{"id":144,"date":"2026-07-22T09:00:00","date_gmt":"2026-07-22T16:00:00","guid":{"rendered":"https:\/\/www.wintechnology.ai\/insights\/ai-phishing-deepfake-scams-small-business\/"},"modified":"2026-07-22T09:00:00","modified_gmt":"2026-07-22T16:00:00","slug":"ai-phishing-deepfake-scams-small-business","status":"publish","type":"post","link":"https:\/\/www.wintechnology.ai\/insights\/ai-phishing-deepfake-scams-small-business\/","title":{"rendered":"AI Phishing and Deepfake Scams in 2026: How Small Businesses Are Being Targeted (and a 15-Minute Defense Plan)"},"content":{"rendered":"<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@graph\": [\n    {\n      \"@type\": \"BlogPosting\",\n      \"@id\": \"https:\/\/www.wintechnology.ai\/insights\/ai-phishing-deepfake-scams-small-business\/\",\n      \"headline\": \"AI Phishing and Deepfake Scams in 2026: How Small Businesses Are Being Targeted (and a 15-Minute Defense Plan)\",\n      \"description\": \"AI now writes the majority of phishing emails and can clone a voice from three seconds of audio. Here is how scammers target small businesses in 2026, and the verification protocol that stops them.\",\n      \"image\": \"https:\/\/www.wintechnology.ai\/images\/WinT-AIPhishing.png\",\n      \"datePublished\": \"2026-07-22\",\n      \"dateModified\": \"2026-07-22\",\n      \"author\": {\n        \"@type\": \"Organization\",\n        \"name\": \"The WinTech Desk\",\n        \"url\": \"https:\/\/www.wintechnology.ai\"\n      },\n      \"publisher\": {\n        \"@type\": \"Organization\",\n        \"name\": \"WinTechnology Inc.\",\n        \"url\": \"https:\/\/www.wintechnology.ai\",\n        \"logo\": {\n          \"@type\": \"ImageObject\",\n          \"url\": \"https:\/\/www.wintechnology.ai\/images\/wintechnology-logo.png\"\n        }\n      },\n      \"mainEntityOfPage\": {\n        \"@type\": \"WebPage\",\n        \"@id\": \"https:\/\/www.wintechnology.ai\/insights\/ai-phishing-deepfake-scams-small-business\/\"\n      },\n      \"keywords\": \"ai phishing scams small business, deepfake scams small business, voice cloning fraud, business email compromise 2026\",\n      \"articleSection\": \"Cybersecurity\"\n    },\n    {\n      \"@type\": \"FAQPage\",\n      \"mainEntity\": [\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How common are AI-generated phishing attacks in 2026?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Very common, and rising fast. Hoxhunt's Phishing Trends Report 2026 found that AI-generated messages made up less than 5% of phishing emails in early 2024, spiked to 56% by December 2025, and settled near 40% in January 2026. The FBI's IC3 2025 report logged more than 22,000 complaints that specifically mentioned AI, with roughly $900 million in associated losses.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Why do scammers target small businesses instead of large corporations?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Small businesses combine real money with thin verification. A 12-person company can wire six figures, but rarely has dual approval on payments, a finance department that questions urgent requests, or security training. Attackers also know that small firms publish enough on their websites and social accounts to make impersonating an owner or bookkeeper easy.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How much audio does a scammer need to clone someone's voice?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"About three seconds. Microsoft's VALL-E research demonstrated convincing voice synthesis from a three-second sample. A voicemail greeting, a podcast appearance, or a video on your company's website is more than enough raw material for a criminal to fake a phone call from your CEO or bookkeeper.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What is a callback verification protocol?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"It is a simple written rule: any request to move money, change payment details, buy gift cards, or share credentials must be verified by calling the requester back on a phone number you already have on file, never one supplied in the message itself. Paired with a shared verbal passphrase for the leadership team, it defeats voice clones, deepfake video calls, and spoofed emails alike.