← Back to the blog AI Consulting · Toledo, Ohio

100 Tech Companies Just Warned About AI Attacks. Nobody Wrote the Small Business Part.

Jayson Hines · August 28, 2026 · 4 min read

The list of companies that signed this thing is longer than the letter itself.

Thursday, more than a hundred companies put their names on an open letter about AI and hacking. OpenAI, Anthropic, Google, Microsoft, Amazon, Cisco, Oracle, Cloudflare, CrowdStrike, Palo Alto Networks. Then a pile of names that have nothing to do with tech: Capital One, Mastercard, Visa, General Motors, Shopify. What they're saying is that attacks built with AI are going to get more common and a lot better over the next few months, and that defending against them has to be a priority right now instead of a line on next year's budget.

The letter names hospitals, water treatment plants, and the infrastructure that keeps the internet running. Those matter, and I'm glad somebody said it. But I went through the thing twice and nobody wrote the paragraph for the six person shop out on Airport Highway, so I'm going to write it.

You're not too small. You're the whole point.

Every owner I've said this to gives me the same look. Why would anybody bother with us, we're not a bank.

Because it used to cost something to bother with you. A scam that actually worked took a real person sitting there for an hour, digging up who your suppliers are and writing an email that sounded like one of them. That hour was worth more than whatever's in your operating account, so they went after somebody bigger instead. The math protected you and you never had to think about it.

The math is what changed. Writing five hundred emails that each name the right vendor and the right kind of job now costs about the same as writing one. So when the price of coming after you drops to almost nothing, everybody is worth coming after. Ok so that's the real news in this letter, and it's why Visa and GM signed it and not just the security companies.

The tell you've been teaching your people is gone

For twenty years the advice was to watch for bad spelling and a strange greeting. Dear Valued Customer. A sentence that reads like it went through three languages on the way to you.

That's done. The email that lands now uses your supplier's real name, mentions the kind of work you actually do, and reads like a tired guy typing between appointments. I've had two clients this year forward me something and ask if it was legit, and both times the writing told me nothing at all. I had to go look at the sending domain, and one of them was off by a single letter. That's the whole difference now, one letter, and it's sitting in a font your eye skips right over.

The phone version is worse and it's already here. A few seconds of audio is enough to copy somebody's voice, and most of you have posted video of yourself on Facebook standing in front of a finished job talking about it. Your bookkeeper gets a call that sounds like you, asking her to push a payment through before you get out of a meeting. She isn't dumb for going along with it. It sounds like you.

Four things this week, none of them expensive

Set a callback rule on money, and say it out loud to everybody who touches your bank account. Any request to move money, change where a payment goes, pay an invoice a new way, or send account details gets verified by calling the number you already had for that person. Not the number in the email. Not the number the caller gives you. The one already sitting in your phone. That single rule stops most of what I just described.

Turn on two factor authentication for your email before you do anything else on this list. Your email is the key to everything else you own, because that's where every password reset lands. If you only do one of these four, do that one.

Have an actual conversation with your team and tell them you will never text or call asking them to buy gift cards, wire money, send a copy of a check, or read you a password. Giving your people permission to hang up on someone who sounds exactly like you is worth more than any software you'd buy this month.

Then go look at who still has access to your accounts. Every shop I sit down with has at least one former employee or some marketing company from four years ago still sitting inside something. Takes about twenty minutes to go through and it's usually the most uncomfortable twenty minutes of the day.

The part I'd push back on

The letter asks organizations to make cyber defense an immediate leadership priority. That's a reasonable sentence if you've got a security team. You've got yourself and maybe a guy you call when the printer quits. So don't read it as a project you have to go start. Read it as four habits, and the callback rule is the one that matters most.

The people running these attacks got a serious upgrade this year. Your side of it hasn't changed much, and it doesn't really need to. The basic stuff still works fine. It just has to be turned on before somebody calls your bookkeeper in your voice.

I run AI workshops and one-on-one AI consultations for companies around Toledo, Northwest Ohio, and Southeast Michigan. Walking a team through what these scams look like now, and setting the callback rule so it actually sticks, is a normal hour in one of those sessions. If you've got an email sitting in your inbox right now that you're not sure about, send me a note and I'll take a look at it.

Email Jayson