October is Cybersecurity Awareness Month, and this year the biggest risk to small businesses isn’t a clumsy, typo-filled email. It’s AI. Scammers now use artificial intelligence to clone voices, fake video calls and write messages that sound exactly like your boss, your bank or your IT provider.
Whether you run a manufacturer in Cedar Rapids, a dental office in Des Moines or a contractor in Dallas-Fort Worth, the playbook is the same. Attackers don’t need to break your firewall when they can trick one employee into clicking, approving or paying. Here are the four AI phishing and deepfake scams hitting Iowa and Texas small businesses hardest in 2026, and how to stop them.
1. Deepfake Voice and Video Calls
Your bookkeeper gets a call from the owner: a vendor needs an urgent wire before end of day. The voice is right, the tone is right, even the little verbal habits are right. But it isn’t the owner. It’s an AI voice clone built from a few seconds of audio pulled from a podcast, a Facebook video or a voicemail greeting.
Video is next. In one widely reported 2024 case, engineering firm Arup lost roughly $25 million after an employee joined a video call where the “CFO” and other colleagues were all deepfakes. Small businesses are an easier target because one person often handles payments with no second check.
How to stop it: Make it a written rule that no call or video meeting is ever enough to approve a payment or change bank details. Verify through a separate channel, like a phone number from your own records. Some businesses also set a family-style “safe word” for money requests.
2. QR Code Phishing (“Quishing”)
QR codes are everywhere: restaurant menus, parking meters, shipping labels, meeting invites. Scammers know employees scan them without a second thought.
A quishing email might say your Microsoft 365 password expires today and ask you to scan a code to keep access. Because the link is hidden inside an image, many email filters miss it. And because the employee scans it on a personal phone, the visit skips the security tools on your company network. The code leads to a fake login page that steals passwords and even one-time MFA codes. Fake QR stickers have also turned up on parking pay stations in Texas cities, including Austin.
How to stop it: Treat an unexpected QR code like an unexpected link. If a message asks you to scan to log in, go to the site directly instead. Check the web address before entering anything.
3. MFA Attacks
Multi-factor authentication (MFA) is one of the best protections you can have, so attackers have learned to wear people down instead of breaking it. Once they steal a password, they trigger login approval after login approval on the employee’s phone, often late at night. Eventually someone taps “Approve” just to make it stop. Sometimes a follow-up call or text from “IT” asks them to accept the prompt.
One tap gives the attacker full access to email, files and financial systems.
How to stop it: Teach staff that a login prompt they didn’t start means someone has their password, so deny it and report it right away. On the technical side, switch to number matching or phishing-resistant MFA such as passkeys or hardware security keys. Real IT staff will never ask you to approve a prompt or share a code.
4. Social Engineering on Slack and Microsoft Teams
As email filters improve, scammers are moving into the chat apps your team trusts. A Teams message from “IT Help Desk” asks an employee to install a remote support tool. A Slack DM that looks like it’s from a manager asks for a quick gift card purchase or a copy of the payroll file.
Chat feels internal and casual, so people let their guard down. Microsoft Teams also allows messages from outside organizations by default in many setups, which gives attackers an easy way in. AI helps them match your company’s tone and names.
How to stop it: Apply the same rules to chat that you apply to email. Any request for passwords, payments, files or software installs gets verified through a separate channel. Ask your IT provider to restrict external Teams and Slack messages to approved partners.
Your Best Defense: A Trained Team
Notice what all four scams have in common. None of them works unless a person clicks, scans, approves or pays. That makes your employees either your biggest risk or your strongest defense, and the difference is training.
The once-a-year compliance video isn’t enough anymore. AI scams change too fast. Your team needs short, practical training built around the attacks they’ll actually see, plus simple rules like “verify every money request through a second channel.”
That’s why Saltech is offering free cybersecurity training for Iowa and Texas small businesses this Cybersecurity Awareness Month. We’ll show your team how to spot deepfake calls, fake QR codes, MFA fatigue tricks and chat-based scams before they cost you money. If you need more than training, our Cybersecurity Services can help lock down the systems behind your people.
Claim your free cybersecurity training today
Frequently Asked Questions
1. What is AI phishing?
AI phishing uses artificial intelligence to write scam emails, texts and chat messages that are personalized and error-free. Without the usual typos and odd phrasing, these messages are much harder for employees to spot.
2. How do deepfake scams target small businesses?
Scammers clone the voice or face of an owner, manager or vendor, then call or video-chat an employee to request a wire transfer, gift cards or a change to bank details. Small businesses are targeted because payments often go through one person with no second approval.
3. How can I tell if a call is a deepfake?
Often you can’t, which is why you shouldn’t rely on your ears or eyes. Watch for urgency, secrecy and unusual payment requests. Then hang up and call the person back on a number you already have on file.
4. Is MFA still worth using if attackers can get around it?
Yes. MFA still blocks the large majority of account takeover attempts. The fix for MFA fatigue is stronger MFA, like number matching or passkeys, plus training staff to deny and report prompts they didn’t start.
5. Is Saltech’s cybersecurity training really free?
Yes. Saltech offers free cybersecurity awareness training to help Iowa and Texas small businesses protect their teams from AI-powered scams. Sign up here to get started.

