AI-Enabled Fraud: How One Call Cost $156K
In this episode of the B2B Brand180 Podcast, Linda Fanaras interviews Jonathan Slain, advisor to middle-market companies and co-author of Rock Your Business. Together, they unpack how Jonathan’s company fell victim to a sophisticated AI-enabled fraud attempt involving email compromise and voice impersonation, and what the costly experience taught him about cybersecurity, risk, and leadership.
Jonathan shares practical insights on strengthening payment approvals, evaluating cyber fraud and social engineering insurance, and keeping employee security training current as AI threats evolve. You’ll hear actionable strategies for protecting your business from AI-enabled fraud, identifying gaps in existing safeguards, and building a more vigilant organization without letting fear of technology get in the way of growth.
01:22 How an AI-Enabled Fraud Scheme Cost the Company $21,000
03:47 How AI Voice Spoofing Can Bypass Traditional Verification
12:24 The Four Safeguards Every Business Should Review After a Fraud Attempt
14:45 Cyber Fraud Insurance and Social Engineering Coverage Explained
16:20 How Much Cyber Fraud Coverage Should Your Business Have?
17:49 Why Ongoing Employee Training Is Critical as AI Threats Evolve
19:13 Rock Your Business: Scaling from $50 Million to $500 Million
21:11 Rapid-Fire Questions: AI Fraud, Risk, and Leadership
https://www.autobahnconsultants.com
Jonathan’s Book:
Rock Your Business
https://www.amazon.com/dp/1544551851
Linda’s LinkedIn: https://www.linkedin.com/in/lindafanaras/
Millennium Agency: Brand Strategy | Marketing | Web Design: mill.agency
YouTube Channel: https://www.youtube.com/@mill.agency
Linda’s Books:
Claim Your White Space
https://www.amazon.com/CLAIM-YOUR-WHITE-SPACE-CRITICAL-ebook/dp/B0CLK8VLYV
Passion + Profits: Fueling Business And Brand Success
https://www.amazon.com/Passion-Profits-Fueling-Business-Success-ebook/dp/B0CLLDDSNX/
Linda:
Welcome to the B2B Brand180 Podcast where we just don’t talk about growth. We challenge the assumptions behind it. I’m Linda Fanaras, CEO of Millennium Agency and your host today. Today I’m joined by Jonathan Slain. I’m very excited for him to come in today. He advises middle market companies in the $50 to $500 million range and beyond. He helps them scale through recessions, disruptions, and now a new layer of risk, AI-enabled fraud. So listen up if you really want to learn a few things today. So earlier this year, his own company was hit by a sophisticated fraud attempt. Bad actors got into their system, spoofed the voice of a trusted team member, something you wouldn’t expect, and convinced his team to send $156,000 payment for a client that didn’t exist. They recovered most of it, but the lesson still cost $21,000. And it changed how Jonathan thinks about risk, systems and leadership.
He also has a new book called Rock Your Business, which we’re going to cover in another podcast in more detail, which he co-wrote with 21 members of his team and he now works with CEOs and leadership. So I’m really glad to have you here today, Jonathan. I think this story will resonate with a lot of industry today because we’re all facing this and we’re all just a little scared about what could happen with AI. So thank you again for coming in, Jonathan. Anything else you want to add that I may have missed?
Jonathan:
No, I love this opportunity to be on the show. The lesson that I wanted to talk about today cost me $21,000, so want to get my money’s worth out of being able to share it with the audience, that’s for sure.
Linda:
That’s awesome. All right, so let’s just call this out. So most companies don’t get burned by fraud because they’re careless. They get burned because of the bad guys that are using AI faster than leadership is actually keeping up with it. So I’d love for you to get started, tell your story a little bit.
Jonathan:
For sure. And I want to start out with defending us and just saying I don’t think that our AI policies were even weak. It was just that they were expired. They were just outdated with everything that’s happening in the market and all the changes and the transformation that AI is bringing for good and for bad. That’s what happened. But it was back in February. It was right after President’s Day. I remember taking the long weekend with the family and I was a little lax in checking our business bank accounts because of the holiday. The bad guys probably know that, so it’s a smart time to attack. But logged into check our bank accounts and the balance looked low. It was lower than I expected. It was actually four transactions that totaled $156,000 for debits that had gone out of our account. And so at first, the stages of grief that you go through.
So at first there was some denial and I was looking for an explanation. I was like, “Well, maybe it was one of those double payroll months or maybe we had some special payment that went out that I forgot to account for.” But I immediately called our accounts payable person and just asked what was going on. And her response was that she had sent the four payments I had asked for over the past week, just as I’d asked for them. She was like, “I double checked it. You emailed me to send out the payments to that new vendor of ours.” And that’s that sinking feeling in my stomach hit because I was like, “Hmm, pretty sure we don’t have any new vendors who I wanted to send $156,000 to over the past week here.”
