Protecting your business against AI-powered phishing in 2026 rests on four pillars: awareness training adapted to the new attacks, phishing-resistant multi-factor authentication, dual-approval procedures for every payment or bank detail change, and hardened technical filtering. The old reflexes — hunting for spelling mistakes or awkward wording — are no longer enough: generative AI produces flawless, personalized messages, and now cloned voices and faces.
How AI industrialized phishing
For years, mass phishing gave itself away through clumsiness: rough translations, pixelated logos, generic phrasing. That era is over. With large language models, an attacker produces in seconds a perfectly written email, in impeccable language, that mirrors the tone of your industry and even your company's internal communication style.
Above all, AI enables personalization at scale. By automatically cross-referencing LinkedIn profiles, press mentions and an SMB's website, an attack tool generates messages that name the right contact, the right ongoing project, the right supplier. What used to be handcrafted targeting reserved for large corporations now hits companies of 20 to 500 employees, often far less well defended.
Cloned voices and video deepfakes: CEO fraud 2.0
A few seconds of audio are now enough to clone a voice convincingly: an interview, a webinar, a voicemail. Attackers use it to call an accountant while impersonating the CEO and demand an urgent transfer. The next stage is already here: deepfake video in conference calls. The most publicized case remains that of an international group whose Hong Kong employee approved transfers of roughly 25 million dollars in early 2024, after an entire video call in which every participant — including the chief financial officer — was a deepfake.
The signals that no longer work, and the reflexes replacing them
Say it plainly to your teams: a flawless, personalized, credible message can be an attack. Signals to abandon: spelling mistakes, generic tone, poor formatting. Reflexes to build instead:
- Context beats form: any unusual request (wire transfer, bank detail change, gift card purchase, data export) is suspicious, however well written it is.
- Urgency is a red flag: time pressure and demanded secrecy (do not mention this matter to anyone) are the two constants of CEO fraud.
- Verify through another channel: call the person back on a known, recorded number — never the one provided in the message. This applies to video calls too: video no longer proves identity.
- Watch the side channels: SMS, WhatsApp and phone calls bypass your email filters and are used massively.
The defense plan for an SMB
1. Modern awareness training, not an annual e-learning module
A generic yearly course prepares no one for a deepfake. Invest in short, regular sessions, realistic phishing simulations (including by phone), and above all a blame-free culture: an employee who reports having clicked should be praised for the report, not punished. Speed of reporting is what limits the damage. The goal is not to turn every employee into a security expert, but to anchor one single reflex: whenever a request involves money, credentials or sensitive data, verification through a second channel is non-negotiable, whoever seems to be asking.
2. Phishing-resistant MFA
Not all MFA is equal. SMS codes and push notifications can be bypassed with real-time proxy kits or through user fatigue. Favor passkeys and FIDO2 security keys, which cryptographically bind authentication to the real domain: even a user fooled by a pixel-perfect login page cannot hand over access. Deploy them first on email, IT administration and financial tools.
3. Dual-approval payment procedures
The best defense against wire fraud is organizational: above a defined threshold, every payment and every change of bank details requires validation by a second person and a callback to the beneficiary on an independently verified number. Put this rule in writing and state that no exception is possible, even at the CEO's request — that is precisely what the attacker will simulate.
4. An up-to-date technical baseline
Configure SPF, DKIM and DMARC in strict mode to make spoofing your domain harder, enable your email platform's advanced filtering, deploy EDR on workstations and offer a one-click reporting button. These measures will not stop everything, but they cut the volume and speed up detection. Review these settings at least once a year: attackers probe email configurations constantly, and a domain left in permissive mode is an open invitation to impersonate your company with your own suppliers and customers.
You clicked? The first 30 minutes
- Report immediately to your IT lead or your provider: speed matters more than anything.
- Change the affected account's password from another device, and revoke active sessions.
- If a file was opened, disconnect the machine from the network without shutting it down, to preserve evidence.
- If a transfer went out, contact your bank without delay to attempt a recall, then file a complaint.
- If personal data leaked, assess the notification obligations to your data protection authority within 72 hours.
Against attacks that evolve every quarter, protection is no longer a one-off project but a continuous discipline: testing your defenses, adjusting your procedures, training your teams. A regular external audit and a technical partner able to respond fast the day a doubt arises often make the difference between a contained incident and a costly crisis.
