- The threat: AI-generated phishing and business email compromise (BEC) now regularly cause seven-figure losses at small and midsize businesses.
- The pattern: Attackers infiltrate, wait for a large transaction, then intercept the invoice or wire.
- The fix: MFA everywhere, real email security, employee training, monitored endpoint detection, offline backups, incident response plan.
Twenty years ago the phishing email was a Nigerian Prince offering you millions. It required almost no skill to write. It required almost no skill to spot. The success rate was low, so the volume was high — spray and pray.
That's over.
On the Operator Mindset episode with Michael Hornby, founder of the IT and cybersecurity firm Techmentum, Michael broke down how 20 years on the front line of small business security has changed. His summary in one sentence:
"Their low-hanging fruit is no longer there because businesses are getting smarter about their security. So the hackers have to get smarter as well."
Which they did. And the tool that upgraded them is AI.
What "getting smarter" looks like in 2026
The Nigerian Prince email of 2005 has been replaced by AI-generated messages that are:
- Written in perfect corporate English.
- Personalized to the recipient's name, role, and recent activity (scraped from LinkedIn and other public sources).
- Contextually accurate — referencing real projects, real vendors, real invoice cycles.
- Sent from spoofed addresses that pass basic email authentication checks.
- Often part of a multi-step conversation, not a single-shot email.
The result is that the traditional filter — "does this feel weird?" — no longer works reliably. And the businesses that were "too small to target" 10 years ago are inside the target profile now, because automation makes small-business attacks profitable at scale.
The attack that's costing seven figures: business email compromise
Michael was blunt about which specific attack pattern is doing the most damage:
"Business email compromise, where a threat actor gets into an environment, they tend to sit in there and watch and study for as long as they can until they find that point where they think it's the right time to attack. That tends to be when there's a big transaction going on — a big invoice being sent around, if it's real estate, a purchase or a sale going on. They try and intercept, and frankly, unfortunately, they tend to be very, very successful."
Break that down. The threat actor doesn't blast the business immediately. They:
- Compromise a mailbox — often via a stolen password, a phishing capture, or a token replay.
- Set up quiet forwarding rules so incoming emails to that mailbox also copy to them.
- Wait weeks or months, reading everything, learning invoice cycles, vendor names, common signatures.
- Intercept the big one. When a real invoice for a large sum comes in — or is about to go out — they intercept it, swap the bank account details, and let the actual recipient believe everything is normal.
- Wire goes to the wrong account. By the time anyone notices, funds have been laundered through multiple accounts and are unrecoverable.
Seven-figure losses from a single incident are not rare. They're the pattern.
The security stack every small business needs (per Techmentum)
Michael's playbook for a midsize business isn't exotic. It's discipline applied to layers most companies half-implement:
1. Multi-factor authentication (MFA) on every account.
Not just email. Every SaaS. Every bank. Every admin console. MFA blocks the vast majority of credential-stuffing and stolen-password attacks that lead to mailbox compromise.
2. Email security beyond default filters.
Microsoft 365 and Google Workspace default spam filters are a floor, not a ceiling. Layered email security tools that inspect for AI-generated patterns, spoofed senders, and anomalous forwarding rules are now standard.
3. Endpoint detection and response (EDR) with monitoring.
Antivirus alone is not enough. A managed EDR with 24/7 human monitoring catches lateral movement — the phase after initial compromise where attackers spread through the network.
4. Regular phishing training and simulation.
Employees are the last line. Quarterly phishing simulations and short training modules move recognition rates significantly. This is one of the cheapest, highest-ROI security investments.
5. Offline backups.
Ransomware often deletes accessible backups before triggering encryption. Backups that are physically offline or in a separated environment survive.
6. Written incident response plan.
When the incident happens, you have hours, not days, to respond. A pre-written plan with contact numbers, containment steps, and communication templates is the difference between managed damage and catastrophe.
The economics
A properly-structured security stack for a small-to-midsize business typically runs $100 to $500 per employee per month, depending on compliance requirements and industry.
For a 30-person business, that's $3,000 to $15,000 per month. For a 100-person business, $10,000 to $50,000.
Compared to a single seven-figure BEC loss? The math is straightforward. And that's before you factor in the reputational hit, insurance premium increases, and customer trust erosion that follow a public incident.
What operators should do this week
Even if you're not ready for a full security overhaul, three moves you can make immediately:
- Turn on MFA everywhere it isn't already on. Free. Takes an hour. Blocks 99% of credential attacks.
- Audit your email forwarding rules. Both admin-level and user-level. Look for rules that forward to external addresses. Delete anything unfamiliar.
- Establish a callback protocol for large payments. Any invoice or wire above a threshold you set requires a phone call to a known number to verify. Not email. Phone. This alone stops the majority of BEC losses.
The bigger picture
The industries that are moving fastest on this — legal, financial services, healthcare — are being forced by regulation and insurance. Everyone else is being forced by the incident.
Michael's read: waiting for your first incident to happen is the most expensive strategy available. And with AI cutting attacker costs by orders of magnitude, the target profile keeps expanding downward.
If you run a business, cybersecurity is now a P&L line. Not an IT one.
- Meet Athena — How Howie's AI operator runs security-aware protocols in his own business.
- All Operator Mindset episodes — Founders, operators, and industry veterans on the decisions that matter.
- Techmentum — Michael Hornby's IT + cybersecurity firm.