Remember when spotting a scam email was easy? Bad grammar, a Nigerian prince, a link that screamed “don’t click me.” Those days are over. According to the FBI’s 2025 Internet Crime Report, Americans lost $20.9 billion to cybercrime last year — a 26% jump — and phishing was the single most reported crime of all, with over 191,000 complaints.
The scams got smarter. The channels multiplied. And AI joined the criminals’ payroll. By the end of this post, you’ll know exactly what modern phishing looks like — in your inbox, your texts, and even your phone calls — and the simple habits that stop it cold.
Phishing Isn’t What It Used to Be
Here’s the stat that should reframe how you think about this: while the number of phishing complaints barely moved year over year, the losses tripled — from $70 million to $215.8 million, per the FBI. Each individual attack is doing far more damage than it used to.
And that’s just the entry point. Phishing is usually step one of something bigger: business email compromise (BEC), where criminals impersonate an executive or vendor to trick someone into wiring money. BEC alone cost businesses $3.05 billion in 2025, averaging about $123,000 per incident. These emails often contain no links and no malware — just a convincing request from someone who appears to be your boss. Nothing for a spam filter to catch. Everything for a busy employee to fall for.
The kicker: Mimecast’s analysis of the FBI data found that nearly 85 cents of every dollar lost came from fraud where a person received something convincing and acted on it. Not malware. Not elite hacking. A human being made a decision they shouldn’t have. Which means the fix isn’t just more software — it’s sharper humans.
The AI Problem: Why “Look for Typos” Is Dead Advice
For the first time in its 25-year history, the FBI’s 2025 report included a dedicated AI section: 22,364 AI-related complaints and $893 million in losses — and the FBI itself flags those numbers as undercounts, because most victims never realize AI was involved.
IBM’s 2025 Cost of a Data Breach Report backs this up: 1 in 6 breaches now involves attackers using AI, mostly for phishing and deepfake impersonation. Chat generators produce flawless, personalized emails in seconds. Voice cloning tools can mimic your CEO from a 30-second clip pulled off a webinar. The Verizon DBIR team even joked this year that their phishing detection advice has shifted from “does it contain many typos” to “does it contain em dashes.”
Translation: you can no longer spot a scam by how it’s written. You have to spot it by what it’s asking.
It’s Not Just Email Anymore: Texts and Phone Calls
As people got better at side-eyeing suspicious emails, criminals simply changed channels. The 2026 Verizon Data Breach Investigations Report found that phishing via text messages and voice calls now succeeds at a rate 40% higher than traditional email phishing. We’ve gotten savvy about our inboxes and stayed trusting of our phones. Attackers noticed.
The greatest hits of mobile phishing:
- The fake delivery text. “Your package couldn’t be delivered — click here to reschedule.” You weren’t expecting a package. Doesn’t matter; the click is reflexive.
- The boss text. “It’s [CEO name]. I’m in a meeting and need you to buy gift cards for a client. Keep this between us.” Real CEOs do not do this. Ever.
- The bank fraud call. A caller “from your bank’s fraud department” needs you to verify your account — by reading them your login code. That code is the attacker logging in as you, right now.
- The voicemail deepfake. A cloned voice of a colleague or executive with an urgent payment request. If money is involved, verify on a channel you initiated.
The Red Flags That Still Work
Polish can be faked. Pressure can’t be hidden. Whatever the channel, modern phishing almost always leans on one of these:
- Urgency and secrecy. “Right now.” “Before end of day.” “Don’t tell anyone.” Legitimate business rarely requires panic, and it never requires secrecy.
- A change to payment details. A vendor “switching banks” via email is the classic BEC setup. Always verify by phone using the number you already have on file — not the one in the email.
- A request for credentials or codes. No legitimate company will ever ask you to share a password or a one-time login code. That request is the attack.
- A channel switch. An email that pushes you to text, or a text that pushes you to WhatsApp, is moving you away from your company’s security tools. That’s deliberate.
- Something slightly off. A sender address one letter off. A greeting that’s too formal from a casual colleague. Trust the itch — verify before you act.
The Verification Habit That Beats Every Scam
Here’s the beautiful thing: one habit defeats email phishing, smishing, vishing, deepfakes, and BEC all at once. Verify through a second channel that you initiate.
Boss emails asking for a wire transfer? Call or message them on the number you already have. Vendor changes their banking details? Phone your contact on the number from your records. “Bank” calls you? Hang up and call the number on the back of your card. The attacker controls the channel they contacted you on. They don’t control the one you open yourself.
Slow is safe. Any request that punishes you for taking five minutes to verify was never legitimate to begin with.
Protecting Your Business (Not Just Yourself)
- Turn on multi-factor authentication (MFA). Even when a phishing attack steals a password, MFA stops the login. Microsoft’s research found MFA reduces the risk of account compromise by 99.22%.
- Train little and often. Ten minutes a month, covering texts and calls — not just email. Run phishing simulations so the first “attack” your team sees is a friendly one.
- Make reporting heroic. The employee who reports “I clicked something weird” in five minutes just saved you six figures. Celebrate them; never shame them.
- Add a payment verification rule. Any new payee, changed bank details, or transfer above a set amount requires voice confirmation on a known number. One sentence of policy, $123,000 of protection.
