Cyber Fraud Costs American Small Businesses More Than $1 Billion Annually

By The Epoch Times | Created at 2026-10-03 09:12:07 | Updated at 2026-10-03 10:46:28 1 hour ago

Cybercrime has been a long-standing risk for anyone who does business online. However, it’s taking a heavy toll on small American companies, costing more than $1 billion per year, according to the Public Private Strategies Institute.

Those who’ve dealt with online fraud attempts say the attacks—including phishing, email scams, fake orders, and ransomware—are getting more sophisticated as artificial intelligence (AI) capabilities expand.

Cybercrime experts say AI-driven digital fraud will only get worse, and there are reasons criminals find high success rates when targeting smaller enterprises.

“Small businesses are typically more vulnerable since they don’t have the depth of knowledge or resources to identify and remediate vulnerabilities in their IT infrastructure that would assist them with identifying these threats,” Daniel Ward, IT and Cybersecurity program coordinator for Southern New Hampshire University, told The Epoch Times.

Ward said many small companies depend on a single individual to manage their entire digital infrastructure, including security.

“Often the business owner fills this role, or they’re outsourcing these responsibilities to [a managed service provider] that may not be particularly security-focused or savvy,” he said.

Chris McGlasson, fractional chief information officer at ClearStack Advisory, agreed.

“Small businesses are vulnerable because security is nobody’s full-time job. IT is usually one person juggling help desk, vendors, and whatever broke today,” McGlasson told The Epoch Times.

McGlasson said criminals are aware of this and use it to their advantage.

“They exploit trust more than technology: a fake invoice from a real vendor, a spoofed email from the owner telling accounting to wire funds. Big companies have layers that catch this. Small ones often have one person and a prayer.”

Moreover, Ward said there’s much more at stake than just money.

“Especially if those customers or vendors are impacted [by fraud] as well. It contributes to eroding trust in the business and impacts future engagements.”

“Financially, I’ve seen more small businesses impacted by phishing scams, with accounting employees wiring money due to impersonation attacks,” he added.

Ward said the companies that end up robbed often have limited success in recovering the stolen funds. Some studies have found the recovery rate of online scams is less than 10 percent.

In April, the Pubic Private Strategies Institute published its survey of 500 American small businesses, which found that 72 percent experienced fraud, scams, or ransomware last year. Credit card, payment fraud, and email phishing were the most frequently reported attacks. Damages for those affected averaged nearly $60,000 for payment fraud and more than $90,000 for email scams.

Within that same group, 76 percent of small business owners reported AI use in the cyber attack.

A smartphone and computer screen displays YouTube and TikTok accounts posting AI-generated deepfake audio of Pope Leo XIV in Los Angeles on June 2, 2025. (Chris Delmas/AFP via Getty Images)

A smartphone and computer screen displays YouTube and TikTok accounts posting AI-generated deepfake audio of Pope Leo XIV in Los Angeles on June 2, 2025. Chris Delmas/AFP via Getty Images

This is supported by other research. The Federal Bureau of Investigation documented more than 22,364 AI-related crime complaints in 2025, the adjusted losses of which surpassed $893 million.

Blind Spots

Ed Gaudet, founder of the risk intelligence and cybersecurity platform Censinet, said criminals are attracted to companies where defense “runs thin.”

“Small businesses are vulnerable because everything about them is built for speed, and speed is exactly what fraud exploits,” Gaudet told The Epoch Times.

He’s seen the price of a ransomware attack up close in his work.

“One of my clients, a small specialty practice, got breached through a remote-access tool a billing vendor had installed years earlier. Nobody remembered it was there, so nobody watched it. Within a few days, everything was locked,” Gaudet said.

The company lost access to scheduling, records, billing—everything it needed to operate.

“They spent close to a month running on paper, with staff calling patients from their personal phones to reschedule. However, the ransom was the smallest cost.”

Gaudet said many canceled appointments never came back. The affected company’s insurer disputed pieces of the claim for weeks while bills kept piling up. He said two employees quit from the sheer stress of the recovery effort.

“The attack itself took days. The financial damage took most of a year to work through,” he said.

