We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Threats

Threats

AI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not

AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The phishing email that knew her clients' project names

The owner of a 15-person staffing agency has been forwarding suspicious emails to her IT provider for years, mostly out of habit. The one she forwards on a Tuesday in March is different, and she knows it before she can say why.

It is addressed to her operations manager, from what appears to be the owner's own address. It references the Harborview account by name, mentions that the contract renewal is "coming up on the 20th, as we discussed," and asks him to send over the updated rate card and the contact list for the client's hiring managers before her flight. The tone is hers. The short sentences. The way she signs off with just her first initial. Even the small joke about the client's procurement team.

None of it is in any email she has ever sent. The Harborview renewal date is in a case study on her own website. The joke about procurement was in a newsletter from 2024. Her writing style is in 300 LinkedIn posts. Her flight is in a conference speaker list.

The IT provider's answer is short: "This is what they look like now." The operations manager, to his credit, did not reply. He had walked over to her office to ask about the flight, and she was sitting at her desk.

What the heck does this mean

An AI cyber attack, in the way the term is used by the people who write the annual reports, is an attack where some part of the work was done by generative software: writing the email, cloning the voice, sorting through stolen data, or writing code. The software did not choose the target. It made the attack faster, cheaper and better written.

AI phishing is the most common form and the one your staff will meet first. The message is fluent, personal, and drawn from what you have published about yourself. The bad grammar your team was trained to spot is gone.

Phishing-as-a-service is the business model behind it: a subscription kit that includes the fake login pages, the sending infrastructure, and now the writing tools, so one person can run a campaign that used to need a crew.

What did not change is the list of things the attacker still needs from you. A password. A click. An approval. An unpatched box. Nothing about the software removes those steps. It only makes the request more convincing.

That is the useful news in an otherwise noisy year. The controls that stopped the old version still stop this one. The training is what has to change.

The numbers that matter

AI-driven attacks rose 56% year over year, and breaches involving AI cost about $1 million more than the average, according to the IBM 2026 Cost of a Data Breach Report. More of them, and more expensive when they land.

68% of businesses expect to be hit by phishing in the next 12 months, and one in three trains staff once a year or less, per the Kaseya 2026 Cybersecurity Outlook. Two-thirds see it coming. A third is preparing for it with a video from last spring.

One in three emails is malicious or spam, according to the Barracuda 2026 Email Threats Report. The volume was already there. The software made the third that matters harder to tell from the two-thirds that do not.

What to do this week

  1. Retire the "spot the typo" training. Replace it with one 20-minute session that shows staff the new kind: fluent, personal, referencing real projects, arriving on the day the owner is travelling. Use your own public material to build the example. (CIS 14 Security Awareness and Skills Training)
  2. Set the rule that any request involving money, credentials or client lists is confirmed through a second channel, no matter how well written. The operations manager walking to the owner's office is the control. Write it down. (CIS 14 Security Awareness and Skills Training)
  3. Turn on the email settings that check origin rather than prose: sender authentication (SPF, DKIM and DMARC) on your own domain, external-sender tagging, and link rewriting that inspects where a URL really goes. (CIS 9 Email and Web Browser Protections)
  4. Audit what you publish. Speaker bios, case studies with client names, newsletters with internal jokes. Keep publishing, but know that every detail is now raw material and adjust what goes in. (CIS 14 Security Awareness and Skills Training)
  5. Get someone watching sign-ins, mailbox rules and outbound data for the small signals that the fluent email worked. A better message does not change what happens after the click, and that is where detection lives. (CIS 13 Network Monitoring and Defense)
  6. Move the owner and finance staff to phishing-resistant MFA, so even a perfect email pointing at a perfect login page gets nothing. (CIS 6 Access Control Management)

Where AccuSights fits

Our assessment separates what changed from what the headlines say changed, and checks the controls that hold either way: sender authentication on your domain, the MFA type on finance accounts, whether anyone reads the logs. The Cyber Hygiene Test takes three minutes and gives a first score. To talk through the training your team needs, book 15 minutes with an engineer.

Questions people ask

Can AI write phishing emails that filters miss? Yes, because filters were never good at judging writing quality, and now there is no bad writing to judge. What filters still catch is the mechanics: the lookalike domain, the newly registered sender, the link that redirects three times, the attachment with a QR code. So the answer is to stop relying on people spotting bad grammar and start relying on controls that check where the message really came from and where the link really goes.

Do I need AI security tools to fight AI attacks? Not as a first step. The AI in an attack mostly makes the message better; the message still needs a password, a click, or a payment approval to do harm. Multi-factor authentication that resists phishing, a callback rule for payments, endpoint detection, and someone watching the logs stop the AI-written version as well as they stopped the old one. Buy the detection tools after the basics are in place, not instead of them.

What is phishing-as-a-service? It is a subscription business, run by criminals for criminals, that rents out everything needed to run a phishing campaign: the fake login pages, the sending infrastructure, the proxy that captures MFA codes, and now the AI writing tools. The customer pays a monthly fee and supplies the target list. It is why a 15-person agency now receives attacks that look like they took a team a week to build. They took one person an afternoon.

The email got better. The ask did not change. Guard the ask, and the quality of the prose stops mattering.

Questions people ask

Can AI write phishing emails that filters miss?

Yes, because filters were never good at judging writing quality, and now there is no bad writing to judge. What filters still catch is the mechanics: the lookalike domain, the newly registered sender, the link that redirects three times, the attachment with a QR code. So the answer is to stop relying on people spotting bad grammar and start relying on controls that check where the message really came from and where the link really goes.

Do I need AI security tools to fight AI attacks?

Not as a first step. The AI in an attack mostly makes the message better; the message still needs a password, a click, or a payment approval to do harm. Multi-factor authentication that resists phishing, a callback rule for payments, endpoint detection, and someone watching the logs stop the AI-written version as well as they stopped the old one. Buy the detection tools after the basics are in place, not instead of them.

What is phishing-as-a-service?

It is a subscription business, run by criminals for criminals, that rents out everything needed to run a phishing campaign: the fake login pages, the sending infrastructure, the proxy that captures MFA codes, and now the AI writing tools. The customer pays a monthly fee and supplies the target list. It is why a 15-person agency now receives attacks that look like they took a team a week to build. They took one person an afternoon.

Controls this post maps to

CIS 14 Security Awareness and Skills TrainingCIS 9 Email and Web Browser ProtectionsCIS 13 Network Monitoring and Defense

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.