- Layer your email defenses. Modern filtering, domain authentication (DMARC), and endpoint protection catch a large share of attacks before a human ever sees them. You can’t click the thing if it never gets to you.
The Receipts: The Five-Minute Save
A bookkeeper at a small firm gets an email from the “owner”: pay this new vendor invoice today, he’s traveling and unreachable. Perfect grammar. Correct signature. Real project name. She almost pays it — then remembers her training, texts the owner’s actual cell, and gets back two words: “Not me.”
Total time to verify: five minutes. Average BEC loss avoided: $123,000. That’s the entire return-on-investment case for security awareness training, in one text message.
Your Quick-Start Checklist
- Today: Enable MFA on email, banking, and admin accounts.
- This week: Set a payment verification rule: new payees and bank-detail changes get voice-confirmed on a known number.
- This week: Tell your whole team about the gift card text and fake delivery scams. Two minutes at your next meeting.
- This month: Start monthly micro-training with phishing simulations — including text-based ones.
- This quarter: Ask your IT provider about email filtering, DMARC, and endpoint protection. If you don’t have an IT provider, that’s the first fix.
Frequently Asked Questions
What’s the difference between phishing, smishing, and vishing?
Same con, different channel. Phishing arrives by email, smishing by SMS/text, and vishing by voice call. All three try to trick you into handing over credentials, money, or access. Per the 2026 Verizon DBIR, the text and voice versions now succeed 40% more often than email — so treat your phone with the same suspicion as your inbox.
Can AI really fake my boss’s voice?
Yes — convincingly, and from just seconds of sample audio. That’s why voice alone is no longer proof of identity for financial requests. The FBI logged $893 million in AI-related losses in 2025, its first year tracking the category. The defense isn’t detecting the fake; it’s verifying every money request through a channel you initiate.
We’re a small business. Are we really a phishing target?
Absolutely — often a preferred one. Phishing campaigns are automated and sent at massive scale, and smaller businesses typically have fewer defenses and less formal payment controls. The human behavior element contributed to 62% of breaches in the 2026 DBIR. Fewer guardrails means the human layer matters more, not less.
An employee clicked a phishing link. Now what?
Move fast, skip the blame. Change the affected password immediately, revoke active sessions, alert your IT provider so they can check for compromise and secure the account, and warn the team in case others got the same message. Reported within minutes, most clicks are fully containable.
Will a spam filter alone protect us?
It helps, but no. The most expensive attacks — BEC — often contain no links or malware at all, just a persuasive request, which filters struggle to flag. Real protection layers filtering with MFA, verification policies, and trained people. Technology catches most of it; humans catch the rest.
Stay Sharp Out There
Liars, scammers, and bugs — you shouldn’t have to worry about any of it. The scams will keep evolving, but the defense stays refreshingly simple: verify before you act, protect your logins with MFA, and build a team that reports fast and never gets shamed for it.
And if you’d rather have professionals watching your inbox, your endpoints, and your team’s training program while you run your business? That’s literally our job — filtering, monitoring, simulations, and real humans who answer the phone. IT for the people. IT for the planet. Zero fluff.
Ready to make phishing someone else’s problem? Get a free quote or explore our services.
Sources
- FBI Internet Crime Complaint Center (IC3) — 2025 Internet Crime Report — https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
Supports: $20.877 billion in total losses (26% increase); 1,008,597 complaints; first dedicated AI section with 22,364 complaints and $893 million in losses.
- The HIPAA Journal — 2025 Losses to Cybercrime Exceeded $20 Billion — https://www.hipaajournal.com/fbi-internet-crime-complaint-report-2025/
Supports: Phishing was the most reported crime type with 191,561 complaints; BEC losses of $3.046 billion.
- Red Sift — FBI IC3 2025 report: Email fraud is now a $4 billion problem — https://redsift.com/blog/fbi-ic3-2025-report-email-fraud
Supports: Phishing losses grew 208% year over year, from $70 million to $215.8 million, while complaint volume stayed flat.
- Mimecast — The FBI’s $20 billion warning — https://www.mimecast.com/blog/the-fbis-$20-billion-warning/
Supports: Nearly 85 cents of every dollar lost came from cyber-enabled fraud rather than malware; BEC averaged about $123,000 per incident across 24,768 cases; 86% of fraudulent BEC payments moved via wire or ACH.
- Verizon — 2026 Data Breach Investigations Report (press release) — https://www.verizon.com/about/news/breach-industry-wide-dbir-finds
Supports: Mobile-based phishing (fake texts and voice calls) succeeds at a 40% higher rate than email phishing.
- Cyber Readiness Institute — Verizon DBIR 2026: Small businesses face escalating cyber threats — https://cyberreadinessinstitute.org/news-and-events/verizon-dbir-2026-small-businesses-face-escalating-cyber-threats/
Supports: Human behavior contributed to 62% of breaches.
- IBM — Cost of a Data Breach Report 2025 — https://www.ibm.com/reports/data-breach
Supports: 1 in 6 breaches involved attackers using AI, primarily for phishing and deepfake impersonation.
- Microsoft Research — How effective is multifactor authentication at deterring cyberattacks? — https://arxiv.org/pdf/2305.00945
Supports: MFA reduced the risk of account compromise by 99.22%.