At Kaizen AI, we specialize in delivering innovative solutions that drive sustainable growth and success for your business, Let us help you transform your vision

Get In Touch

AI Scam Reports Are Up 395%. The Typo Test Won’t Save You.

  • Home
  • Blog
  • AI Scam Reports Are Up 395%. The Typo Test Won’t Save You.
Flat illustration of a market trader holding a phone next to a floating email envelope with a fishing hook hanging from it, headline 395% more AI scam reports

Reports of AI-linked fraud in the UK rose 395% in a single year. That is nearly five times as many, and the reason is simple: the scam emails no longer look like scams.

For years the standard advice on scam emails was the same: look for the spelling mistakes. Clumsy grammar, an odd greeting, a logo that looked slightly off. We gave that advice ourselves. We have stopped giving it, because it no longer works, and this month the BBC showed exactly why.

What happened to the food festival traders

A BBC Wales investigation found dozens of small food and craft traders receiving emails that impersonated real UK food festivals, including events in Narberth, York, Ludlow, Mold, Newport, St Fagans and the Forest of Dean. These were not the crude scams most of us have learned to ignore. The messages carried the real festival branding. Some used the names of real members of staff. They addressed traders by name, knew the layout of the site, and used the same kind of online booking form that traders fill in every season.

The scammers were patient, too. Payment was only requested after several rounds of friendly back and forth: an invitation to apply for a pitch, a confirmation that the application had been successful, and only then a request to pay the stall fee. The account details pointed to a private account rather than a business one, and by the time anyone noticed, the money had gone.

Giles Mason, who runs UK Finance’s Take Five to Stop Fraud campaign, put it plainly: the spelling and grammar errors that used to give scams away have gone. Generative AI writes a clean, friendly, perfectly punctuated email in seconds, in any tone, as many times as the criminal likes.

The numbers behind it

This is not an isolated case. Report Fraud recorded a 395% rise in AI-linked reports in 2025-26 compared with the year before. And the money being lost is large and still growing. UK Finance’s Annual Fraud Report 2026 puts authorised push payment fraud, where the victim is tricked into sending the money themselves, at £576.4 million in 2025, up 19% on the year. Two thirds of it started online.

Authorised push payment fraud is the one that should worry a small business most, because the bank’s systems see a genuine payment made by a genuine account holder. Nothing gets hacked. Somebody simply believes an email and presses send. UK Finance’s figures show banks reimbursed 61% of APP losses in 2025, which also means a large share was never recovered.

Invoice and mandate fraud, the classic “our bank details have changed” email from a supplier, accounted for another £41.3 million across 2,305 cases. That is the same trick the festival scammers used, just dressed as a supplier instead of an event organiser. AI makes both versions far more convincing and far cheaper to run at scale.

Why small businesses are the target

Small businesses sit in an awkward spot. You pay suppliers, book services and take deposits by email every week, so a payment request arriving in your inbox is completely normal. You usually do not have a finance team or an IT department checking anything before it goes out. And the owner is often the person who both reads the email and makes the payment, frequently from a phone, between jobs.

Scammers know this. The festival emails worked because a stall booking is exactly the kind of message a trader expects in September. The best scams do not look unusual. They look like Tuesday.

Replace the typo test with a process

We build AI tools for small businesses, so we are not going to tell you AI is the enemy. But we are going to be straight about what has changed: you can no longer judge an email by how it reads. You have to judge the request by how it is verified. That means a simple process that does not rely on anyone spotting anything.

Here is what we set up with clients:

  • Never pay new bank details from an email alone. If an email gives you account details for the first time, or says the details have changed, call the organisation on a number you already have or that you look up yourself. Never use the phone number in the email.
  • Treat a private account as a stop sign. A festival, supplier or public body asking you to pay into a personal account is the single clearest warning sign in the festival cases.
  • Add a pause for any first payment. A rule that any payment to a new payee waits until the next day, or needs a second person to agree, costs almost nothing and breaks the urgency scammers rely on.
  • Use Confirmation of Payee properly. When your banking app says the name does not match, stop. Do not override it because the email was convincing.
  • Tell your team the typo rule is dead. Anyone who handles email in your business needs to hear that a perfectly written message proves nothing.

None of this is technical. It is five rules on a single page, and it protects you whether the scam email was written by a person, by AI, or by something that has not been invented yet. If a scammer’s email is flawless, it will not matter, because the payment still has to get past a phone call.

Where AI actually helps on the defensive side

There is a useful flip side. The same tools that write convincing scams can also help you check suspicious messages. Pasting a doubtful email into an AI assistant and asking what a careful finance manager would check before paying it is a genuinely useful second opinion. Email providers are also getting better at flagging lookalike domains. But these are extra layers, not replacements. The phone call to a known number is still the check that works every time.

If you would like help writing a one-page payment policy for your business, or checking where your own processes are exposed, that is exactly the kind of thing our free 30 minute AI audit covers. More detail on current scam types is also available from Take Five to Stop Fraud.

Leave A Comment

Fields (*) Mark are Required