Skip to content
AI Metric

Chris

AI has changed the cyber threat to UK small businesses

The same models that draft your quotes now draft the other side's phishing. Fluent, personalised attacks are cheap to produce at scale, the old tells (bad spelling, generic greetings, clumsy phrasing) are gone, and voice cloning means a caller who sounds exactly like the director is no longer proof of anything. The defences that still work are process controls: call-back verification on payment changes, multi-factor authentication everywhere, least privilege on accounts.

What has not changed is the objective. The attacker wants a payment redirected, a login captured or your files encrypted, exactly as before. AI has changed the quality and volume of the approach, not the destination. That matters, because it means the controls that beat it are boring, procedural and mostly free.

What has actually changed about the threat?

Three mechanisms, none of them exotic.

First, fluency at scale. A language model writes a natural, correctly spelled, well-mannered email in seconds, in your supplier's tone, referencing a live project it found on your website or inside a compromised mailbox. Personalised attacks used to cost an attacker hours per target, so small firms rarely received them. That marginal cost is now close to zero, so a twelve-person contractor gets the treatment once reserved for banks.

Second, voice. A short sample of speech, a clip from your website or a voicemail greeting, is enough to produce a convincing clone. The classic use is a Friday afternoon call to accounts from "the MD", urgent and confidential, asking for a payment to be released before the weekend.

Third, patience inside real conversations. A compromised inbox lets an attacker read a genuine invoice thread for weeks, then join it at exactly the right moment with new bank details, quoting the real invoice number and the real surnames.

Why do the old tells no longer work?

Because they were never signs of fraud. They were signs of attackers working fast in a second language, and a model removes all of them in one pass.

Staff were trained to spot misspellings, "Dear customer", odd phrasing. That training now filters out only the attacks that were already failing. What cannot be polished away are the structural tells, because they are the attack itself: urgency, secrecy, a change to payment details, a switch of channel, a request that sidesteps normal process. Detection has to move from how a message reads to what a message asks for.

Which controls actually stop these attacks?

The approachWhat it looks like nowThe control that beats it
Invoice fraudA fluent email inside a real supplier thread announcing new bank detailsCall back on a number you already held before the request, never one from the email
Director impersonationA cloned voice or plausible message demanding an urgent, confidential transferNo payment on a call or message alone; a second person authorises every new payee
Credential phishingA perfectly branded login page behind a perfectly written emailMulti-factor authentication on email, banking and accounts software
Account takeoverA quiet attacker reading and joining genuine threadsLeast privilege, so one mailbox cannot reach banking, payroll and every shared drive
RansomwareThe same fluent lure carrying malwareUpdates applied promptly, and backups kept offline or versioned, tested by restoring

Notice what is missing from the right-hand column: any judgement about whether a message feels genuine. Every control assumes the message will be convincing, because from now on it will be. The NCSC Small Business Guide covers the baseline (backups, malware protection, passwords and MFA, phishing) in an afternoon's reading, written for firms without an IT department.

What is the call-back rule, and why adopt it this week?

Because payment diversion is the attack that closes small companies, and the control costs nothing.

The rule: any change to bank details, any new payee and any urgent payment request is verified by phoning a number you already hold on file and speaking to a person you know. Not the number in the email signature. Not a reply to the message. Not a callback the requester kindly offers to arrange.

And it binds everyone, including the MD, which is precisely why it works. If the real director cannot waive the check in the moment, the cloned one cannot either. Write it down, tell your suppliers you operate it, and ask whether they do the same, because your money also travels through their inboxes.

What are your duties if something gets through?

Move on the money first: your bank may be able to recall a transfer if told within hours rather than days.

Then assess the data. If personal data was involved (a raided mailbox usually holds plenty) and the breach is likely to put individuals at risk, you must report it to the ICO within 72 hours of becoming aware. Where you judge it not reportable, record that assessment anyway. Being able to show your reasoning afterwards is part of accountability under UK GDPR, and it is much easier to write on the day than six months later.

Where does AI sit on your side of this?

The same place it sits everywhere else in the business: governed, not banned and not ignored.

Your staff will use these tools either way, so give them a sanctioned route rather than a blanket ban, keep client and personal data out of free tools (the public versus private tier question), and treat the whole subject as a leadership position rather than an IT ticket. A firm that has decided how it uses AI is usually also a firm that has decided how it verifies payments.

The threat got better at writing. Your defence should stop depending on reading. A call-back rule, MFA and least privilege beat the sharpest suspicious eye, because the eye is now up against a machine that writes better than most people.

AI Metric is a construction-native AI consultancy. If your team is spending more time operating software than doing their job, get in touch or book a call.