Phishing has been a problem for businesses for years, but the way these attacks are being carried out is changing. The obvious phishing email with poor grammar, strange formatting, and a suspicious-looking link is becoming easier to recognize. The bigger concern now is that attackers can use artificial intelligence to create messages that sound natural, look professional, and are tailored to a specific person or business. For small and midsize businesses, this makes it increasingly difficult to rely on employees simply recognizing what a traditional phishing email looks like.
Artificial intelligence is giving cybercriminals new ways to automate and personalize attacks, allowing them to create convincing messages at a scale that would have required significantly more time and effort in the past. Microsoft's 2026 Digital Defense Report highlights the growing role of AI in cyberattacks and the continued importance of identity and human behavior in successful compromises. The report also describes how attackers are using AI to improve social engineering and impersonation campaigns.
For business owners, this does not mean that every email should be treated as a potential attack or that employees need to become cybersecurity experts. It means businesses need to rethink how they approach phishing. Employee awareness is still important, but it needs to be supported by strong authentication, email security, access controls, monitoring, backup systems, and clear procedures for handling unusual requests.
![]()
What makes AI-powered phishing different?
Traditional phishing attacks often depend on volume. An attacker sends thousands of generic messages and waits for someone to click a link or provide information. AI can make that process much more sophisticated because attackers can create messages that are more relevant to the person receiving them. A message can be written to match a particular company's communication style, reference the recipient's role, or create a sense of urgency around something that appears to be part of their normal responsibilities.
Consider an employee who works in accounting and receives an email that appears to come from a company executive. The message explains that the executive is in a meeting and needs an invoice paid immediately, perhaps even providing details that make the request seem legitimate. The language is professional, the request fits the employee's job, and there are no obvious spelling mistakes or strange phrases to raise suspicion. An employee who has been trained to look for poorly written emails may have no reason to immediately recognize the message as fraudulent.
This is one of the most important changes businesses need to understand. The absence of obvious mistakes does not mean that an email is legitimate. AI can help attackers produce polished messages, but the underlying goal remains the same: convince someone to take an action that benefits the attacker.
Phishing is no longer just an email problem
Although email remains one of the most common ways phishing attacks reach employees, businesses should not limit their security awareness efforts to the inbox. Employees communicate through Microsoft Teams, text messages, phone calls, collaboration platforms, and other business applications every day, and attackers are increasingly using those channels to impersonate trusted people.
Microsoft reported an increase in malicious activity involving Teams during the second quarter of 2026, including attacks in which criminals used social engineering and impersonation to persuade users to take actions that could compromise their accounts or devices. This matters because employees often have a different level of suspicion when a message arrives through a platform they use internally every day. A person may hesitate before opening a strange email but may be much more willing to respond to a message that appears to come from a coworker or someone claiming to be from the company's IT department.
The same concern applies to phone calls. An attacker who has gathered information about a business online may already know the employee's name, position, company, and even the software or services the company uses. A phone call claiming to be from technical support can therefore sound surprisingly convincing. Businesses that rely heavily on phone communications should consider security alongside reliability when evaluating their communication systems. A modern business phone system can give employees flexibility and better communication capabilities, but employees still need clear procedures for verifying unexpected requests that come through calls or messages.
Why urgency makes phishing more effective
One of the most effective techniques used in phishing is not necessarily sophisticated technology. It is pressure. Attackers understand that people are more likely to make mistakes when they believe something needs to be handled immediately.
An email might tell an employee that their Microsoft 365 account will be disabled unless they verify their password. A message from an executive might request an urgent payment because the executive is supposedly traveling or unavailable. A vendor might appear to be asking for updated banking information before the next payment is processed. In each case, the attacker is trying to create a situation where the employee focuses on completing the request instead of questioning whether the request itself is legitimate.
This is why employee training should go beyond teaching people how to identify suspicious links. Employees should understand which types of requests require additional verification. Any unexpected request involving money, passwords, sensitive information, remote access, or changes to financial details deserves a second layer of verification, particularly when the request is presented as urgent.
For example, if an employee receives an email requesting that a vendor's bank account be changed, replying to the same email is not a reliable way to verify the request. The employee should contact the vendor through a previously established phone number or another trusted communication channel. The same principle applies when an executive requests a large payment or when someone claiming to be IT support asks an employee to install software or provide access to a computer.
These procedures do not have to be complicated. In fact, the simpler they are, the more likely employees are to follow them consistently.
Employee training is important, but it cannot carry the entire burden
It is common for businesses to respond to phishing by scheduling security awareness training and reminding employees not to click suspicious links. While education is an important part of cybersecurity, it should not be treated as the primary defense.
