AI voice scams are hitting small businesses. Set this one rule by Friday.
AI voice scams now target small businesses by faking the confirmation call. Here is the free, ten-minute rule that stops them, and what to skip.
BlueFort AI
BlueFort AI
The call comes in at 4:40 on a Friday. It is the controller at your biggest customer. You know her voice. She says the invoice you just sent has the old bank details on it, the corrected ones are in the email she sent an hour ago, and can you please get it pushed through before the cutoff.
It is not her. It was never her.
AI voice scams are now pointed squarely at small businesses, and here is the ugly part: the fraud advice you were given years ago is the exact thing that gets you robbed.
Why this landed on your desk this month
In its 2025 annual report, the FBI’s Internet Crime Complaint Center gave artificial intelligence its own section for the first time in the center’s 25 year history. The headline numbers: 22,364 complaints where the victim could tell AI was involved, and roughly $893 million in losses.
Note the phrase “could tell.” The FBI says that figure almost certainly undercounts, because most victims never find out AI was in the room at all.
Then there is the line in the report that should stop you cold. Business email compromise, the wire fraud category that took $3.05 billion off American businesses in 2025 across 24,768 complaints, now has a confirmed AI slice worth more than $30 million. The report spells out the method: voice cloning used to place the follow-up call that appears to come from a CFO or a CEO, reinforcing written wire transfer instructions.
And on July 20 the FBI issued a fresh public warning (alert I-072026-PSA) about criminals posting deepfake videos of senior FBI officials on social media to funnel people toward fake complaint websites. If they are willing to clone the Bureau’s own leadership, nobody is treating your voice as a hard target.
In plain English: the scam is the confirmation call
Most owners think the danger is the fake email. You already know to squint at the email. That is not where the money goes.
The danger is the phone call that makes the email feel safe.
Every fraud briefing ends the same way: if payment details change, pick up the phone and confirm it with a human. Criminals read that advice too. So now they want you to call. They put a number in the email, or they call you first. And the voice that answers is the voice you were expecting.
In plain English: voice cloning is text to speech trained on a sample of a real person’s voice. Feed it a short clip and it will read whatever the operator types, in that person’s voice, live, mid-conversation. The clip is not hard to get. It is the podcast you went on, the panel you sat on, the webinar recording on your own website, the outgoing message on your cell phone.
Your voice is not a password. It stopped being one a while ago. Most businesses just have not updated the rule.
The one rule
Here it is, in a sentence you can paste into an email today:
No money moves and no payment details change on the strength of a voice.
That is the whole policy. Everything below is how you make it real, and it takes about ten minutes.
1. Call back on a number you already had. Not the number in the email. Not the number that called you. The number in your accounting system, on the signed contract, or in the vendor record you set up two years ago. Out of band or it does not count.
2. Agree on a code word. One for your internal team, and one with each vendor or customer who moves real money with you. Say it out loud on money calls. It costs nothing, and it is the single fastest tell.
3. Write down that slowing a payment is never punished. This is the step people skip and it is the one that matters most. These scams run on urgency plus a junior person’s fear of irritating the boss. Take that fear off the table in writing, and half the attack stops working.
4. Two humans on anything over a threshold. Pick a number that would actually hurt to lose. Two thousand dollars, ten thousand, whatever is true for you. Above it, a second person approves, and never over chat.
5. Run one fake attempt. Call your own bookkeeper, do the urgent voice, ask for a payment detail change, and watch what happens. You will learn more in five minutes than from any training video.
Then tell your customers and vendors what your process is. Fraud protection only works in both directions.
What this means for you
For your business: this costs zero dollars and one meeting. There is no product to buy here, which is why nobody is running ads about it. It is also the highest return security work available to a company your size, because wire fraud is not a slow leak. It is one bad Friday afternoon and the money is gone.
At home, the same rule with a different label. The FBI report counts more than $5 million in “distress scams,” the ones where a cloned voice calls a parent or grandparent in a panic asking for money right now. Pick a family code word this weekend. It is the same fix.
The honest limits
This does not make you scam proof, and I am not going to pretend it does.
Do not trust your ear. The old tells (flat delivery, odd pauses, a slightly robotic edge) are mostly gone, and training your staff to “listen for the fake” gives them false confidence in the one moment you need them cautious.
Voice-clone detection software exists and is being sold hard. For a business your size, treat it as not yet. It adds cost and a vendor relationship to solve a problem a callback rule already solves, and detection accuracy in a live phone call is nowhere near good enough to bet a payment on.
The verdict
The callback rule: worth it. Do it this week. Free, ten minutes, and it defends against the attack that actually empties accounts.
Voice-clone detection tools: not yet. Process beats software here, and it is not close.
The broader point is one we keep landing on. AI did not invent this fraud, it just made the convincing part cheap. Your defenses have to stop depending on things AI can now fake for pennies: a voice, a face, a well-written email. What it cannot fake is a number you already had in your records and a word you agreed on in advance.
While you are at it, know what your team is already pasting into AI tools, and if you are putting an AI voice on your own phone line, understand that your customers are getting trained to trust synthetic voices too.
Reading about fraud is free. A wire that leaves your account is not. When you want the boring parts done properly (the payment controls, the email authentication, the policy your team will actually follow), that is BlueFort IT’s day job.
Want the AI firehose decoded like this, verdict and all, twice a week? The newsletter signup is right below.
Want this kind of thinking applied to your business?
BlueFort IT helps you adopt AI safely and put it to work.
Talk to BlueFort IT