link in a way that email security tools often don’t catch, since the scan happens on a phone, outside the protections built around a work computer. Recent statistics show how quickly this threat is growing. In early 2026, Microsoft’s threat intelligence team found that the use of malicious QR codes in phishing emails increased 146% in just two months, from 7.6 million attacks in January to 18.7 million in March. Most of the codes were hidden inside PDF or Word attachments. Roughly 89% of QR code phishing attacks are designed to steal personal data, and a resulting data breach costs businesses an average of $4.45 million.

What to do: Treat QR codes like links from a stranger. Don’t scan codes from unsolicited emails, flyers, or attachments, and be wary of any code that’s been taped over another one in public.

Even Video Calls Can Be Faked

AI-enabled impersonation is moving beyond fake messages and voices. Criminals can now use deepfake video to impersonate executives, vendors or other trusted contacts, including during calls conducted through WhatsApp, Telegram and similar platforms.

In a widely reported February 2024 case, a finance employee at a multinational company’s Hong Kong office transferred $25 million after participating in a video call with people who appeared to be the company’s CFO and several colleagues. They were actually deepfakes. Deloitte estimates that losses from AI-enabled fraud could reach $40 billion by 2027.

What to do: Don’t rely on sight or sound alone to verify a high-value request. Before transferring money or sharing sensitive information, confirm the request using a trusted verification method your business has established in advance.

The Bottom Line for Small Businesses

Attackers aren’t relying on obviously-fake emails anymore. For the last few years, they’ve been exploiting trust, urgency, and familiar-seeming voices and faces across whatever channel is easiest. Small businesses are attractive targets precisely because they usually lack the layered defenses of a large enterprise. A few low-cost habits go a long way:


Free Cybersecurity Resources for Small Businesses

Ready to take the next step?

Request Counseling