Back to blog
Cybersecurity

AI scams: how to protect your business

AI scams: how to protect your business

Deepfake voices, flawless phishing emails and fake video calls are now cheap to produce. The good news for small businesses is that the defences have barely changed.

AI has made scams much harder to spot. Stopping them is still about the basics.

In early 2024, a finance employee at the engineering firm Arup joined a video call with his chief financial officer and a few colleagues. The CFO asked him to make a series of urgent transfers. He knew the faces and the voices, so he did as asked: 15 payments, 25 million US dollars, into five Hong Kong bank accounts. Everyone on that call except him was a deepfake. The faces and voices had been rebuilt from clips the executives had posted online.

That case made headlines because of the sum. The method behind it is now ordinary.

What actually changed

Scams are old. What changed is the cost of running a convincing one.

A few years ago, a fraudster targeting your company needed decent language skills, some research and a lot of patience. Now an AI tool writes a clean email in seconds, in any language, in the tone of a real supplier. Voice cloning needs about three seconds of clear audio to copy someone well enough to fool a colleague. Video deepfakes that once took a studio now run on a laptop.

The numbers follow the technology. A study by the security firm Surfshark put reported losses linked to deepfakes in Europe above 1.3 billion euros, with 860 million of that in 2025 alone. People click AI-written phishing emails far more often than the clumsy ones we all learned to ignore, because the spelling mistakes and the odd phrasing are gone.

Why this is landing in Estonia now

Estonia used to have a natural filter: the language. A scam written in broken Estonian was easy to spot. That filter is going. AI now writes clean Estonian, and Estonian voice cloning improves every year, even if it still trails English.

The damage is already visible. The Information System Authority (RIA) reported that people in Estonia lost around 29 million euros to fraud in 2025, roughly three times the year before. The Estonian Artists' Association lost 700,000 euros to a single scam. Most of these attacks still involve a real person on the phone and a familiar script: an urgent call, a second call "from the bank" warning you about the first, and a push to confirm with your Smart-ID or Mobile-ID. Add a cloned voice to that script and the last obvious warning sign disappears.

The defences that still work

One weakness sits under almost every one of these attacks. Someone acts on a request without checking it through a second channel. Break that habit and most of the effort collapses.

Verify money and data requests out of band. If an email, call or video asks for a payment, a change of bank details or sensitive data, confirm it through a contact method you already have, not the one in the message. Hang up and call the person back on their known number.

Treat urgency as the warning, not the reason to hurry. Fraudsters manufacture time pressure on purpose, because a rushed person skips the check. A real colleague will not mind you calling back in five minutes.

Lock down payment changes. Any change to a supplier's bank details should need a second person to approve it and a call to a known number to confirm it. This one control stops the most expensive kind of fraud.

Shrink your audio and video footprint where you can. Every conference recording, podcast and webinar featuring your executives is training material for a voice or face clone. You will not remove all of it, and you should not try, but it helps to know that public footage of your finance director carries a small cost.

Make it safe to pause. Staff fall for these scams partly because they do not want to question someone who sounds like the boss. Tell your team in plain terms that checking a payment request will never get them in trouble, and that you would rather wait than lose 50,000 euros.

Keep the dull basics running. Multi-factor authentication, a password manager and prompt software updates will not stop a deepfake call, but they shut the easy doors, so attackers have to attempt the hard ones.

AI helps the defenders too

The same technology cuts both ways. Modern email filters use AI to catch patterns a person would miss, flag a supplier whose writing style suddenly shifts, or spot a login from an odd location. It is worth having. Treat it as a smoke alarm rather than a sprinkler: it buys you warning, not a guarantee, and none of it replaces a person picking up the phone to check.

Most of this is process, and process can be built

Look again at the list. The strongest defences are not products. They are habits: a callback rule, a second approver on payment changes, a clear "it is fine to pause" message from the top. The weak point is that these habits depend on a busy person remembering them under pressure.

That is where automation earns its place. A payment-change request can route through an approval step before anyone can act on it. A new supplier can trigger a verification checklist before a single invoice gets paid. The system, not the memory of a tired employee on a Friday afternoon, enforces the pause. Building those quiet guardrails into how a company already works is a large part of what we do at Nopler.

You cannot stop criminals from using AI. You can make your business the one that checks before it pays.