Here's a scenario playing out in small businesses all over the country right now. An owner gets a call from his office manager on a Thursday afternoon.
"Hey, I sent the wire. Just confirming you got the paperwork for the equipment deal?"
He has no idea what she's talking about. There is no equipment deal.
Two hours earlier, she got a call from a number she didn't recognize. On the line was him. His voice, his cadence, the way he says "real quick" before everything. He said he was at the bank closing on a used truck, the seller wanted funds today, and could she wire twenty two thousand dollars to the account he was about to text her. He sounded rushed and a little annoyed. Exactly like he does when he's rushed and a little annoyed.
She did what any good employee would do for a boss who sounded like that. She sent it.
It wasn't him. It was a clone of his voice, built from a couple of Instagram videos and his outgoing voicemail greeting.
I'm sending you this on a Friday because I want you to do something about it before Monday.
The numbers, quickly
The FBI's Internet Crime Complaint Center released its 2025 report earlier this year. Reported losses hit about twenty one billion dollars, up twenty six percent from the year before. Business email compromise alone, which is the fancy name for "someone pretended to be someone you trust and asked for money," accounted for just over three billion of that.
The FTC's numbers tell the same story from the consumer side. Imposter scams cost Americans around three and a half billion dollars in 2025.
And those are just the reported losses. Plenty of small businesses get hit, feel embarrassed, and never tell anyone.
Here's the part that should bother you. A McAfee study back in 2023 found that about three seconds of audio is enough to create a voice clone with an eighty five percent match to the original speaker. If you've ever posted a video, done a podcast, left a voicemail, or recorded your own outgoing message, your voice is already out there.
Don't panic. Just get a protocol in place. It takes about an hour and I'll walk you through it.
The three scams hitting service businesses right now
The boss call. Like the story above. A cloned voice, or just a convincing email, from the owner to whoever handles money. It's urgent, it's a little off, and there's always some reason you can't call back. "I'm in a meeting." "I'm at the closing." "My phone's about to die."
The vendor bank change. This one is quieter and more dangerous. You get an email from a supplier you've paid for years. Same logo, same signature, same invoice format. It says they've switched banks and here's the new account for this month's invoice. Sometimes it comes from a lookalike domain that's one letter off. Sometimes it comes from the vendor's real email account, because the vendor got hacked and the scammer has been sitting in their inbox for weeks, reading everything, waiting for the right invoice.
The fake you. The one nobody thinks about. Scammers impersonate your business to your clients. They send your customers an invoice from a domain that looks like yours, with new payment instructions. Your client pays the scammer. Now your client is out the money, you're not paid, and somehow you're the one who looks bad.
Q4 makes all three worse. You've got more invoices flying around, year end buying, half the office on vacation, and everybody in a hurry. Scammers know that December is the month when everybody's rushing and nobody's double checking.
The lockdown, rule by rule
None of this costs much. Most of it is free. All of it works best when it's written down and everyone on your team knows it's non negotiable.
Rule one: the callback rule.
Any request to send money to a new place, or to change where money goes, gets verified with a phone call to a number you already had on file before the request showed up.
Not the number in the email. Not the number in the text. Not "just reply to this." A number from your contacts, your old invoices, or the vendor's website that you look up yourself.
This one rule kills most vendor bank change scams. Write it on a sticky note and put it on the monitor of whoever pays your bills.
Rule two: the code phrase.
Pick a phrase that only you and the people who handle money know. Something random. Not your dog's name, not your kid's birthday, nothing that's on social media. "Blue tractor." "Aunt Linda's lasagna." Whatever.
Any urgent money request from you, by phone, by text, by anything, requires the code phrase. No phrase, no payment. Even if it sounds exactly like you. Especially if it sounds exactly like you and you're "in a hurry."
Then tell your team, out loud, in a meeting: "If I ever get mad at you for asking for the code phrase, you have my permission to ignore me." Because the whole scam works by making people afraid of annoying the boss.
Do this at home too. Grandparent scams use the same technology, and your parents need a family phrase just as much as your bookkeeper does.
Rule three: two people over a line.
Set a dollar threshold. For a lot of small businesses, twenty five hundred dollars is about right. Any payment over that line needs a second person to approve it, and that second person has to independently confirm the payee.
If you're a one person shop, the second person can be you, the next morning. Which brings us to the next rule.
Rule four: the 24 hour cooling period.
Any new payee, or any change to an existing payee's bank details, waits twenty four hours before the first payment goes out.
Real vendors won't care. Scammers will, because the whole con only works if you move before you think. Twenty four hours gives you time to make the callback and come to your senses.
Rule five: call your bank and turn on everything.
This takes thirty minutes on the phone and most owners have never done it. Ask your business banker for these by name.
Positive Pay. You tell the bank which checks you've written and which companies are allowed to pull from your account, and they flag anything that doesn't match.
ACH debit block or ACH filter. This stops unauthorized withdrawals from hitting your account, or limits them to companies you've pre approved.