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How much does business email compromise cost on average?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"According to the FBI's IC3 2025 Annual Report, business email compromise caused $3.05 billion in reported losses across 24,768 incidents, which works out to roughly $123,000 per incident. For most small businesses that is not a survivable loss, which is why prevention and verification matter more than insurance alone.\"\n          }\n        }\n      ]\n    }\n  ]\n}\n<\/script><\/p>\n<article itemscope itemtype=\"https:\/\/schema.org\/BlogPosting\">\n<h1 itemprop=\"headline\">AI Phishing and Deepfake Scams in 2026: How Small Businesses Are Being Targeted (and a 15-Minute Defense Plan)<\/h1>\n<div class=\"tldr-box\" role=\"note\" aria-label=\"Article summary\">\n    <strong>TL;DR<\/strong><\/p>\n<p>AI-written messages jumped from under 5% of phishing emails to 56% by December 2025 (Hoxhunt), and criminals can clone a voice from about three seconds of audio. Small businesses are the preferred target because the money is real and the verification is thin. The fix costs nothing: a written callback rule, a verbal passphrase, and 15 minutes of team training.<\/p>\n<\/p><\/div>\n<p itemprop=\"description\">Picture a Tuesday afternoon at a 12-person contracting firm. The office manager gets a call. It is the owner&#8217;s voice, no question about it, same cadence, same slight rasp. He is at a job site, a supplier is threatening to pull a delivery, and he needs $18,400 wired in the next hour. He will explain later. She has heard that voice every day for six years. She wires the money.<\/p>\n<p>The owner never made the call. His voice came from a 40-second promo video on the company&#8217;s own website, run through a cloning tool that needed only a fraction of it. Microsoft&#8217;s <a href=\"https:\/\/www.microsoft.com\/en-us\/research\/project\/vall-e-x\/\" rel=\"noopener\" target=\"_blank\">VALL-E research<\/a> showed that roughly three seconds of audio is enough to synthesize convincing speech. That was the research milestone. The street version is now a scam economy.<\/p>\n<h2>How Big Is the AI Phishing Problem in 2026?<\/h2>\n<p>Big, and accelerating. The FBI&#8217;s <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2025_IC3Report.pdf\" rel=\"noopener\" target=\"_blank\">IC3 2025 Annual Report<\/a> logged 1,008,597 cybercrime complaints and $20.9 billion in losses, up 26% year over year. For the first time, the FBI tracked AI as a descriptor: more than 22,000 complaints mentioned it, tied to roughly $900 million in losses.<\/p>\n<p>The sharper number comes from the training side of the industry. Hoxhunt&#8217;s <a href=\"https:\/\/hoxhunt.com\/lp\/phishing-trends-report-2026\" rel=\"noopener\" target=\"_blank\">Phishing Trends Report 2026<\/a> measured the share of phishing emails written by AI. In early 2024 it was under 5%. By December 2025 it hit 56%, a roughly fourteenfold jump, before settling near 40% in January 2026. The majority of phishing email you receive this year was probably not written by a person.<\/p>\n<figure><figcaption><strong>AI-generated share of phishing emails<\/strong> (Hoxhunt Phishing Trends Report 2026)<\/figcaption><svg viewBox=\"0 0 600 320\" role=\"img\" aria-label=\"Bar chart: AI-generated share of phishing emails rose from under 5 percent in early 2024 to 56 percent in December 2025, then settled near 40 percent in January 2026\" style=\"max-width:600px;width:100%;height:auto;background:#F2EFEA;border-radius:8px;\">\n      <line x1=\"70\" y1=\"260\" x2=\"560\" y2=\"260\" stroke=\"#2C2824\" stroke-width=\"2\"\/>\n      <text x=\"35\" y=\"70\" font-size=\"13\" fill=\"#2C2824\" font-family=\"Arial, sans-serif\">60%<\/text>\n      <line x1=\"70\" y1=\"64\" x2=\"560\" y2=\"64\" stroke=\"#2C2824\" stroke-width=\"0.5\" opacity=\"0.2\"\/>\n      <text x=\"35\" y=\"167\" font-size=\"13\" fill=\"#2C2824\" font-family=\"Arial, sans-serif\">30%<\/text>\n      <line x1=\"70\" y1=\"162\" x2=\"560\" y2=\"162\" stroke=\"#2C2824\" stroke-width=\"0.5\" opacity=\"0.2\"\/>\n      <rect x=\"110\" y=\"243\" width=\"90\" height=\"17\" fill=\"#2C2824\"\/>\n      <text x=\"155\" y=\"233\" font-size=\"15\" font-weight=\"bold\" fill=\"#2C2824\" text-anchor=\"middle\" font-family=\"Arial, sans-serif\">&lt;5%<\/text>\n      <text x=\"155\" y=\"285\" font-size=\"13\" fill=\"#2C2824\" text-anchor=\"middle\" font-family=\"Arial, sans-serif\">Early 2024<\/text>\n      <rect x=\"255\" y=\"77\" width=\"90\" height=\"183\" fill=\"#C48C56\"\/>\n      <text x=\"300\" y=\"67\" font-size=\"15\" font-weight=\"bold\" fill=\"#2C2824\" text-anchor=\"middle\" font-family=\"Arial, sans-serif\">56%<\/text>\n      <text x=\"300\" y=\"285\" font-size=\"13\" fill=\"#2C2824\" text-anchor=\"middle\" font-family=\"Arial, sans-serif\">Dec 2025<\/text>\n      <rect x=\"400\" y=\"129\" width=\"90\" height=\"131\" fill=\"#C48C56\" opacity=\"0.75\"\/>\n      <text x=\"445\" y=\"119\" font-size=\"15\" font-weight=\"bold\" fill=\"#2C2824\" text-anchor=\"middle\" font-family=\"Arial, sans-serif\">~40%<\/text>\n      <text x=\"445\" y=\"285\" font-size=\"13\" fill=\"#2C2824\" text-anchor=\"middle\" font-family=\"Arial, sans-serif\">Jan 2026<\/text>\n      <text x=\"315\" y=\"310\" font-size=\"12\" fill=\"#2C2824\" text-anchor=\"middle\" opacity=\"0.7\" font-family=\"Arial, sans-serif\">Source: Hoxhunt Phishing Trends Report 2026<\/text>\n    <\/svg><br \/>\n  <\/figure>\n<p>Authorship matters because the old advice was to look for typos and clumsy grammar. AI killed that tell. Machine-written phishing is fluent, personalized to your industry, and referenced against whatever your company has published online. The email that mentions your actual project, your actual vendor, and your actual invoice numbering format is not a lucky guess anymore.<\/p>\n<h2>Why Do Scammers Clone Your Bookkeeper Instead of a Fortune 500 CFO?<\/h2>\n<p>Because the payoff-to-friction ratio favors small businesses. A Fortune 500 wire request passes through treasury controls, dual approvals, and trained finance staff. A 15-person firm can move six figures on one person&#8217;s say-so. FBI IC3 data puts average business email compromise losses near $123,000 per incident, well within small company wiring authority.<\/p>\n<p>The headline deepfake case was a big one. In 2024, an employee at engineering firm Arup joined a video call with what looked like the company&#8217;s CFO and colleagues. Every participant except the victim was a deepfake. The employee transferred roughly $25.6 million (<a href=\"https:\/\/www.cnn.com\/2024\/05\/16\/tech\/arup-deepfake-scam-loss-hong-kong-intl-hnk\/index.html\" rel=\"noopener\" target=\"_blank\">CNN, 2024<\/a>).<\/p>\n<p>But Arup is the outlier, not the pattern. The pattern is smaller and far more repeatable. Attackers do not need a boardroom-grade production to fool a busy office manager on a Tuesday. They need a voicemail greeting, a LinkedIn page listing who handles the books, and a plausible reason for urgency. Small firms hand over all three for free.<\/p>\n<p>Consider what a criminal can assemble about a typical small business in under an hour. The owner&#8217;s voice from a website video or podcast. The bookkeeper&#8217;s name from LinkedIn. The bank the firm uses from a careers page screenshot. Vendor relationships from Instagram job-site photos. None of it is a data breach. All of it is ammunition.<\/p>\n<h2>What Do These Scams Actually Look Like?<\/h2>\n<p>Four patterns account for most of the damage hitting small businesses right now. Business email compromise leads on dollars, with $3.05 billion in reported 2025 losses across 24,768 incidents (FBI IC3). Voice cloning, deepfake video, and callback phishing round out the set. Each one exploits trust in a familiar channel, not a software flaw.<\/p>\n<h3>1. Business email compromise, upgraded<\/h3>\n<p>A vendor you actually work with emails new bank details before a real invoice comes due. The attacker has been reading a compromised mailbox for weeks, so the timing, tone, and invoice number all check out. The money leaves, and nobody notices until the real vendor calls asking where their payment went.