AI didn't just make phishing emails easier to write. It made them good enough that the FBI's annual fraud report had to give AI-enabled fraud its own section for the first time. Most business owners sense that something changed. Far fewer have done anything about it.

This one isn't about adopting AI in your business. It's about other people using it against your business, whether or not you ever open a tool yourself.

Four sources, four pieces of the picture

The numbers here come from four separate places, each covering a different part of the problem. None of them breaks out construction, manufacturing or trades specifically. Two are government fraud trackers with no commercial stake. Two are companies with a clear interest in the topic looking serious, and I'll flag that where it applies.

A category that didn't exist before this year

The IC3 has tracked online fraud complaints for nearly 25 years. Its latest annual report, announced by the FBI in April, added something new: a dedicated section for fraud involving artificial intelligence.

In its first year of being counted that way, AI-related fraud accounted for 22,364 complaints and nearly $893 million in reported losses. That's out of 1,008,597 total complaints and about $20.9 billion in total reported losses to online fraud in 2025.

The FBI didn't add that section because AI fraud might become a problem someday. It added it because the losses were already large enough to need their own line in a federal report.

The invoice that reads right

I spent 18 years in construction before this work, and the oldest scam in the business is still the same one: an email that claims to be from a supplier, asking you to send the next payment to a new account.

That scam has a formal name and a dollar figure. Business email compromise, or BEC, cost U.S. victims $3,046,598,558 in 2025, according to the IC3 report. That makes it the second-costliest fraud category the FBI tracks, behind investment fraud.

Most of that BEC total has nothing to do with AI. It's the same impersonation scam that's been running for years. But the report also logged, for the first time, BEC losses involving AI: more than $30 million in 2025. The FBI notes that AI is being used to make these emails more convincing, and that voice cloning is being used to request wire payments, while also noting that not all BEC tactics are AI-enabled.

That $30 million is a small slice of the total, and it's worth keeping in proportion. It's also the first year anyone counted it, which means it's a floor, not a ceiling.

Why construction is exposed

Trades and construction businesses fit the BEC pattern almost perfectly. Payments are large and frequent. Supplier and subcontractor relationships run mostly over email. Banking details change legitimately from time to time. And the person approving payment is often busy on a site and checking email from a phone. None of that is a failing. It's how the industry works, and it's exactly what this scam is built to exploit.

What the new version looks like

Picture a mid-sized framing contractor with a regular lumber supplier. The office manager gets an email from what looks like the supplier's accounts receivable contact. The name is right. The signature block matches the last twenty invoices. The tone is the same slightly hurried, friendly tone that contact always uses. It mentions the actual job the last load went to, because that detail was easy to find on the contractor's own social media. It says the supplier has switched banks and asks that this month's payment go to the new account, with an updated void cheque attached.

Nothing in that email has a spelling mistake. Nothing about it feels off. The old warning signs simply aren't there, and that's the point. AI tools make it cheap to produce a message that matches a real person's writing style and drops in plausible details, at scale, for many targets at once.

The only reliable defence in that scenario isn't spotting the fake. It's a rule that banking changes never get accepted by email alone, no matter how real the email looks.

How fast the fake got good

The old advice for spotting a scam email was to look for bad grammar, odd phrasing and a generic greeting. That advice is running out of road.

Hoxhunt reported that in November 2025, about 4% of the phishing emails flagged across its threat-detection network showed clear signs of being AI-generated. In December, that figure was 56%. By January 2026 it had settled around 40%, still roughly ten times where it started two months earlier. Hoxhunt says the network covers more than 4 million users and over 50 million phishing simulations and real attacks across 125 countries.

It's worth being clear about the source. Hoxhunt sells phishing-awareness training, so it has a reason to want these numbers to look alarming. The underlying shift still holds up against the FBI data, which carries no such interest: the badly written scam email is becoming the exception.

Training people to watch for bad grammar stops working once the email is written to sound exactly like the person it claims to be from.

Worried isn't a plan

Business owners aren't oblivious to this. Gallagher's 2026 Business Owners Survey, conducted by Wakefield Research among 1,000 U.S. business owners between January 29 and February 10, 2026, found that 68% are worried cyberattacks will affect their business. Eighty-nine percent are at least somewhat concerned about AI's impact on their business more broadly.

Here's where the concern runs out. Only 44% said they want to acquire or expand insurance coverage for cyberattacks. A large share of the owners who are worried haven't acted on it, at least not through insurance.

Two notes on that survey. Gallagher is an insurance brokerage, so it has a direct interest in more businesses buying cyber coverage. And the sample spans everything from very small firms to companies with more than a thousand employees, so it's a broad U.S. business-owner sample, not a small-business or trades-specific one.

Being concerned about a risk and being covered for it are two different line items. Insurance is only one kind of coverage, and arguably not the most important one. A payment-verification habit that every person in the office actually follows does more to stop a fake invoice than any policy does after the money's gone.

The phone call isn't automatically safe either

The standard advice for years has been to call and confirm before changing payment details. That advice still holds, with one adjustment. The FBI report specifically notes that voice cloning is being used to request wire payments. A phone call to a number supplied in the suspicious email, or a call that comes in from someone who sounds exactly like your supplier or your own boss, doesn't prove much anymore.

The check that still works is one you start, to a number you already had on file before the request arrived. It's a small habit. It takes two minutes. And it's the kind of control that's easy to agree with in a meeting and easy to skip on a Friday afternoon when a payment run is late and everyone wants to go home.

That's why the gap between worrying about fraud and being protected against it is usually a process gap, not a technology gap. The control only works if it's written down, everyone who handles money knows it, and nobody gets to skip it because they're senior or in a hurry.

It isn't only an American problem

Canadians reported more than $704 million in fraud losses to the Canadian Anti-Fraud Centre in 2025, according to the CAFC figures cited in that March release, which was issued by the identity-verification company Facephi and headlined the total as a record.

That number only counts what got reported. The CAFC's own estimate is that reported fraud represents just 5 to 10% of actual incidents, which suggests the real figure is several times higher.

None of the Canadian data breaks out how much of that started with an AI-written email or a cloned voice. I won't pretend it does. But the pattern underneath the U.S. numbers, a scam that used to take real effort now taking very little, isn't something that stops at the border.

Why the reported numbers understate it

The CAFC's reporting estimate is worth dwelling on, because it applies to businesses as much as individuals. A business that wires money to a fake supplier account often has reasons not to report it: embarrassment, a hope that the bank will recover the funds quietly, or a sense that reporting won't change anything. The loss gets absorbed as a bad month and the story stays inside the company.

That's understandable, and it also means the industry doesn't learn from it. Owners in the trades rarely hear about these losses from peers, so the risk feels more distant than it is. When the official figures are only counting a fraction of incidents, the absence of stories from people you know isn't evidence that the scam isn't reaching your industry.

What changes for a small business

The practical takeaway isn't to panic or to buy a security product. It's to recognize that the controls many small businesses rely on were designed for a world where fake emails looked fake.

A few questions worth asking about your own operation:

If the honest answer to any of those is "it depends who's in the office that day," that's the exposure. It has nothing to do with whether you use AI yourself. The people writing the emails already do.

For more on how AI use inside a business should be bounded and supervised, the governance page covers the approach I take.

Finding out where that kind of exposure actually sits in your business is part of the AI Discovery and Readiness Assessment. It's a paid engagement, not a general chat about AI: a discovery call and a structured review of your workflows, systems and data access, ending in a written report.

Review the assessment details →