Cybersecurity coverage skews toward the most cinematic threats — nation-state hacking groups, ransomware gangs taking down hospitals — because those stories are dramatic and newsworthy. But the threats actually draining money from ordinary people and small businesses day to day are less exciting and far more common: AI-assisted phishing, business email compromise, and SIM-swap fraud.
AI made phishing dramatically better
The single biggest shift in the threat landscape over the past two years is that generative AI eliminated the tell-tale signs — bad grammar, awkward phrasing, generic greetings — that used to help people spot a phishing email. A scam email can now be written in flawless, personalized, contextually appropriate language, sometimes referencing real details scraped from a target’s public social media or a previous data breach. Voice-cloning has made phone-based scams — someone calling, sounding exactly like a family member in distress, asking for an urgent wire transfer — a genuinely new and effective category of fraud that barely existed five years ago.
Business email compromise, where an attacker impersonates a executive or vendor to trick an employee into an urgent wire transfer, remains one of the most financially damaging categories of cybercrime specifically because it doesn’t require any malware or technical breach at all — just a convincing enough email and someone in accounts payable moving fast under perceived pressure.
The tools got scarier, but the actual defense hasn’t changed: verify unusual requests through a second channel, and slow down anything that’s designed to make you feel rushed.
What actually reduces your risk
The most effective, least glamorous defense remains multi-factor authentication on every account that offers it — the overwhelming majority of account takeovers still succeed because of a reused or stolen password with no second factor, not because of some novel exploit. For businesses, a simple internal policy — any payment or wire-transfer request above a set threshold requires verbal confirmation through a known phone number, not the number in the suspicious email — closes off the business-email-compromise attack almost entirely, because it breaks the attacker’s ability to move fast.
The uncomfortable truth about cybersecurity for most individuals and small businesses is that the sophisticated nation-state threats you read about are not the ones you’re likely to encounter. The mundane stuff — a reused password, an unverified wire transfer, a rushed decision on a convincing phone call — accounts for most real-world losses, and all three are addressed by boring, well-known habits rather than exotic new tools.