<\/p>\n<h3>2. Voice cloning calls<\/h3>\n<p>The owner, a manager, or a key client calls with an urgent, confidential request. The voice is right. The caller ID may be spoofed to match. The ask is always time-boxed: wire this now, buy these gift cards now, read me that code now. Urgency is the tell, not the voice.<\/p>\n<h3>3. Deepfake video calls<\/h3>\n<p>Rarer, but no longer exotic. A short video call from a &#8220;CFO&#8221; or &#8220;buyer&#8221; approving a transfer. If a request only needs a face and a voice to pass your controls, your controls are already obsolete.<\/p>\n<h3>4. Callback phishing<\/h3>\n<p>An email arrives with no malicious link at all, just an invoice or renewal notice and a phone number to call to cancel. The scam happens on the phone, where your email filters cannot follow. Hoxhunt&#8217;s 2026 research tracked a sharp surge in this tactic in late 2025, alongside a spike in weaponized SVG image attachments that slip past filters expecting PDFs and Office files.<\/p>\n<figure><figcaption><strong>Reported 2025 losses by category, FBI IC3<\/strong><\/figcaption><svg viewBox=\"0 0 620 240\" role=\"img\" aria-label=\"Horizontal bar chart of FBI IC3 2025 reported losses: all cybercrime 20.9 billion dollars, business email compromise 3.05 billion, complaints flagged as AI-assisted about 0.9 billion\" style=\"max-width:620px;width:100%;height:auto;background:#F2EFEA;border-radius:8px;\">\n      <text x=\"20\" y=\"52\" font-size=\"13\" fill=\"#2C2824\" font-family=\"Arial, sans-serif\">All cybercrime<\/text>\n      <rect x=\"150\" y=\"38\" width=\"430\" height=\"24\" fill=\"#2C2824\"\/>\n      <text x=\"520\" y=\"55\" font-size=\"14\" font-weight=\"bold\" fill=\"#F2EFEA\" text-anchor=\"end\" font-family=\"Arial, sans-serif\">$20.9B<\/text>\n      <text x=\"20\" y=\"112\" font-size=\"13\" fill=\"#2C2824\" font-family=\"Arial, sans-serif\">BEC<\/text>\n      <rect x=\"150\" y=\"98\" width=\"63\" height=\"24\" fill=\"#C48C56\"\/>\n      <text x=\"222\" y=\"115\" font-size=\"14\" font-weight=\"bold\" fill=\"#2C2824\" font-family=\"Arial, sans-serif\">$3.05B (24,768 incidents)<\/text>\n      <text x=\"20\" y=\"172\" font-size=\"13\" fill=\"#2C2824\" font-family=\"Arial, sans-serif\">AI-flagged<\/text>\n      <rect x=\"150\" y=\"158\" width=\"19\" height=\"24\" fill=\"#C48C56\" opacity=\"0.7\"\/>\n      <text x=\"178\" y=\"175\" font-size=\"14\" font-weight=\"bold\" fill=\"#2C2824\" font-family=\"Arial, sans-serif\">~$0.9B (22,000+ complaints, first year tracked)<\/text>\n      <text x=\"310\" y=\"220\" font-size=\"12\" fill=\"#2C2824\" text-anchor=\"middle\" opacity=\"0.7\" font-family=\"Arial, sans-serif\">Source: FBI IC3 2025 Annual Report. Losses up 26% year over year.<\/text>\n    <\/svg><br \/>\n  <\/figure>\n<h2>The 15-Minute Defense Plan: Callback Verification and a Verbal Passphrase<\/h2>\n<p>The strongest defense against voice clones and deepfakes is procedural, not technical, and it is free. Adopt one written rule: no money moves and no credentials change based on any single inbound message or call. Every such request gets verified through a second, independent channel. Fifteen minutes with your team makes it policy.<\/p>\n<p>The protocol below is ready to copy into your operations manual.<\/p>\n<table>\n<caption>Callback Verification Protocol (copy and adapt for your business)<\/caption>\n<thead>\n<tr>\n<th scope=\"col\">Step<\/th>\n<th scope=\"col\">Rule<\/th>\n<th scope=\"col\">Why it works<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1. Define triggers<\/td>\n<td>Any request to wire funds, change bank details, buy gift cards, share credentials or MFA codes, or ship goods to a new address.<\/td>\n<td>Scammers vary the story but not the ask. Trigger on the ask.<\/td>\n<\/tr>\n<tr>\n<td>2. Hang up, call back<\/td>\n<td>Verify by calling the requester on a number already in your contacts or contract file. Never use a number, link, or email supplied in the request itself.<\/td>\n<td>A cloned voice cannot answer the real person&#8217;s phone.