Employees are human, and even experienced employees can make mistakes. Someone may be distracted, working under pressure, or dealing with an unusually convincing message. An employee who has successfully identified dozens of phishing emails may still click the wrong link one day. A good security strategy assumes that mistakes will happen and puts additional controls in place to reduce the potential damage.
Multifactor authentication is one of those controls. If an attacker obtains an employee's password through phishing, having an additional authentication requirement can make it considerably more difficult for the attacker to access the account. Microsoft's 2026 security research continues to emphasize stronger identity protection, phishing-resistant authentication, passkeys, and better control over privileged accounts as important defenses against identity-based attacks.
Businesses should also review who has access to important systems and information. Employees should have the access they need to perform their jobs, but unnecessary administrative privileges can increase the potential impact of a compromised account. Former employees and inactive accounts should also be removed promptly rather than being left available indefinitely.
For businesses that depend heavily on Microsoft 365, cloud applications, remote access, and shared business systems, identity security should be considered an important part of the overall managed IT services strategy.
Your email security should be working before an employee sees the message
Another important part of the equation is making sure employees are not expected to identify every dangerous message on their own. Email security systems can analyze messages, attachments, links, sender information, and other characteristics to identify suspicious activity before it reaches an employee's inbox.
This becomes particularly important as phishing messages become more polished. If a business relies exclusively on an employee noticing something suspicious, the final decision is being made at the point where the attacker wants it to be made. The better approach is to have security controls working in the background and filtering as much malicious activity as possible before it reaches employees.
Employees should still have a simple way to report suspicious messages when something does get through. Reporting should be encouraged rather than treated as an admission that someone made a mistake. If an employee reports a suspicious email that turns out to be legitimate, that should be considered part of a healthy security culture. The objective is to make it easier for employees to ask questions before an incident becomes a larger problem.
What happens if a phishing attack succeeds?
Even with strong security controls, businesses need to prepare for the possibility that an attacker will eventually get through. A compromised password can provide access to email, cloud applications, files, and other business resources. Depending on what the attacker gains access to, the incident can lead to financial fraud, data theft, account compromise, or a much larger cybersecurity event.
This is where backup and disaster recovery become particularly important. A backup is not simply a copy of your files sitting somewhere else. Businesses need to know what is being backed up, how frequently backups are performed, how those backups are protected, and whether the company can actually recover the information when it needs it.
A recovery plan should also account for the possibility that the systems themselves may be compromised. If an attacker gains administrative access, simply restoring from an accessible backup may not be enough. Businesses need to think about how they would isolate the incident, secure their accounts, restore critical systems, and return to normal operations.
Your data backup and recovery strategy should therefore be part of your broader cybersecurity planning rather than something considered separately from security.
What should a small business do now?
The first step is to look at how your employees currently access company accounts and determine whether multifactor authentication is enabled wherever it should be. Businesses should also review administrator accounts, remove unnecessary access, and make sure former employees no longer have access to company systems. If your organization uses Microsoft 365 or other cloud platforms extensively, reviewing account security and authentication settings should be part of that process.
The next step is to review how your business handles unusual requests. Employees should know what to do when someone asks for a password, requests a payment, changes banking information, asks for sensitive documents, or wants remote access to a computer. Having a simple verification process in place can prevent an employee from having to make a difficult decision on their own.
Businesses should also review their email security and make sure employees have a straightforward way to report suspicious messages. Security tools should be configured to reduce the number of malicious messages that reach employees, while employees should understand that reporting something suspicious is encouraged.
Finally, take a close look at your backups and recovery procedures. Ask when the last recovery test was performed and whether your business could continue operating if an important system or set of files became unavailable. A backup that has never been tested may provide less confidence than a business owner realizes.
AI is changing phishing, but the fundamentals of security still matter
Artificial intelligence is making phishing more convincing and giving attackers new ways to personalize and automate their campaigns, but the basic objective has not changed. Attackers still want someone to trust a message, click a link, reveal information, approve a request, transfer money, or provide access to a system.
The response should therefore not be to expect employees to identify every AI-generated scam perfectly. Instead, businesses should create several layers of protection so that one mistake does not automatically become a serious incident.
Strong authentication can make stolen passwords less useful. Email security can stop dangerous messages before they reach employees. Access controls can limit what a compromised account can reach. Employee training can help people recognize unusual requests and know when to stop and verify. Monitoring can help identify suspicious activity, while reliable backups can give a business a way to recover if an incident causes damage.
For small businesses, cybersecurity does not have to mean implementing every security technology available. It means understanding where your business is most exposed and putting sensible protections around the systems, accounts, data, and people that keep the business operating.
AI may be changing the way phishing attacks are created, but businesses can still take many of the same practical steps to reduce their risk. The most important thing is to start before an employee receives the message that someone in the company wishes they had recognized sooner.