So in digging through it, the bad guys had gotten into our system and the first thing that they did we learned afterwards was that they put my email in what the tech people call a sandbox. So I wasn’t seeing all the emails that were purportedly going out from me to the rest of the team.
And so if you looked in my sent items, I couldn’t see any weird looking emails. It was only later that we figured out how they did that. And so these requests went to our team member and ultimately she asked the bad guys to verify their information. They sent her a phone number to call. She called it and it sounded like one of our other team members giving permission for her to make those transfers. And so I believe that they were using AI to spoof the voice of one of our other team members to make it sound as if they were approving these transactions since they were large amounts for our business at least.
Linda:
That’s amazing because this is the moment I think every CEO just dreads because in your case you have some solid policies, you set up sort of a backup to verify the spend, you set those limits on the payments. So it’s like your team did the right thing.
Jonathan:
Yeah. I mean that’s the thing here. We’re in the consulting business. We have these conversations with other teams all the time to make sure that we’re doing all the double checks before large amounts of money transfer. And we were just behind because the bad guys figured out a way to get ahead of what was at the time best practice for verification. In the aftermath of it, a couple of things happened. I called my insurance company and they were like, “Yeah, you should really have cyber fraud insurance with social engineering coverage.” And we were like, “Well, yeah.”
Yeah, I mean, exactly. It’s a great time to share this with me now, but social engineering is the industry term we learned for when the bad guys create a situation, they socially engineer a situation to trick you into doing something that you wouldn’t have done otherwise. So basically, I guess the insurance form of protecting you from entrapment. And the insurance companies don’t love social engineering coverage, I don’t think. So it’s not like they’re front and center with offering it. They were able to find some small portion of our property insurance that had a $10,000 limit. So good news, instead of losing 156, it was more like 146. We were going to be able to get a little bit of a return there. But now we have plenty of social engineering coverage. And I recommend after going through this that our audience, your audience, carry five to 10% of revenue in cyber fraud insurance with social engineering.
So that means for a $50 million business, they should really have at least five million of coverage because often these kinds of losses can be five, 10% of revenue. They can be big amounts fast. So talked to insurance, that wasn’t very fruitful, except now we have much better insurance than we did before. Talk to the bank next. And the bank was like, “Yeah, you really should have two people that have to verify every ACH going forward.” And it’s a product that the banks offer, a fraud protection product. And I think I had gotten an email from the bank and maybe even talked to my business banker and they had mentioned it in passing. But again, looking back, the bank mentioned so many different products, Linda. I feel like they’re always trying to sell me credit card protection or debit protection or this or that. And when it happened, I was frustrated that my business banker didn’t drive over to my office and shake me and force me to have that coverage, but we though we were so ahead of it. We were like, “Well, any large amounts, we have AP call and verify them. What else do we need to do?”
Linda:
Yeah. Did they recommend on the ACH just any size or only a high amount?
Jonathan:
Yeah, great question. Depending on the bank, they have different. Some banks will let you set a threshold so that transactions over 1,000, 10,000, 100,000, whatever’s appropriate for your size business need dual verification. I don’t believe that our bank allows that. So it is annoying that every ACH, even the ones for 50 or $100 need double verification, but now we have that. So now we have the better insurance, we have the better banking. And the third thing was that we have a great managed service provider that looks out for all of our computers and making sure that all of our security is there. In debriefing with them though, they were like, “Hey, we were two weeks out from a patch that would’ve prevented the bad guys from getting into your systems.”
And the issue there is that if they do early patches, and they explained all this to me after, I didn’t really understand at the time, but if we do early patches, you would’ve had to renew your Microsoft license two weeks early and then you would’ve lost out in two weeks. And so yes, knowing what I know now, that would’ve been cheaper, but ordinary run of business, they usually don’t renew your licenses early. So we’re in a better place now. And then the last one is that, Linda, probably the place that I would take the most responsibility as the founder CEO is I don’t think we had done a good enough job of training and retraining our team on what was possible and just making sure we were all staying as vigilant as possible.
Linda:
Yeah, that’s a great point. I guess the uncomfortable truth is AI doesn’t just fake data, fakes people. So they can mimic and it’s becoming more obvious, especially in business and in these instances when they can actually mimic the voice of someone you trust.
Jonathan:
This happened back in February of this year. Now fast-forward, we’re seven or eight months later, it’s getting close to being able to mimic video in very realistic ways. So what happens when somebody thinks they’re on a video call with you and it’s spoofed AI Linda or spoofed AI Jonathan? That’s I think where a lot of this is going. So again, it’s just training the team to be able to think about what’s possible and evolve as quickly as the technology is and not be remiss about it.
Linda:
No, I mean in your case, it’s like the email looks real, the voice sounds real, the process is followed, the money’s gone before anyone knows there’s even a problem. So it can be scary. So it’s kind of like I think a big wake-up call for any business that’s out there. And I’m glad you were able to at least recover the majority of what you have. That’s the happy ending to the story is that we did file with the FBI like you’re supposed to. You give them all your paperwork. It was a very unsatisfying experience. You submit the paperwork to the FBI and after filling out an application or a form that takes a couple hours, you hit submit and it just goes, “Thank you for the form. You’ll probably never hear back from us.” It doesn’t say those exact words, but basically it’s like you might hear back from us in 12 to 16 weeks and you probably will never hear back.
