You think you're safe- until you're not.

Artificial intelligence has seamlessly woven itself into our daily routines, impacting almost everything we do whether we realise it or not. As business owners, we are actively encouraged to embrace AI to drive efficiency, which is a highly positive step forward. However, if you ask most owners whether their business is protected against AI-driven scams, the answer is usually a confident "yes". Most point to their firewalls, multi-factor authentication (MFA), and up-to-date antivirus software. Unfortunately, recent real-world events show that these traditional defenses are no longer enough.

We recently witnessed a sophisticated phishing scam that caused devastating financial damage to a local business. Phishing does not rely on traditional hacking to break through your network. Instead, it tricks staff into clicking malicious links, handing over sensitive information, or unknowingly downloading malware by pretending to be a trusted contact.

Worse still, hyper-personalised "spear phishing" is surging. Scammers are now using AI tools to harvest personal data at an unprecedented scale. By scraping social media and public records, AI can map out a target’s specific role, organizational structure, and even the exact software they use daily. The resulting emails perfectly mimic the victim's professional tone and context.

As an example, you’ve sent a payment to your regular supplier. It’s business as usual until you find out it wasn’t them. The invoice was fake. The bank details were switched. And the money? Gone.

It’s very hard to pick out what’s legitimate and what’s a phishing campaign. It usually starts with a fake email that looks like it’s come from a trusted supplier or even your boss. Everything looks legitimate — the tone, the logo, even the email address. But behind the scenes, scammers are hijacking or impersonating accounts to redirect payments. And the damage isn’t small. Some scams cost businesses tens of thousands of dollars.

So what can you do to minimise your chances of being a victim:

Here is a checklist of steps to help protect your business and team from these sophisticated scams:

Technical Defenses

  • Configure Email Authentication: Contact your IT provider to set up additional protocols to prevent cybercriminals from spoofing your organization's domain.

  • Use Phishing-Resistant MFA: Implement Multi-Factor Authentication (MFA), prioritizing hardware keys like FIDO2 or passkeys rather than basic SMS codes.

  • Deploy Advanced Filtering: Use cloud-based email security solutions that scan links and inspect attachments in real time.

  • Keep Systems Updated: Install regular software patches and system updates to close known security gaps.

Human and Process Controls

  • Verify Unusual Requests: Establish an out-of-band communication rule (such as calling the person via a known, trusted phone number) to confirm any urgent request for money transfers or sensitive data.

  • Create Clear Vendor Procedures: Establish a formal process for onboarding new suppliers and updating existing vendor profiles, requiring documentation that is independently verified.

  • Confirm with the Source: Speak directly to the person who supposedly sent the request—whether it is a regular supplier or your boss—before transferring any funds.

Additionally, we strongly recommend you review your cyber insurance cover and ensure you have adequate insurance to cover the financial losses of being scammed.