Deepfake Scams Are Targeting NYC Small Businesses in 2026 — Here’s How to Protect Yours
Deepfake Scams Are Targeting NYC Small Businesses in 2026 — Here’s How to Protect Yours
The phishing email of 2022 was easy to spot. Typos, awkward phrasing, suspicious links — even employees at the best NYC small businesses could quickly flag those as fraudulent. But in 2026, the threat has evolved dramatically. Deepfake technology, powered by generative AI, is now being used by cybercriminals to clone the voices and faces of real business executives — and small businesses in New York City are on the front line.
The statistics are staggering. According to recent cybersecurity research, deepfake-based fraud has reached industrial scale. A single deepfake video call cost global engineering firm Arup $25.6 million when a Hong Kong finance employee was tricked into authorizing fraudulent wire transfers based on a video meeting populated entirely by AI-generated avatars. Deepfake scams totaled $350 million in damages in Q2 2025 alone, and the FBI’s Internet Crime Complaint Center recorded $16.6 billion in cybercrime losses in 2024 — a 33% year-over-year increase, with AI-enhanced social engineering driving a growing share.
How Deepfake Scams Actually Work (And Why They’re So Effective)
Deepfake scams in 2026 fall into three primary categories, and all three exploit the same human vulnerability: trust.
1. Voice Cloning (Vishing)
This is arguably the most dangerous vector for small businesses right now. Modern voice cloning models can produce convincing replicas from as little as three to five seconds of clean audio. Where does an attacker get that audio? Public sources — earnings calls, conference presentations, YouTube interviews, LinkedIn video posts, even voicemail greetings. The output is real-time synthesized speech that retains the target’s accent, cadence, and vocal character.
The pattern is predictable: a finance team member at a Staten Island or Manhattan firm receives a call that sounds exactly like their CEO or CFO. The cloned voice demands an urgent wire transfer, urgent vendor payment change, or immediate credential sharing. The call comes from a spoofed internal extension. The social pressure of an urgent request from an authority figure bypasses standard skepticism. Deepfake-enabled voice phishing surged more than 1,600% in the United States between Q4 2024 and Q1 2025 — and the trend has only accelerated.
2. Deepfake Video Meetings
Schedule a video call with a finance team member, impersonating an executive or external auditor. Use deepfake face replacement software in real time. The meeting is brief — long enough to establish an instruction but not long enough for the victim to study the video carefully. Then follow up with a spoofed email confirming the wire transfer amount and account details. This is the attack that cost Arup $25.6 million, and the same technique is now being targeted at mid-market companies across New York.
3. AI-Generated Spear Phishing
Generative AI eliminated the typos, awkward grammar, and cultural tells that once flagged phishing emails. Attackers now scrape LinkedIn, press releases, and earnings transcripts to write messages that mirror an executive’s actual voice, reference real internal projects, and time delivery to known travel windows. One campaign targeting 800 accounting firms with AI-generated emails referencing specific state registration details achieved a 27% click rate — far above industry averages for phishing campaigns. LLM-generated phishing emails have achieved click-through rates of 54% versus 12% for generic templates in controlled corporate settings.
Why NYC Small Businesses Are Particularly Vulnerable
New York City’s small business community — from professional service firms in Midtown Manhattan to medical practices in Staten Island and restaurants in Brooklyn — is uniquely exposed for several reasons:
- High-value targets: NYC SMBs manage wire transfers, vendor payments, and sensitive financial data daily, making them attractive for deepfake fraud.
- Remote work prevalence: More small businesses now operate with remote or hybrid staff who rely on Zoom, Teams, and phone calls for financial communications — exactly the channels deepfake attacks target.
- Limited security budgets: Unlike large enterprises, NYC small businesses rarely have dedicated security teams, 24/7 monitoring, or advanced email security gateways.
- Publicly available executive data: Business leaders in NYC’s competitive professional services space are active on LinkedIn, published in trade publications, and featured at conferences — providing attackers with abundant audio and video material for cloning.
