How AI Scales Your Cyber Risk 
Shutterstock

How AI Scales Your Cyber Risk 

Companies are faster than ever. So are attackers.

The same tools making your team more productive are also making attackers more productive

Imagine you land the positive press every founder desires. Your team celebrates. Customers send congratulations. And somewhere, a group of hackers reads that news and starts making plans.

That is what recently happened. Within weeks of a company’s good news, attackers impersonated customer accounts, got inside the company’s systems, and moved money out by faking transactions that looked completely normal. It was nasty, and it was fast.

I think about couple of key themes when I see AI in the headlines related to that story.

Businesses are clearing years of IT backlog in months. Engineering teams using tools like Claude Code are shipping software at a pace that would have seemed absurd two years ago. World leaders and AI executives, meanwhile, must debate safety and long-term, existential risk.

For a Twin Cities business owner, the more urgent risk sits between those stories. If AI makes it dramatically easier to build software, it makes it dramatically easier to create attacks. Not every engineer is on your side.

The losses are already staggering. The FBI reports Americans lost $20.9 billion to internet crime in 2025, and those are only the incidents people reported.

Cyber risk has been serious for years. It’s about to get much worse.

What does that mean for a company with 50 or 200 employees? Three risks stand out.

  1. Phishing that no longer looks like phishing. The typos and awkward grammar are gone. AI writes personalized emails at scale, using details pulled from your website, LinkedIn, and press coverage.
  2. Voices and faces you can’t trust. In 2024, an employee at the engineering firm Arup sent almost $25 million after a video call with deepfakes of company executives. Cloning your CEO’s voice now takes a few seconds of audio.
  3. “Too small to target” is over. When an attack took weeks of skilled work, criminals chased larger companies. When AI does the work, the math changes, and a midsize manufacturer or distributor becomes worth the effort.

So what should you do?

  • Verify through a second channel. Any request to move money, change banking details, or reset credentials gets confirmed by a call to a known number. No exceptions for the boss.
  • Lock down the basics. Use multi-factor authentication on every account, with software patched promptly. To this day, most breaches begin with a gap someone meant to close.
  • Train with current examples. Play your team a cloned voice. Once people hear one, they stay alert.
  • Raise your guard when you make news. Before a big announcement goes public, tell your bank, your IT partner, and your finance team to watch closely.

AI is making good companies faster. It is making bad actors faster, too. Slow down every request that moves money or grants access.