<\/td>\n<\/tr>\n<tr>\n<td>3. Use the passphrase<\/td>\n<td>Owners and anyone with payment authority agree on a private verbal passphrase, set in person, never written in email or chat.<\/td>\n<td>AI can clone a voice from public audio. It cannot know a secret that was never digitized.<\/td>\n<\/tr>\n<tr>\n<td>4. Enforce a cooling period<\/td>\n<td>New or changed payment instructions wait 24 hours before first use, no exceptions for urgency.<\/td>\n<td>Manufactured urgency is the engine of every one of these scams. Remove it.<\/td>\n<\/tr>\n<tr>\n<td>5. Two people on big moves<\/td>\n<td>Transfers above a threshold you set (many firms pick $5,000) require a second person&#8217;s sign-off.<\/td>\n<td>One deceived employee is likely. Two, on the same lie, on the same day, is much less so.<\/td>\n<\/tr>\n<tr>\n<td>6. Make refusal safe<\/td>\n<td>Put it in writing: no employee will ever be disciplined for delaying a payment to verify it, even if the request came from the owner.<\/td>\n<td>Scams work because staff fear saying no to the boss&#8217;s voice. Take that fear away.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Notice what is not on that list. No AI detection software. No deepfake scanners. Detection tools lag the generators, and always will. A callback rule does not care how good the fake is, because it never asks anyone to judge authenticity in the moment. It routes around the question entirely.<\/p>\n<h2>What Else Should a Small Business Lock Down?<\/h2>\n<p>Procedure first, then three technical basics. Turn on multi-factor authentication everywhere, since Microsoft research shows MFA blocks about 99.2% of account-compromise attacks. Add a mail rule flagging external emails that spoof internal names. Then rehearse the callback protocol once with a live drill so it survives contact with a real Tuesday.<\/p>\n<p>MFA deserves the emphasis. Business email compromise usually starts with one hijacked mailbox, and <a href=\"https:\/\/www.microsoft.com\/en-us\/research\/publication\/how-effective-is-multifactor-authentication-at-deterring-cyberattacks\/\" rel=\"noopener\" target=\"_blank\">Microsoft&#8217;s research<\/a> on MFA effectiveness makes it the single highest-leverage switch you can flip this week. Prefer an authenticator app over SMS where you can.<\/p>\n<p>Also worth an hour: an audio audit. Search your own website, YouTube, and social accounts for clear recordings of anyone with payment authority. You do not need to delete them. You need to know they exist, and to assume any voice on the phone can be faked. That mental shift is the real control.<\/p>\n<p>One more angle owners often miss. The same automation that runs your operations can enforce these rules for you. A payment-change request that automatically opens a verification task, holds the vendor record for 24 hours, and pings a second approver is a scam-resistant workflow by design. That is the kind of guardrail we build into every system in our <a href=\"\/ai-automation.html\">AI and business automation work<\/a>: automations that move fast but refuse to skip verification, because software does not get flustered by an urgent voice on the phone.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<section aria-label=\"Frequently asked questions\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\">\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h3 itemprop=\"name\">How common are AI-generated phishing attacks in 2026?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\">Very common. Hoxhunt&#8217;s Phishing Trends Report 2026 found AI-generated messages rose from under 5% of phishing emails in early 2024 to 56% by December 2025, settling near 40% in January 2026. The FBI&#8217;s IC3 2025 report logged over 22,000 complaints mentioning AI, tied to roughly $900 million in losses.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h3 itemprop=\"name\">Why do scammers target small businesses instead of large corporations?