This story is part of the Nerds News briefing for April 7, 2026. Watch the full episode on YouTube or read all six stories together in the main briefing.
AI-Generated Phishing Is Now Aimed Squarely at Small Businesses
For years, the playbook for spotting a phishing email was simple: look for the typos, the awkward grammar, the "Dear valued customer" opener that no real company would ever use. That playbook is officially dead. A new report from Acrisure confirms what we’ve been warning clients about for months: attackers are using AI to generate hyper-convincing phishing emails targeted directly at small business employees.
The writing is now better than the average human’s. In a lot of cases, it’s better than almost anyone you’d find in a typical office. The lures are personalized using publicly available data scraped from LinkedIn, your company website, and previous breaches. The result is an email that looks like it came from a vendor you actually use, asking you to do something that sounds completely reasonable — until you click the link and hand over your password.
Here’s the rule we want every employee to internalize: never enter a username and password into anything you reached from an email link unless you are absolutely positive it’s legitimate. Type the URL yourself, or use a saved bookmark. And if you don’t already have a security awareness training program in place — including phishing simulations — that’s the single highest-ROI security investment you can make right now. We can help you set one up.
Watch the 60-second clip
How ACS helps
Stuff like this is exactly why we built our managed services packages — so small business owners don’t have to track every Microsoft announcement or wonder which patch matters. If you’d like an IT partner that watches this stuff for you and acts before it becomes a problem, schedule a quick call with our team and we’ll put a plan together.