Like many, Gaudet believes AI has made it easier than ever to steal from businesses. In his assessment, it gives even novice criminals a serious advantage.

Before AI, he said it was a trade-off between “quality and volume” for scammers.

“Now every message in a mass campaign reads like the handcrafted one. And the research phase collapsed too. Scraping a company’s site, its staff pages, its vendors, then writing a personalized email referencing a real project and a real colleague takes seconds,” he said.

Breaking the Loop

With increasingly realistic AI voice cloning and deepfake videos, it’s easy to convince someone that you’re a customer, a vendor, or even the boss.

Deepfake attacks certainly aren’t a new phenomenon, but people still struggle to tell the difference. In an iProov study, less than 1 percent of participants could correctly identify deepfakes and real samples. Paradoxically, individual confidence in being able to detect a deepfake was high. Sixty percent of participants said they felt they could accurately spot one.

This is why Gaudet said breaking a criminal’s feedback loop is critical in derailing an attack.

“Stop authenticating people and start authenticating through channels the attacker doesn’t control,” he said.

Gaudet cited a case in Hong Kong where a finance employee joined a video call, saw his chief financial officer and colleagues right there on screen, and wired out “roughly the price of a private jet fleet.”

“Every single face on that call was a deepfake. The lesson is the request came through the attacker’s channel, and the confirmation happened in the same channel. You have to break that loop. Agree on a code word for anything touching money or credentials. And drill one sentence into your team: I’ll call you back on the number we have on file,” he said.

McGlasson concurred.

“On verification, make it cultural. Any request involving money or sensitive data gets confirmed through a second channel, a phone call to a known number, never a reply to the email that made the request.”

He said there needs to be a “no exceptions” rule, even if the request is flagged as urgent.

“Especially when it’s urgent. Urgency is the weapon,” McGlasson said.

For small business owners like Angela Zeng, navigating a minefield of attempted cyberattacks is becoming a regular part of operations.

(Illustration by The Epoch Times, Shutterstock)

Illustration by The Epoch Times, Shutterstock

“I am the target these spam emails are aimed at. … We have seen an increasing stream of suspicious proposal submission invitations, payment links, and invoices arriving in our company mailboxes, each one looking like it was from a real customer or a supplier, with an attachment and a request to click links or open attachments,” Zeng told The Epoch Times.

Zeng is the founder and CEO of the St. Louis-based beverage company Karviva. She said her team did not open the suspicious messages, but the volume has become high enough that she’s considering adding a cybersecurity official.

“That is the real cost for a company our size. Not money taken by a criminal, but a full salary spent on defense instead of on product development and on the staff who grow the business,” she said.

Zeng has a firm and fast rule when it comes to suspicious communications.

“We do not open any link we were not expecting, not even to see who sent it. If a bill cannot be matched to something we ordered, we call the vendor to verify. The verification has to happen outside the email.”

So far, she’s been lucky to avoid becoming a victim of costly and reputation-damaging fraud. However, hiring a dedicated security person isn’t an expense many small businesses can handle.

Research from StrongDM suggests 47 percent of businesses with fewer than 50 employees have any budget for a cybersecurity professional. Fifty-one percent of small businesses claimed to have no cybersecurity measures in place, and just 17 percent said they have insurance against these kinds of attacks.

But McGlasson and Gaudet said small business owners can take steps to protect their enterprises today without breaking the bank.

“The biggest mistakes I see: no multi-factor authentication on email and banking, and backups that have never actually been tested,” McGlasson said.

Gaudet agreed.

“Almost everyone has [backups]; almost nobody has tested them. They sit on the same network as everything else, so when ransomware hits, it encrypts the backups too. You find this out at the worst possible moment, when the backups were your entire recovery plan.”

He added that the fixes for this are “embarrassing in how cheap they are.” Gaudet said multi-factor authentication for email and remote access, along with backups kept offline and tested before restoration is needed, are important immediate steps owners can take.

McGlasson believes email authentication is the most underused defense tool. These include tools like Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication, Reporting, and Conformance.

“It’s free, it takes an afternoon to set up, and it stops a huge share of spoofed email cold. Most small businesses have never heard of it,” McGlasson said.

Read Entire Article