AI can make fraudulent messages more convincing, but basic verification and access controls remain essential.
How AI changes impersonation
Attackers can produce polished emails and plausible voice or video content. Good grammar and a familiar voice are not proof that a request is genuine.
Protect payments and bank-detail changes
Use a trusted contact number already on file to confirm changes. Do not rely on a number, link or callback instruction contained in the suspicious message.
Strengthen account security
Use MFA or passkeys, separate administrative accounts and monitor unusual sign-in activity. Train employees to report unexpected authentication prompts.
Practise a realistic scenario
Run an exercise involving an urgent supplier payment request or a supposed director asking for confidential files. Focus on the verification process, not whether a message looks convincing.
Respond quickly
If money or credentials have been shared, contact the bank or IT response team promptly, preserve evidence and follow the incident plan.
Book cybersecurity and AI training
Learn these skills with Matthew Southgate in our combined full-day course. View and book upcoming training events, or register interest in the online training course.