Wire limits and dual approval. Many banks let you require two logins to release a wire, or set a daily cap.
Alerts on every outgoing payment. Text or email the moment money leaves. You want to know in minutes, not at the end of the month.
Some of these cost a few bucks a month. Compared to one bad wire, they're free.
Rule six: lock down your email.
Most of these scams start in an inbox. Yours, your vendor's, or your bookkeeper's.
Turn on two factor authentication for every email account in the business, and use an authenticator app instead of text message codes wherever you can. Text codes can be stolen with a SIM swap. App codes are much harder.
Then go check your forwarding rules. This is the one almost nobody knows about. When scammers get into an email account, they often set up a quiet rule that forwards certain messages to them, or moves anything with the word "invoice" or "payment" into a folder you never look at. In Gmail, open Settings, click See all settings, and check two tabs: Filters and Blocked Addresses, and Forwarding and POP/IMAP. In Outlook, go to Settings, then Mail, and check both Rules and Forwarding. If you see a rule you didn't create, delete it, change your password, and call whoever handles your IT.
Finally, register the obvious misspellings of your domain. If you're deadsimplegrowth.com, someone could register deadsimpelgrowth.com for twelve bucks and send invoices to your clients from it. Grab the three or four most likely typos yourself. It's cheap insurance.
Rule seven: protect your clients from fake you.
Put one line on every invoice, every proposal, and in your email signature:
"We will never change our payment details by email. If you ever receive a message saying otherwise, call us at (407) 555 0100 before you pay."
Use your real number, obviously. Then say it out loud during onboarding. "One quick thing. We'll never email you new bank details. If you get one, it's not us. Call me."
Your clients stay safe, and you come off like a shop that has its act together. Not a bad trade for one sentence on an invoice.
Rule eight: know your first hour.
If money goes out the door to the wrong place, speed matters more than anything else. Write this down now, while you're calm.
Call your bank's fraud department immediately and ask them to recall the payment. Not email. Call.
File a complaint at ic3.gov the same day. The FBI has a team that works with banks to try to freeze fraudulent domestic transfers, and they're much more successful when the report comes in fast.
Report it at ReportFraud.ftc.gov too.
Change the passwords on every email account involved, and check those forwarding rules again.
Then tell the vendor or client whose identity was used, so they can warn everyone else who might be next.
The ten minute team meeting
Rules nobody knows about don't protect anybody. Get everyone who touches money, email, or the phones into a room for ten minutes next week and cover this:
"Scammers can now fake my voice and fake our vendors' emails well enough to fool anyone. So here's how we handle money from now on. Any new payee or bank change, we call a number we already had. Any urgent request from me needs the code phrase. Anything over twenty five hundred needs two people. New payees wait a day. And nobody here will ever get in trouble for slowing down a payment to double check. Ever."
That last sentence is the whole meeting. Say it twice.
Then, a month from now, run a drill. Have someone send a fake "urgent payment" request to your bookkeeper from an outside email address and see what happens. Make it friendly. Buy lunch for whoever catches it. You're not out to catch anybody. You just want the rules baked in before the real call comes.
A few tools that help
If you want an extra set of eyes on a suspicious email, paste it into ChatGPT or Claude and ask, "What about this email looks like a payment scam?" They're surprisingly good at catching lookalike domains, odd urgency, and mismatched details that a busy human skims right past. Just don't paste in account numbers or anything sensitive.
If your accounting software connects to Make.com, you can set up an alert that texts you whenever a new vendor is created or vendor payment details change. That way no bank change happens without the owner knowing about it, even if the owner isn't the one paying the bills.
And consider changing your outgoing voicemail to a generic greeting instead of your own voice. It's one less clean sample of you sitting out there for anyone to grab.
Why this belongs in a growth newsletter
I know, this is usually a newsletter about getting clients and making money. Stick with me, because this is the same thing.
A twenty two thousand dollar wire to a scammer shows up as a cash flow problem first. Then a payroll problem. For a lot of businesses doing a few hundred thousand a year, it's the entire profit from a good quarter, gone in one phone call, with very little chance of getting it back.
And the fake you scam is a reputation problem. If one of your clients gets burned by an invoice that looked like it came from you, they won't remember the technical details. They'll remember that paying you got complicated.
No point growing revenue if it walks out the door on a Thursday afternoon.
Do this before Monday
Call your bank. Turn on alerts, ask about Positive Pay and ACH blocks.
Pick your code phrase and tell the people who handle money.
Write the callback rule on a sticky note.
Check the forwarding rules on your email.
Add the "we'll never change payment details by email" line to your invoice template.
Total time is about an hour. The owner in that Thursday story would pay a lot more than an hour for a do over.
Talk Soon,
Dan
Dan Kaufman
Founder, Dead Simple Growth and Pinnacle Masters
P.S. Reply with LOCKDOWN and I'll send you the one page payment protocol I give clients. It's the rules above formatted as a policy you can print, sign, and hand to your team, plus the bank call checklist, the client notice language, and the first hour response plan.

