How AI Is Making Business Email Compromise Harder to Detect
Key Takeaways
- Cybersecurity Awareness Month is a good moment to revisit how artificial intelligence (AI) has changed business email compromise (BEC) and payment fraud, making them harder to catch with old warning signs.
- AI-generated phishing emails succeed at a far higher rate than manually written ones, and voice and video deepfakes are become far more widespread as technology improves.
- Five practical steps can meaningfully reduce exposure: stronger internal controls, updated training, a data classification policy, tabletop exercises and a cyber insurance review.
- Verification built into everyday habits is the most reliable defense against AI-enabled fraud.
We hear these stories more than you might think. A client receives what looks like a routine email from a trusted vendor, same name, same email format, same friendly tone they’ve exchanged for years. The instructions are simple: process the payment as usual, just use this updated account number. No red flags, no alarm bells, and by the time anyone realizes the email didn’t come from the vendor at all, the funds are gone.
Business email compromise and payment fraud have been around for years, but artificial intelligence (AI) has made them dramatically harder to detect.
What once required a skilled attacker, significant time and considerable effort can now be accomplished in minutes using widely available tools, and the results are increasingly convincing. We’ve worked with clients who had solid processes in place. The request still succeeded because it was indistinguishable from the hundreds of legitimate ones they’d processed before.
Recent data reflects just how quickly this threat has evolved:
- According to KnowBe4’s 2026 Phishing Threat Trends Report, 86% of phishing attacks are now AI driven, and phishing volume rose 17.1% over the previous six months.
- Microsoft’s 2025 Digital Defense Report found that AI-generated phishing emails achieve a 54% click-through rate compared to just 12% for manually crafted ones, making them 3.5 times as effective.
- According to CrowdStrike’s 2026 Threat Hunting Report, voice phishing intrusions doubled in the first half of 2026 compared to the second half of 2025.
- In its 2025 Internet Crime Report, the Federal Bureau of Investigation (FBI) dedicated a section to AI-related cybercrime for the first time in its 25-year history, recording nearly $893 million in reported losses associated with AI-related complaints. The actual impact may be higher because victims may not recognize or report the role AI played in the fraud.
The Warning Signs We Used to Rely On Are Disappearing
For years, spotting a suspicious email came down to familiar red flags:
- Awkward grammar
- A generic greeting
- The sender’s email address that is slightly different than the legitimate address
We trained employees to look for those tells, and for a long time, that approach worked reasonably well. AI has quietly retired most of those cues.
Today, a phishing email can be written in the exact tone of your chief financial officer (CFO) or other executive, reference a real project your team is working on and arrive from an address that looks legitimate. A voicemail can sound indistinguishable from your managing partner. A video call can feature a face you trust, saying words they never spoke.
According to Pindrop’s 2026 Deepfake Readiness Index, 74% of security leaders say their organization has encountered or suspects a deepfake attack in the past year. One in four of those affected reported losses exceeding $1 million from a single incident, often from impersonation of a trusted executive or colleague. What makes these attacks particularly challenging is that they exploit something no firewall can filter: human trust. We are wired to respond to familiar voices, recognize writing styles and act on requests from people we know and respect, and attackers are engineering their approach around exactly those instincts.
One of the most significant shifts happening right now is what security researchers call multi-channel attacks, where criminals coordinate email, voice, text messages (SMS) and video in a single, highly targeted operation. A bad actor can research a target using publicly available information, clone a voice from a conference recording, generate a deepfake video and launch a coordinated attack within a single afternoon.

Five Practical Steps for Business Email Compromise Prevention
1. Strengthen Your Internal Controls Around Financial Processes
Some of the most effective defenses against AI-enabled fraud come down to process and controls. Proper segregation of duties ensures no single person can initiate and approve a financial transaction on their own. And any request to update vendor banking details should trigger a mandatory multi-step verification process separate from the channel that delivered the request. For organizations already working within a Sarbanes-Oxley Act (SOX) or System and Organization Controls (SOC) framework, many of these controls are familiar territory. The key is making sure they extend to the scenarios AI-powered fraud is creating today.
2. Update Your Training and Verification Protocols
If your security awareness training hasn’t been refreshed in the past year, it’s likely teaching your employees to spot yesterday’s attacks. Your team needs to understand:
- What AI-generated phishing looks like
- What voice cloning is
- Why a convincing-sounding request still warrants a second look, even when everything about it appears legitimate.
