Skip to content
Go to homepageDrova logo

AI scams targeting businesses

Old scams, industrialised. What changed and what still works against them.

Almost no AI scam is a new scam. What AI changed is the economics: polish, personalisation and volume that used to take skill now take a subscription. This page maps the family and routes you to the deep dives.

Simple feature visual

TL;DR

  • AI scams against businesses are mostly familiar scams with three multipliers applied: perfect polish, personal detail pulled from public sources, and volume that costs the attacker nothing.
  • The family has four branches: payment and impersonation fraud, credential theft, fake counterparties, and extortion or reputation attacks.
  • The old tells, clumsy grammar, generic greetings, odd tone, are gone. The tells that remain are behavioural: urgency, channel switching, and resistance to verification.
  • The safeguards are process, not detection: callbacks on known numbers, out-of-band checks, dual approval with no urgency exceptions.
  • Report early. In Australia, the ACSC; in the UK, the NCSC. Banks can sometimes recall payments if told fast.

What makes a scam an AI scam?

Usually nothing about the scam itself. Invoice fraud, executive impersonation, fake suppliers and phishing all predate AI by decades. What earns the label is how they are now made: fluent messages in any language and register, cloned voices, personalised approaches assembled from public information, and thousands of attempts run for the cost of one.

That shift matters for defence. Training that taught people to spot the fakes by their roughness now protects against attackers who no longer exist. The scams your business will actually meet are polished, are addressed to the right person by name, reference real projects and suppliers, and arrive in believable numbers.

One page in our series on the real risks of AI for a business: old entries on the register, with the likelihood turned up.

The four branches of the family

Payment and impersonation

Cloned voices, faked video calls, perfect invoices, redirected bank details. The money branch, covered in depth in Fraud no longer needs a forger.

Credential theft

Phishing with flawless grammar and personal context, aimed at logins rather than payments. The stolen account then powers the other three branches.

Fake counterparties

Suppliers, customers, even job applicants who do not exist: AI-generated websites, references, profiles and interview performances that pass a casual check.

Extortion and reputation

Fabricated compromising material, fake reviews at scale, and threats to publish AI-generated content unless paid. Damage does not require the material to be real.

Detection has moved

The tells that remain

The old advice, look for bad grammar, generic greetings, strange phrasing, now selects for the least dangerous attackers. What remains are behavioural tells, because they are the parts the scam cannot remove without breaking itself.

Manufactured urgency. The scam needs you to act before you verify; a genuine counterparty survives an hour's delay. Channel switching. Requests to move from the channel where you could verify to one where you cannot. Verification resistance. Any pushback against a callback, a known number, or a second approver is itself the strongest signal you will get.

Which is why the safeguards are process rather than perception: callbacks on numbers you already had, out-of-band checks on any change of payment details, and dual approval that urgency can never bypass. The full set is on the safeguards page.

When it happens

If your business is hit

Speed matters more than embarrassment. Contact your bank immediately if money moved, recalls sometimes succeed in the first hours. Preserve the messages rather than deleting them. Report it: in Australia through the ACSC, in the UK through the NCSC's reporting routes. Then tell your people what the attempt looked like, because the same campaign usually tries several doors.

Afterwards, treat it as free intelligence: re-score the register entry it exploited, and check the safeguard that should have held. Honest reporting inside the business is a safeguard too, and it only works where reporting is never punished.

AI scams FAQs

What are the most common AI scams against businesses?

Payment fraud through cloned voices and polished invoices, credential phishing with personal context, fake counterparties such as suppliers or applicants who do not exist, and extortion using fabricated material. Most are established scams with AI-grade polish, personalisation and volume.

How do you spot an AI scam?

Not by quality any more. The reliable tells are behavioural: manufactured urgency, requests to switch channels, and resistance to verification. If a request cannot survive a callback on a number you already had, treat that as your answer.

Why are small businesses targeted?

Payment authority is concentrated in a few people, verification often relies on familiarity rather than process, and the volume economics of AI mean attackers no longer skip small targets. The same campaign can try ten thousand small businesses for the cost that used to buy one attempt.

What should we do immediately after a scam?

Bank first if money moved, since recalls sometimes succeed early. Preserve evidence, report through the ACSC in Australia or the NCSC routes in the UK, warn your own people, and then re-score the register entry the scam exploited while the details are fresh.

Do AI detection tools stop AI scams?

Not dependably, and building your defence on detection repeats the mistake that made these scams effective. Process safeguards, callbacks, out-of-band verification and dual approval, work whether or not the fake is detectable.

The AI Disruption Index scores the risks AI is driving against your objectives, with a safeguard drafted for each. Free, in about ten minutes.

Scams are one branch. See the whole tree.