
The email looks like it came from your boss. The caller sounds exactly like your son. The text from a vendor refers to an invoice you recognize. Everything feels legitimate, except the person on the other end may not be who you think they are.
Artificial intelligence is giving scammers better tools to imitate people, write convincing messages, and create realistic audio, images, and video. According to the FBI’s 2025 Internet Crime Report, more than 22,000 complaints involved AI, with reported losses approaching $893 million. The FBI has specifically warned that AI can be used in business email compromise, voice-cloning schemes, fake online identities, and other forms of fraud targeting both individuals and businesses.
During Cybersecurity Awareness Month, it is a good time to look at how these scams are changing and what you can do before a convincing message leads to a costly decision.
How are scammers using AI to impersonate people?
Many of today’s scams are updated versions of schemes that have been around for years. What AI changes is how believable they can be.
For individuals, a scammer may clone the voice of a child, grandchild, spouse, or friend and claim there has been an accident, arrest, medical emergency, or other crisis requiring money immediately. The Federal Trade Commission warns that scammers can create a convincing voice clone from a relatively short audio sample, including audio that may be available online.
Businesses face a similar problem. An employee may receive what appears to be an email, text, or call from an executive asking for an urgent wire transfer, a change to payment instructions, or the purchase of gift cards. A request that once might have contained awkward wording or obvious warning signs can now be polished, personalized, and consistent with how someone normally communicates. The FBI notes that AI-generated messages and voice cloning can be used to support business email compromise schemes.
How can you tell if a payment request is fake?
As scams become more convincing, appearance alone is becoming a less reliable test. A familiar voice, professional-looking email, or correct company logo does not prove a request is legitimate.
Pay particular attention when someone:
● creates a strong sense of urgency or asks you to act before you have time to think
● requests payment by wire transfer, cryptocurrency, gift card, or another difficult-to-reverse method
● asks you to keep the request confidential
● unexpectedly changes banking or payment instructions
● asks for passwords, verification codes, account information, or other sensitive data; or
● tells you not to contact the person or company through your usual channels
The safest response is often simple: verify the request another way. Call the family member using a number you already have. Contact the vendor using established contact information. Walk down the hall and ask your supervisor. Do not rely on a phone number, email address, or link provided in the suspicious message itself. That independent verification step is one of the most effective ways to interrupt a social engineering scam.
What can individuals do to reduce their cyber risk?
Good digital habits still matter, even as scams become more sophisticated.
Use strong, unique passwords, turn on multi-factor authentication when it is available, keep devices and software updated, and be cautious about unexpected links or attachments. Think about how much personal information you share publicly, too. Names of family members, travel plans, workplaces, birthdays, and videos containing someone’s voice can all give a scammer more material to work with.
Families may also want to agree on a simple way to verify an unexpected emergency request. A private family question or code word can provide one more layer of protection when a call sounds frighteningly real.
Most importantly, resist pressure to act immediately. Scammers benefit when fear, excitement, or urgency keeps you from checking the story first.
What should businesses do before transferring money?
Technology is only one part of business cybersecurity. Procedures matter just as much.
Businesses should establish clear verification requirements for wire transfers, changes to vendor banking information, unusual purchases, and other financial requests. Employees who handle payments should know they have permission to slow down an urgent request and verify it independently, even when the request appears to come from an owner, executive, or important customer.
Employee training also deserves regular attention. Cyber risk is not limited to the IT department. Anyone who uses email, handles customer information, approves payments, or has access to company systems can become a target.
Other important safeguards include limiting access to sensitive systems, using multi-factor authentication, maintaining reliable backups, installing security updates promptly, and removing system access when employees leave the organization.
Can insurance help if a personal cyber incident occurs?
Prevention is important, but no security practice eliminates every risk.
Personal cyber protection may be available to help with certain losses associated with online fraud, computer attacks, cyber extortion, compromised personal data, and attacks on connected devices. Depending on the policy and coverage selected, protection may help with direct financial losses, restoring systems or data, professional assistance after a cyber incident, or services needed when private information has been compromised.
Because coverage varies by insurer, policy, state, limits, and the circumstances of a loss, it is worth asking your insurance agent what protection you currently have rather than assuming a cyber-related loss is covered.
What can business cyber insurance cover?
Businesses can face a different set of expenses after a cyber incident. A data breach, ransomware attack, compromised payment request, or system outage may create costs well beyond the money initially lost.
Depending on the coverage purchased, commercial cyber insurance may provide protection for expenses such as breach response, forensic investigation, data and system restoration, cyber extortion, loss of business income, certain liability claims, regulatory matters, and other costs associated with responding to an attack.
The right coverage depends on how a business operates, what information it stores, how dependent it is on technology, and where its greatest exposures lie. Learn more about Cyber Liability Insurance from Wichert Insurance, or talk with your Wichert agent about coverage options that may fit your business.
Is your cyber protection keeping up with the scams?
AI will continue to change how cybercrime looks, but one of the best defenses remains surprisingly human: question unusual requests, verify before acting, and make it easy for employees and family members to speak up when something feels wrong.
It is also worth reviewing the financial protection behind those precautions.
Wichert Insurance can help individuals and businesses review their current insurance programs, understand where cyber coverage may fit, and explore options based on their specific risks. Contact your Wichert agent to start the conversation.