One of the most important behaviors to reinforce is a healthy skepticism around urgency. AI-powered attacks almost always pressure recipients to act now, skip the normal approval process or avoid looping in a colleague. Training your team to treat that pressure as a warning sign rather than a reason to move faster is one of the most effective shifts you can make.
Pairing updated training with a pre-established verification protocol for high-stakes requests, whether that’s a challenge phrase agreed upon in advance or a required callback on a known number, adds another layer of protection that’s simple enough for people to follow consistently under pressure.
3. Establish a Data Classification and AI Acceptable Use Policy
Before your organization can effectively manage the risks AI introduces, you need to understand what data you have, where it lives and how sensitive it is. A data classification framework helps define what information can be shared, stored or processed and by whom. That foundation becomes especially important as employees adopt AI tools in their day-to-day work. Without a clear policy governing how those tools can be used, well-intentioned employees can inadvertently expose sensitive client data, proprietary information or financial records to platforms that aren’t approved or secured for business use. Defining both what your data is and how AI can interact with it gives your organization a meaningful layer of protection that many organizations are still developing.
4. Run a Company-Wide Tabletop Exercise and Know Your Response Plan
A tabletop exercise is one of the most practical investments your organization can make right now, and the most effective ones go well beyond information technology (IT). Walking your finance, operations, legal and leadership teams through a realistic AI-driven attack scenario, whether that’s a fraudulent wire request, a deepfake impersonation of an executive or a coordinated multi-channel phishing attempt, helps the entire organization understand how these threats actually unfold and where the gaps in your response process exist. It’s also an opportunity to stress-test how AI is being used within your own organization, ensuring the tools your teams rely on day to day aren’t inadvertently creating new vulnerabilities. Most organizations focus heavily on prevention but have no documented plan for what happens when an attack succeeds. Knowing who to call, what to escalate and how to contain damage in the first hours of an incident is just as important as the controls designed to prevent one, and a well-run tabletop exercise is the most effective way to find out whether that plan actually holds up under pressure.
5. Review Your Cyber Insurance Policy
Many businesses assume they’re covered for social engineering and AI-enabled fraud, only to discover their policy has sublimits or exclusions for exactly these scenarios. Understanding your coverage before an incident is critical, and the time to address questions with your broker is now, not after a loss forces the conversation. Key areas to examine include:
- Whether your policy covers funds transfer fraud
- Social engineering losses
- Business email compromise
- What your insurer requires you to have in place in terms of controls and training before honoring a claim
The Bigger Picture
AI is accelerating, and so is the creativity of the people using it for malicious purposes. The organizations that navigate this environment best will be the ones that took the time to assess where they were exposed, put the right controls and processes in place and built a culture where verification is normal and questioning is encouraged.
The Moore Colson Risk Advisory team can help assess where your organization is exposed and build the controls needed to stay ahead of AI-driven fraud.
FAQ
What should I do immediately if I suspect a business email compromise attempt?
Contact your financial institution right away to request a wire recall, loop in your IT or security team and preserve the original email or message rather than deleting it. Acting within the first hours meaningfully improves the odds of recovering funds.
How does business email compromise differ from a typical phishing attack?
General phishing often casts a wide net to steal credentials or install malware. Business email compromise is narrower and more deliberate, usually impersonating a specific trusted person to redirect a real payment or request sensitive information.
Are small and midsize businesses actually targeted, or is this mainly a large-enterprise problem?
Small and midsize businesses are frequent targets, in part because they often have fewer layered controls in place than larger organizations, even though headlines tend to focus on the biggest losses.
Who helps a business recover funds after a business email compromise loss?
If funds are wired quickly enough, the FBI’s IC3 Recovery Asset Team can work with financial institutions to freeze and potentially recover them through what’s called the Financial Fraud Kill Chain, though speed is critical to any recovery effort.
About the Author
Enessa Mikhaliants, CISA, is a Senior Manager in Moore Colson’s Risk Advisory Practice Area. She leads IT audit and advisory engagements for companies across the healthcare, professional services, distribution, technology and transportation industries.
Disclaimer: This content is provided for informational purposes only and reflects information available as of the date of publication. It does not constitute legal, tax, accounting, or other professional advice. Please consult a qualified professional before taking action based on this content.

