A payment request arrives from the boss.
The name is right. The company signature looks right. There is an invoice attached, perhaps even a forwarded email conversation showing that the purchase has already been discussed and approved.
The request is urgent, but not wildly suspicious.
Please process this today.
That is exactly why this kind of fraud works.
For years, criminals have used business email compromise — often shortened to BEC — to impersonate executives, suppliers and colleagues. What is changing is the quality of the deception. Generative AI can help criminals produce cleaner writing, more convincing formatting, more believable invoices and personalised messages at a scale that used to require much more work.
Microsoft recently described a campaign in which attackers sent more than a million fraudulent emails, impersonating executives and presenting fabricated invoices and fake forwarded conversations. The goal was to persuade accounts-payable staff to make ACH payments of nearly $50,000.
The important lesson is not that artificial intelligence has invented a completely new scam.
It has made an old scam easier to polish.
The old warning signs are becoming less reliable
We used to tell people to look for obvious spelling mistakes.
That was good advice when many phishing messages looked like this:
Dear Sir kindly urgently transfer monies today.
But modern scam messages can be grammatically perfect.
They can use the correct name of your CEO, your accountant or your supplier. They can copy logos from a legitimate company. They can imitate an invoice template. They can reproduce an email signature. They may even refer to real projects or employees discovered through LinkedIn, company websites or other public information.
So the question can no longer simply be:
Does this email look professional?
A better question is:
Can I independently verify the action it is asking me to take?
The most useful security tool may be a phone call
Suppose an email says that a supplier has changed its bank account.
Do not verify that change by replying to the email.
If the email account itself has been compromised, you may simply be asking the criminal whether the criminal's instructions are genuine.
Instead, use a phone number you already know, a number stored in your accounting system, or the number on the supplier's official website.
The FBI specifically recommends independently verifying payment and purchase requests and confirming changes in account numbers or payment procedures.
That one habit can prevent an enormous amount of trouble.
Create a payment verification rule before you need it
Small companies often rely on trust and speed.
That is normally an advantage.
It becomes a weakness when an attacker can imitate the person everyone trusts.
A simple internal rule can help:
Any new bank account, changed payment instruction, unusual transfer, or urgent payment above a chosen amount must be verified through a second communication channel.
For example:
- An invoice arrives by email.
- The bank details are new.
- Someone calls the supplier using the number already on file.
- The supplier confirms the change.
- Only then is the payment released.
This does not require expensive cybersecurity software.
It requires a habit.
"But I recognised the voice"
Unfortunately, even a phone call is not automatically proof anymore.
AI voice cloning can imitate a person's voice from relatively small amounts of recorded material. The Federal Trade Commission has warned that voice cloning can be used in fraud against families and businesses.
That means a surprise call from "the owner" saying:
I need you to wire this immediately. I'm walking into a meeting, so don't call me back.
should not bypass normal controls simply because the voice sounds familiar.
A useful defence is independent call-back verification.
End the call. Then call the person back using the number already stored in your contacts.
For especially sensitive transactions, companies can also agree on internal verification procedures that are not normally discussed publicly.
Urgency is still one of the biggest warning signs
Technology changes. Human psychology changes much more slowly.
Scammers often need to stop you from thinking.
That is why messages frequently contain some combination of:
- urgency;
- secrecy;
- authority;
- financial pressure;
- a changed payment method;
- a request to bypass normal procedure.
A legitimate manager may occasionally send an urgent request.
A legitimate supplier may genuinely change banks.
The danger is not any one of those things by itself. It is allowing urgency to cancel verification.
Look beyond the display name
Email programs often show a friendly name prominently while making the actual email address less obvious.
So you may see:
John Smith — CEO
while the message actually came from a lookalike domain.
Attackers sometimes register domains that differ from a real company's address by only one character or a small addition.
Check the complete sender address.
And when money is involved, check the reply-to address too. The address receiving your response may be different from the one displayed as the sender.
A forwarded email thread can be fake
One particularly effective trick is including what appears to be an earlier conversation below the message.
It creates context.
You see the CEO apparently discussing the purchase with a supplier. Then the final message simply says the invoice is approved.
That feels more convincing because you appear to be joining a conversation that already happened.
But text inside an email can be fabricated just like any other text. A fake forwarded chain does not prove that those messages were ever sent.
Microsoft's September 2026 report specifically described attackers using fabricated forwarded conversations alongside a fake invoice.
Two-factor authentication is still important
Not every impersonation attack depends on hacking a real mailbox. Sometimes the criminal simply sends from a lookalike address.
But real email accounts are also compromised.
That is why two-factor or multi-factor authentication remains important for email, accounting systems, cloud storage and other business services.
Use it.
Also review old accounts and remove access that is no longer needed. A forgotten mailbox belonging to a former employee can become a surprisingly useful doorway for an attacker.
AI is not the villain
It is tempting to describe this as an "AI scam".
That is slightly misleading.
AI is a tool.
The actual attack is still social engineering: convincing a human being to trust the wrong message and perform an action.
The same AI technology that helps attackers write a convincing fraudulent email can also help security products identify suspicious activity.
The practical problem is that appearance is becoming weaker evidence of authenticity.
A professional-looking message is not necessarily genuine.
A familiar voice is not necessarily the person you think it is.
A realistic invoice is not necessarily a real invoice.
My simple rule
When a message asks you to do something that is difficult to undo — send money, disclose a password, change bank details, grant account access — do not let the message itself be the only proof that the request is genuine.
Verify it somewhere else.
Email says to transfer money? Call.
Phone call asks for credentials? Open the official website yourself.
Supplier says its bank changed? Use the contact details already on file.
Boss says normal procedure must be skipped? Confirm independently.
That extra minute may feel unnecessary 99 times out of 100.
The hundredth time, it could be the most profitable minute of your day.