Phishing in the Age of Deepfakes: A Field Guide for Small Teams
Scam emails no longer have typos, and the voice on the phone might be cloned. Simple processes that protect a small business when you can't trust your eyes and ears.
For years, security training taught people to spot phishing by its flaws: bad grammar, odd formatting, a generic greeting. Generative AI has erased most of those clues. Scam emails are now fluent and personalised, and voice and video can be convincingly faked from a few minutes of public recordings.
You can't train people to detect a perfect fake. You can build processes that make a perfect fake harmless. Here's how.
How modern scams work
The most damaging attacks on small businesses usually aren't technical. They're requests:
- Payment redirection. "We've changed banks — please use these new details for the attached invoice."
- Executive impersonation. A message, call or even video call from "the CEO" asking for an urgent transfer or gift cards.
- Credential harvesting. A realistic login page for your email, file-sharing or accounting tool.
- Help-desk manipulation. Someone calls IT or a provider pretending to be an employee who's locked out.
All of them rely on two things: urgency and a single channel of trust — the request and its confirmation arrive the same way.
Rule 1: Verify through a second channel
The most effective defence is simple: any request involving money, credentials or sensitive data must be confirmed through a different channel you initiate.
- Email asks to change bank details → call the supplier on the number already in your records, not the one in the email.
- Voice message from the boss asks for a transfer → message them on your usual internal chat.
- Video call asks for something unusual → end the call and call back.
Write this down as a policy so nobody feels rude doing it. Verification should be normal, not an accusation.
Rule 2: Agree on a safe word
For small teams and families, a pre-agreed code word for urgent, unusual requests is a surprisingly strong defence against voice cloning. If "the CEO" calls asking for an urgent payment and can't give the word, the conversation is over. Change the word if it's ever used in a message that could be intercepted.
Rule 3: Slow down money
Most payment fraud succeeds because the money moves before anyone has time to think.
- Require two people to approve new payees or changes to bank details.
- Add a waiting period — 24 hours, for example — before payments to new accounts.
- Keep a list of verified supplier details and treat every change as suspicious until confirmed.
These cost little and stop the majority of payment scams outright.
Rule 4: Make credentials worthless
If you can't stop every fake login page, make stolen passwords useless:
- Passkeys or hardware security keys for email and critical accounts. They can't be used on a fake site.
- Authenticator apps instead of SMS codes where passkeys aren't available.
- A password manager for everyone. It won't autofill on a look-alike domain, which is itself a warning sign.
Rule 5: Reduce what attackers can learn
Personalised scams are built from public information. Review what's easy to find:
- Org charts, job titles and reporting lines on your website.
- Long voice and video recordings of executives.
- Details about suppliers, payment processes and tools in job adverts.
You don't need to disappear online — just avoid publishing a ready-made script for impersonating you.
Training that actually helps
Instead of "spot the typo" exercises, train for behaviours:
- Recognise pressure tactics: urgency, secrecy, authority, unusual payment methods.
- Practise verification: make calling back feel routine.
- Celebrate reporting. Thank people who flag suspicious messages, even false alarms. The worst outcome is someone who suspects a scam but doesn't want to look silly.
If something gets through
Have a short, written plan:
- Contact your bank immediately to attempt to stop or recall payments.
- Reset affected passwords and sign out active sessions.
- Check email forwarding rules — attackers often add them quietly.
- Tell your team, suppliers or customers if they might be targeted next.
- Report the incident to your national fraud or cybercrime agency.
The takeaway
When anything can be faked, trust the process, not the message. Second-channel verification, two-person approvals and phishing-resistant sign-in will protect your team far better than any attempt to out-spot a machine built to be convincing.
Have something worth publishing?
We accept guest posts across all 8 topics, edited and published within days.