
Catching AI-Written Scams Starts With Verification


Picture an office manager at a small Long Island business on a Thursday afternoon. An email arrives from a vendor the company has paid for years. The vendor name is right, the invoice number follows the usual format, and the note explains that the vendor switched banks and needs Friday's payment sent to the new account. The writing is clean, polite, and sounds like every other email from that vendor.
A scammer can assemble that message in minutes, using details gathered about the business and polished by an AI writing tool. A call to the vendor at a number the business already has on file could expose the request before any money moves.
What the FBI Says AI Has Done to Scam Messages
In a December 2024 public service announcement, the FBI warned that generative AI tools can correct for the human errors that used to serve as warning signs of fraud. The same announcement noted that foreign criminals use AI translation to limit grammar and spelling mistakes in messages aimed at US victims. The misspellings and clumsy phrasing people were taught to look for are exactly what these tools clean up.
The FBI's Internet Crime Complaint Center began tracking AI-related complaints as their own category in its 2025 annual report. Business email compromise, the scam in which a criminal poses as a vendor, executive, or coworker to redirect a payment, accounted for more than $3 billion in reported losses in 2025. Business email compromise complaints that mentioned AI accounted for just over $30 million of that total. The FBI tags a complaint as AI-related only when the victim's report refers to AI, and the report observes that many victims do not realize how much AI may be involved in the scams that reach them.
A payment request deserves the same check whether a person or a machine wrote it, which is why verification is the habit worth building.
Where These Scams Show Up
Email is the first channel. The FBI's 2025 report notes that chat tools can quickly produce official-sounding emails that imitate a company's CEO or other officials, carrying phishing links or instructions to wire funds.
The phone is the second. The FBI has warned that criminals use AI-generated audio to impersonate relatives in staged emergencies and to pose as account holders to get into bank accounts. Its 2025 report adds that voice cloning can be used to request wire payments. A familiar voice on a call is still useful information, and it is also something a scammer can now imitate.
Scale is the third change. In its discussion of investment fraud, the FBI describes scammers using AI to generate thousands of conversations that each look different to the person receiving them. Its AI warning also notes that criminals embed AI chatbots in fraudulent websites to steer visitors toward malicious links. Answering questions and keeping a victim engaged used to cost a scammer time. Software now handles much of that work.
Some requests carry no link at all: new bank details for an existing vendor, a rush gift card purchase for the boss, a reply with an account number. Those messages give link-checking advice nothing to inspect. A call to a known number still applies to every one of them.
Build a Verification Routine
Make it a standing rule that no one acts on new payment instructions, a bank account change, or a gift card request until they confirm it by calling a number the business already has on file. The FBI gives the same advice: hang up, look up the contact information yourself, and call that number directly. The rule applies even when the request appears to come from the owner
Turn on multi-factor authentication for email, banking, and every account that offers it. CISA notes that any form of MFA is better than none
Use passkeys or security keys on email and banking where the provider supports them. CISA calls this phishing-resistant MFA the gold standard, because a fake login page can capture a typed code but cannot reuse a passkey
Keep public voice and video recordings of the owner and staff to what the business needs. The FBI suggests limiting online images and voice content to reduce the material scammers can work with
Consider a shared phrase for payment approvals as a second check, adapted from the FBI's advice that families agree on a secret word. Keep the callback as the main control, since a phrase can leak or get passed along
Give staff clear permission to pause any urgent or confidential request and verify it first, even when it seems to come from the top
If a Message Already Got Through
The right response depends on how far the message got.
If someone only received or read the request, the computer itself needs no repair. Verify the request through a number on file, and tell whoever handles IT so they can warn anyone else who may have received the same message
If someone clicked a link or opened an attachment, tell whoever handles IT exactly what happened. They can check the destination or file and scan the device. If something downloaded or ran, disconnect the computer from the network and have it examined. Our post on what to do when an employee clicks the wrong link walks through those first steps
If someone typed a password into a page the message led to, change that password right away, along with any other account that uses the same one, starting with email and banking
If money has already moved, call your bank immediately to request a recall, then file a complaint at ic3.gov with the full transaction details, as the FBI advises
Speed makes a real difference in that last case. In 2025, the FBI's Recovery Asset Team worked 3,900 such incidents and helped freeze about $679 million of roughly $1.16 billion in attempted theft, and the report stresses that time is critical.
Get a Second Opinion on a Suspicious Request
Unfrustrating Computers helps Long Island small businesses keep their computers patched, monitored, and cleaned up when something gets through, including malware removal after a suspicious click. If an email or call has your team unsure what to do next, Steven Burstyn can look at what happened and help you decide what to put in place.
Call 516-679-5540 or email info@unfrustratingcomputers.com to talk through a request before anyone acts on it.




Comments