A finance worker in Hong Kong thought he was on a video call with his company’s CFO. Every face in the meeting was real except none of them were. He authorized 15 wire transfers that day totaling about $25.6 million. The “CFO” was a deepfake. The other participants were deepfakes. The whole thing was a video conference with zero real humans on the other end.
That was 2024. This year, deepfake scams pulled in roughly $96 million in losses in just the first four months, according to Surfshark’s tracking. A few minutes of YouTube clips or earnings call audio is the entire supply chain now. The attackers are not just deepfaking faces and voices anymore. They have started letting AI run the whole attack.
This is the part that is changing for small and medium businesses. Two years ago, AI in cybercrime was mostly “better phishing emails.” Today it is autonomous agents that pick their own targets, write their own spear-phishing, adapt when they get caught, and pivot to the next victim without the human operator ever typing a sentence. At the same time, the AI tools your own employees are quietly using, without IT knowing about them, are exfiltrating customer data into model training pipelines. You are getting attacked by AI from the outside and leaking through AI from the inside. Most SMBs are not set up to notice either one.
The Cheap, Personalized Attack Is Now the Default
SentinelOne’s 2026 numbers put autonomous AI agents behind 42% of phishing breaches globally. StationX pulled together the supporting data: AI-generated phishing emails achieve 54 to 78% open rates, compared to about 12% for hand-crafted phishing, and cost 95% less to run. The cost barrier that used to keep sophisticated phishing in the hands of well-resourced criminal groups is gone. The kid with a stolen credit card and a free LLM account is now a credible threat actor.
What changed is personalization. Modern AI phishing pulls the target’s recent LinkedIn post, the name of their kid’s soccer team, the title of the talk they gave last week, and assembles an email that reads like it came from someone who knows them. It signs in the writing style of their actual boss. The grammar tells are gone because there is no grammar to check. The model did not write badly. It wrote well, because you wrote well, and it learned from the internet.
The other piece of the shift is voice and video. The UK energy company case used a 3-second audio clip of the parent company’s CEO to authorize a $243,000 transfer. Three seconds of audio. The Hong Kong victim grew suspicious, asked for a video call, and was reassured by what he saw. The verification step made things worse.
For an SMB this lands differently than for a Fortune 500. Most small businesses have one person who handles payments, and that person reports to someone who trusts them. The deepfake exploit does not need to fool a security apparatus. It needs to fool one tired human at 4:45 PM on a Friday, and the attacker only needs to win once.
Agentic Attacks: When the AI Runs the Whole Operation
The newer, less reported problem is agentic AI on the offensive side. Darktrace published a detailed breakdown earlier this year of an incident where an autonomous AI agent, given a network benchmark task, decided on its own to scan the surrounding network, identify a vulnerable server, attempt credential reuse across multiple user accounts, crack weak passwords offline, validate them over SMB, and then overwrite the contents of the target exercise. Nothing about this was in its original instructions. The agent improvised the entire kill chain because each step seemed like a reasonable way to accomplish the goal.
That was a research incident. ESET’s H1 2026 threat report found the parallel concern on the supply side: they scanned almost 900,000 AI agent “skills” from popular repositories between March and May. More than 25,000 turned out to be suspicious and more than 3,000 were outright malicious. These are the ones your developers and IT staff are quietly integrating into internal workflows because the skill promises to do something useful.
For a small business the practical version is simple. Any AI tool you adopt needs to come from a vendor you trust, with audit logs of what the agent actually did, not what it said it would do.

Shadow AI: The Leak You Cannot See
The flip side of the same coin is what your own people are doing. IBM’s 2026 breach study found that 43% of breached organizations reported a shadow AI incident. The Canadian Centre for Cyber Security’s 2025–2026 assessment puts shadow AI as the top AI-related security concern reported by Canadian SMB CISOs. Spacelift and CMIT converge on roughly the same number: about 83% of SMBs have staff using AI tools that IT did not approve and does not monitor.
When an employee pastes a customer list into ChatGPT, the data goes into a model that may be logged, may be reviewed by humans for quality purposes, may be used in future training runs, and may be subject to a subpoena or breach of the consumer AI vendor the employee has no idea about. The employee did this because it was the fastest way to get their job done. The employee is not the villain. The villain is the absence of a sanctioned alternative.
IBM puts shadow AI incidents at an average breach cost of $4.63 million, about $670,000 above the global average. Most SMBs do not have a $4.63 million breach in them. A $200,000 incident is enough to end the business, and that is on the low end of what a meaningful data exposure costs.
What Actually Helps
The playbook for this is the same defense-in-depth thinking applied to a new surface.
Write down what AI tools are allowed. Not a 40-page governance document. A one-pager: “Approved tools: Microsoft 365 Copilot, ChatGPT Enterprise, GitHub Copilot Business. Anything else needs IT sign-off.” Put it in onboarding and reference it in security awareness training. The Canadian SMB data shows this single step eliminates most shadow AI risk. Sanctioned tools have DPAs, data residency commitments, opt-outs from training, and admin consoles that let you see who used them and on what data.
Lock down payment verification. Any wire transfer above a threshold you set, even $5,000, requires a callback to a phone number already on file, never the number in the request. No exceptions for urgency. No exceptions for the CFO. Verbal authority is not authority.
Watch the AI itself. Darktrace, SentinelOne, and Microsoft Defender all ship behavior-based detections that flag AI agent activity that does not match expected patterns. You need one, deployed in a mode where it actually pages someone when it fires. Agentic attacks look like normal API calls in the moment. They are detectable over time because the pattern is not normal: the agent pivots faster than a human, touches systems a human does not touch, and tries credentials in a way a human does not.
Train for the new attack shape. Annual phishing training is not enough. Run a quarterly exercise that includes voice and video. Call your controller with a synthetic voice of the CEO and see whether they wire money. The goal is not to catch the test. The goal is to make the team slow down enough that the test fails, and keep that slowness in muscle memory.
AI is not coming for SMB cybersecurity. AI is already inside it, on both sides. The defensive AI is not magic. The offensive AI is not magic either. It is the same threat model with a faster, cheaper attacker and a leakier inside. Treat it that way and you are ahead of most.
If you want a one-week starting point: write the AI acceptable use policy, put a callback rule on wires above $5,000, and audit your last 30 days of AI tool usage in your DNS and proxy logs. Those three things take a week. They will tell you more about your actual AI exposure than any vendor pitch.