What Deepfake Scams Have in Common (And How to Spot Them)
Despite the sophistication of the technology, every deepfake scam shares common hallmarks. The three pillars are speed, authority, and secrecy:
Speed: The attacker creates urgency to suppress critical thinking. “I’m in a board meeting and need this done now.” “This is time-sensitive — don’t tell anyone else yet.” “The bank is closing and I need you to process this immediately.”
Authority: The request comes from someone in a position of authority — CEO, CFO, a trusted vendor, or a legal representative. The cloned voice or face adds credibility that makes the request feel legitimate.
Secrecy: The attacker explicitly asks for discretion. “Don’t mention this to anyone.” “Handle this quietly.” This prevents the target from verifying the request with colleagues.
How Managed IT Providers Like MicroSky Protect NYC Businesses
At MicroSky Managed Services, we’ve seen the deepfake threat evolve from a theoretical risk to an active campaign targeting our clients across New York and New Jersey. Here’s what we implement for our SMB clients:
Email Security Gateways with AI Detection
A modern email security gateway with AI-based detection catches AI-generated phishing emails that slip past legacy filters — including business email compromise attempts and payload-less social engineering attacks. MicroSky deploys advanced email security as part of our managed IT services package, ensuring that even perfectly written, hyper-personalized phishing emails are flagged and quarantined.
Out-of-Band Verification Protocols
We help clients establish and enforce a critical policy: any request for wire transfer, credential sharing, or sensitive data access received via phone, video call, or email must be verified through a separate, pre-established channel. Not a number in the email. Not a link in the message. A known, verified phone number. This single control defeats virtually every deepfake vishing and BEC attack.
EDR and Threat Detection
While deepfake attacks target humans rather than endpoints, MicroSky’s Endpoint Detection and Response (EDR) solution monitors the broader environment. If an employee falls for a deepfake-influenced phishing email and clicks a malicious link, our EDR detects and neutralizes the follow-on threat before it can spread through the network.
AI-Powered Security Awareness Training
Traditional phishing training tells employees to look for grammar errors and urgency. Those signals no longer work. MicroSky’s security awareness programs are updated specifically for AI attacks — training employees on deepfake voice recognition, out-of-band verification procedures, and simulated attacks that mirror what they actually see in their inboxes today. The most effective defense against a deepfake scam is not better detection — it’s processes that make detection irrelevant.
5 Immediate Steps Every NYC Small Business Should Take
- Establish a verbal code word: Create a unique word or phrase between senior staff and their likely targets (PA, finance team). The code word must be included in any legitimate urgent request. An attacker who doesn’t know the code word cannot complete the attack.
- Implement multi-party wire approval: Require multiple approvals for transactions above threshold amounts. A single point of social engineering cannot authorize a transfer when a second approver must log into a separate system and confirm.
- Deploy advanced email security: If your business is still relying on standard spam filters, you are already getting hit by AI-generated phishing. MicroSky’s managed email security solutions catch what standard filters miss.
- Update your security awareness training: Make sure every employee — from the receptionist to the partners — understands that deepfake scams are a real threat and knows the verification procedures to follow.
- Strongly enforce DMARC, DKIM, and SPF: Email authentication stops the spoofed sender addresses that typically accompany deepfake attacks in the follow-up email.
Contact MicroSky for a Deepfake Security Assessment
Deepfake scams aren’t a hypothetical threat. They’re happening right now to small businesses across New York, New Jersey, and beyond. The attackers don’t care how small your business is — they care that you’re profitable enough to have money to steal.
MicroSky Managed Services provides comprehensive cybersecurity solutions designed specifically for NYC small businesses. From managed IT services and EDR to AI-powered threat detection and security awareness training, we help businesses like yours stay protected against the evolving threat landscape. Call us at (718) 672-2177 or visit microskyms.com to schedule a free consultation.

