The old advice for spotting a phishing email was simple: watch for typos, awkward grammar, and a sender address that looked a little off. That advice is quickly becoming useless.
AI tools can now write flawless, personalized emails in seconds — the kind that reference your actual vendors, mimic your boss’s writing style, and hit your inbox at exactly the right moment. Google’s 2026 Cybersecurity Forecast flags this as one of the biggest shifts of the year: attackers are using AI not just to write better emails, but to clone voices for follow-up phone calls that make the whole scam feel real.
If you run a small or medium business in Castle Rock or the Denver metro area, here’s what changed and what you can actually do about it.
What Changed
Phishing used to be a numbers game — send thousands of generic emails and hope a few people click. AI flipped that model. Now attackers can scrape a company’s website, LinkedIn profiles, and public records in minutes, then generate an email that sounds like it came from a real coworker or vendor, with correct names, correct project details, and zero red flags.
The bigger shift is voice. AI voice cloning can now recreate what an executive sounds like from a few seconds of public audio — a podcast clip, a webinar recording, even a voicemail greeting. Combine that with a well-written email, and you get a two-part scam: a message that looks legitimate, followed by a phone call that sounds exactly like your CEO confirming it.
3 Patterns Showing Up Right Now
1. The “urgent voice memo”
A voicemail or phone call that sounds precisely like your boss or a company owner, asking for a wire transfer, gift cards, or sensitive information — usually with urgency and a reason you can’t verify in person (“I’m in a meeting, just handle this quickly”).
2. The “perfectly normal” email
No spelling errors, correct tone, references a real invoice or vendor relationship — just one small change, like an updated bank account number for a payment. Because everything else checks out, it slips past people who’ve been trained to look for obvious red flags.
3. The multi-touch confirmation scam
An email arrives, and if you hesitate or question it, a follow-up call comes in from a cloned voice “confirming” the request is legitimate. The two channels reinforcing each other is what makes this version so effective — and so different from the smishing (SMS phishing) scams we covered last year.
What Actually Still Works
The good news: the defense hasn’t changed much, even though the attacks have gotten smarter.
- Verify through a second channel. If a request involves money or sensitive data, call the person back using a number you already have on file — never the number or link in the message itself.
- Require more than one person to approve financial changes. Wire transfers, vendor bank account updates, and gift card purchases should never rely on a single email or call, no matter how convincing.
- Treat urgency as a warning sign, not a reason to move fast. Real emergencies rarely require skipping your normal verification process.
These habits cost nothing to implement, and they work whether the scam comes from a human, a bot, or a cloned voice.
What To Do Next
If your team hasn’t reviewed how financial approvals and vendor changes get verified in the last year, now’s a good time. CRS can walk through your current process, flag the gaps, and run a quick awareness session for your staff so everyone knows what to watch for — no fear-mongering, just practical steps.
Reach out and we’ll help you build a process that holds up even when the email — or the voice on the phone — looks completely legitimate.