For years, the easiest way to spot a scam was the writing. Broken English, weird spacing, a greeting like "Dear Valued Costumer." That tell is dead. Attackers now use AI to produce clean, professional, personalized messages in seconds, and they send them by the millions. The scam that used to be obvious now reads exactly like a note from your bank, your supplier, or your own bookkeeper.

If your rule for spotting scams was "look for the typos," you need a new rule. Here is what changed, the scams pointed at your business, and the habits that still stop them cold even now that the messages look perfect.

You can no longer trust a message because it looks professional. Looking professional is now free. What you can still trust is how you verify it.
0
typos left to tip you off, AI writes clean copy
Seconds
for AI to craft a convincing, personalized scam
1
second-channel check that stops almost all of them

What Changed: AI Removed the Tells

Phishing is not new. What is new is how good and how cheap it has become. The same AI tools that help you write a proposal help an attacker write a flawless scam, and they change the game in four ways.

1

Perfect writing, every time

Grammar, tone, and formatting are now flawless. The clumsy mistakes that used to trigger your gut are gone, so a scam email can read exactly like a real one from a company you trust.

2

Personalized at scale

AI can pull details from your website, social profiles, and public records to reference your real projects, your city, even a recent job, then do it for thousands of targets at once. A scam that mentions your actual work feels legitimate.

3

Convincing brand impersonation

Attackers can closely mimic the look and language of Google, Microsoft, your bank, or your software vendors. "Your account will be suspended" emails now match the real thing closely enough to fool a quick glance.

4

More channels, more speed

It is not just email anymore. The same polished scam arrives by text, chat, and social message, often in a coordinated sequence, so it feels like a real back-and-forth rather than a single suspicious note.

The Scams Aimed at Your Business

These are the ones actually hitting local and home service businesses right now. Recognize the shapes and you are halfway to safe.

The fake invoice or vendor change. A supplier you use emails a new invoice, or asks you to update their bank details for the next payment. The email looks right, the tone matches. This is business email compromise, and it is the most expensive scam on this list because it ends with you wiring real money to a stranger.

The account suspension notice. A polished email or text says your Google, Microsoft, or payment account has a problem and you must log in to fix it. The link goes to a fake login page built to steal your password. This is a cousin of the Google Business Profile suspension scam we covered separately.

The boss or employee request. A message that looks like it is from you, or a team member, asks for a quick favor: buy gift cards, move a payment, share a document. It leans on authority and urgency so nobody stops to check.

The malicious attachment. A message poses as a customer with an estimate request or a photo of a job, but the attachment or link carries malware. This overlaps with the web-based threats in our guide to protecting your site from malware.

The New Red Flags (Since Typos Are Gone)

Stop grading the spelling. Start reading the behavior of the message. These are the signals that still give a scam away no matter how clean the writing is.

Watch the Behavior, Not the Grammar

  • ⚠️ Urgency or a threat: act now, or your account, payment, or listing is at risk.
  • ⚠️ Any request for money, a payment, login details, or a verification code.
  • ⚠️ A change to bank details, wiring instructions, or where a payment should go.
  • ⚠️ A sender address that is slightly off, or a reply-to that does not match.
  • ⚠️ Links whose real destination does not match the text you see.
  • ⚠️ Pressure to keep it secret, or to move the conversation to another app.
  • ⚠️ An unexpected request, even if it looks like it came from someone you know.

How to Protect Your Team

You cannot out-read a machine that writes perfectly. You beat this with habits and systems, not with a sharper eye for typos.

1

Verify money and logins on a second channel

Any request involving payment, bank details, or credentials gets confirmed by voice on a number you already have, not the one in the message. This single habit stops nearly every version of this scam.

2

Turn on two-factor authentication everywhere

Even if someone steals a password, two-factor stops them from getting in. Put it on email, banking, Google, Microsoft, and every account that matters. It is the same lock we stress in our website and account security guide.

3

Make "slow down on urgency" a team rule

Teach everyone that pressure to act fast is itself a warning sign. Nobody gets in trouble for pausing to verify a payment or a login request. Make that explicit so people feel safe checking.

4

Lock down your own domain

Set up email authentication, the SPF, DKIM, and DMARC records, so scammers cannot easily send email that appears to come from your business. This protects both your team and your customers from impersonation.

5

Report it, then delete it

Use your email tool's report or phishing button so future copies get filtered, then delete the message. If someone did click or reply, change that password immediately and turn on two-factor.

When the Scam Wears Your Name

Here is the angle most owners miss: attackers do not only target you, they impersonate you to target your customers. A scammer can send fake invoices, appointment confirmations, or review requests that appear to come from your business, and your customer pays the price while your name takes the hit.

Two things reduce that risk. First, lock down your accounts and your domain so it is harder to convincingly fake you. Second, tell your customers plainly how you will and will not contact them, for example that you will never text a link asking them to pay an invoice. Clear expectations make a fake obvious.

💬

Give your customers a simple rule too: if a message that looks like it is from us pressures you to pay or log in through a link, stop and call our real number first. A little friction on their end shuts the scam down.

The One Rule That Still Works

You do not need to detect every clever fake. You need one reflex that makes the cleverness irrelevant.

Urgency plus money or credentials equals stop and verify on a separate channel you chose. That one rule survives every upgrade the attackers make.

AI made the messages perfect. It did not change the goal, which is always to rush you into handing over money or access. Slow that moment down, confirm through a channel you control, and the most polished scam in the world falls apart. The writing got better. Your verification habit is what keeps you safe.

Your Phishing Defense Check

Run through this with your team this week. Every box you cannot check is an opening.

  • We confirm every payment or bank-change request by voice on a known number.
  • Two-factor authentication is on for email, banking, and key accounts.
  • The team knows urgency is a warning sign, and pausing to verify is encouraged.
  • Our domain has SPF, DKIM, and DMARC set up.
  • Our customers know how we will and will not contact them.

Want a second set of eyes on your accounts and setup? Get a free audit →