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\">Small businesses combine real money with thin verification. A 12-person company can wire six figures, but rarely has dual approval on payments or trained finance staff who question urgent requests. Small firms also publish enough online, voices in videos, names on LinkedIn, vendors on social media, to make impersonation easy.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h3 itemprop=\"name\">How much audio does a scammer need to clone someone&#8217;s voice?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\">About three seconds, based on Microsoft&#8217;s VALL-E research. A voicemail greeting, a podcast clip, or a video on your company website provides more than enough material to fake a phone call from your owner or bookkeeper.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h3 itemprop=\"name\">What is a callback verification protocol?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\">A written rule that any request to move money, change payment details, or share credentials must be verified by calling the requester back on a number you already have on file, never one supplied in the message. Paired with a private verbal passphrase for leadership, it defeats voice clones, deepfake video, and spoofed email alike.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h3 itemprop=\"name\">How much does business email compromise cost on average?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\">The FBI&#8217;s IC3 2025 Annual Report recorded $3.05 billion in BEC losses across 24,768 incidents, roughly $123,000 per incident. For most small businesses that is not a survivable hit, which is why a free verification protocol beats hoping your email filter catches everything.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<h2>Key Takeaways<\/h2>\n<ul>\n<li>AI wrote the majority of phishing email by late 2025, so &#8220;look for typos&#8221; is dead advice. Hoxhunt measured the jump from under 5% to 56% in under two years.<\/li>\n<li>The FBI logged $20.9 billion in 2025 cybercrime losses, with BEC averaging around $123,000 per incident. Small businesses are the preferred target because verification is thin.<\/li>\n<li>Three seconds of public audio is enough to clone a voice. Assume any voice on the phone can be faked, and verify the request instead of the voice.<\/li>\n<li>The complete defense is procedural and free: callback verification on known numbers, a verbal passphrase, a 24-hour hold on new payment details, and dual sign-off on large transfers.<\/li>\n<li>Well-built automation can enforce these rules without slowing your team down. Our <a href=\"\/services.html\">services team<\/a> designs workflows with verification built in. If you want a second set of eyes on how money and data move through your business, <a href=\"\/get-started.html\">start a conversation with WinTechnology<\/a>.<\/li>\n<\/ul>\n<p><em>Written by <strong>The WinTech Desk, WinTechnology Inc.<\/strong> WinTechnology builds secure automations and advises small businesses on safe AI adoption. We are not a managed security provider; for 24\/7 monitoring, pair these practices with a reputable MSSP.<\/em><\/p>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>AI Phishing and Deepfake Scams in 2026: How Small Businesses Are Being Targeted (and a 15-Minute Defense Plan) TL;DR AI-written messages jumped from under 5% of phishing emails to 56%&hellip;<\/p>\n","protected":false},"author":1,"featured_media":145,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[36],"tags":[],"class_list":["post-144","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"_links":{"self":[{"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/posts\/144","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/comments?post=144"}],"version-history":[{"count":0,"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/posts\/144\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/media\/145"}],"wp:attachment":[{"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/media?parent=144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/categories?post=144"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wintechnology.ai\/insights\/wp-json\/wp\/v2\/tags?post=144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}