And Linda, it’s the craziest thing. We didn’t hear anything. Two months later though, I’m checking my bank accounts because now I’m every morning and there was about $120,000 was returned and we contacted the bank just to confirm. I wanted to go to the bank and just take it out in cash and just before they found their mistake, they had able to recover part of the funds. So between that and the small bit we got back from insurance, it’s a $21,000 lesson that I can share instead of. If it was still $156,000 loss, I’m not sure I could tell the story and still be smiling here.
Linda:
I can’t blame you. I mean, you think about it. I mean, I like the three points that you made. This is really important for businesses to listen in here. Because it was a multi-step process, it’s like one failure point during that approval process doesn’t slow down. It threatens the whole process for any sort of company. So if you have that gap that’s exposed, and that’s where I think AI gets a little scary, I think for companies that need to start to think about, okay, how are they going to protect their assets? How can we make sure nobody gets impersonated within the company? So you talked about the three fixes. Is there anything else that you think would be valuable to our audience?
Jonathan:
The three biggest are checking your insurance, checking with your bank, and then checking with your managed service provider about computer security. And the fourth one that I mentioned briefly is just training your team. I think for me, it’s like we make everybody take a course on a security when they first join the business, and then we promptly don’t do anything to keep up that training. Everybody here rolls our eyes when we have to go through and watch those terrible videos about the hackers and how to not open up and click links on phishing emails. But again, just what we’re trying to do is to have some fun with it. So instead of sending everybody links and then begging them to go watch the videos, we try to bring in lunch, have some fun with it, do the training together, make fun of the training together, but then take it seriously and just make some time to talk about what it looks like.
A lot of our business is helping companies use AI for good. And so for us, it’s just part of our daily flow that we’re also thinking about what are different ways that the bad guys could be using it and how do we protect ourselves? But really, I think just trying to have some fun with it, Linda, making an open conversation at your company is better than just sending everybody a link and then asking them over and over and again if they’ve watched the required videos. That’s not what we’re really after. We’re really after a cultural change. We have to be even more vigilant because we are a pretty careful company. It’s just we are being careful about something about outdated ways of going about it.
Linda:
Yeah. No, great point. So you talked about the social engineering with the insurance. Some things I have never heard of, and I too, like you, am on top of my insurance. So that coverage, I think it’s good for the leaders out there to listen in, maybe take a look at that, see if you have a good solid cyber policy, see if that’s enough. If it’s not enough social engineering, it sounds like that’s an add-on. Is there anything else you think our audience should know when it comes to that coverage?
Jonathan:
The one easy thing to do for the audience would be just take your policy. I know mine’s close to 200 pages. We use ChatGPT, we use Claude, Gemini. I don’t care which AI model you like, just take your policy and drop it in and just ask it what kind of social engineering coverage you have, and then also ask it if it’s got any recommendations for you. And I think you’ll be amazed at the quality of the response. And then you can take that response and forward it to your insurance broker and just ask them what they think. And then it’ll tell you very quickly, it used to be that none of us. I’ll just speak for myself. I don’t know about your audience. Maybe they were reading the 200-page insurance documents that they got. Personally, I probably was a little lax going through every page, but now the great thing about AI is it just democratizes all of our ability to understand so much clear what is in those documents and just have more say in the process.
Linda:
Yeah, that’s great. I mean, it’s not necessarily about buying more insurance, it’s just buying the right insurance and finding out what they do have and don’t have, because I think that’s one of those things that business leaders may just buy without really completely getting a full understanding of what the coverage is. But I do love the multi-step approvals processes that you put into place even though they were in place, but having to make sure to put these processes in place so people are not getting tricked. You also mentioned a percentage, I think, of revenue, what you would recommend. Can you just go back to that a little bit?
Jonathan:
Yeah. In conversations back and forth with Claude, it’s about five to 10% of revenue is where I think companies should be for their cyber fraud protection. And then for social engineering, that could be a sub limit underneath your larger cyber fraud policy. And again, I’m not an insurance agent, so you should all talk to your brokers and figure it out. But I think, again, the reason for social engineering is that I don’t think most of us can know or can figure out or stay ahead of the bad guys. That’s what makes them the bad guys. I would like to ensure that risk that they will probably be a step ahead of me. And so no matter what they come up with next to trick me or to potentially trick the audience, that’s where I think insurance can be especially valuable to cover.
Linda:
Yeah. And to your point, I think training seems to be one of those things instead of, like you said, sending out an email, really having an intentional training process and collaborative training process so people are really learning and understanding how serious it can be. I mean, it’s an expensive lesson, right?
Jonathan:
Yeah. I think in your business, I think a lot of it is it’s more fun when you need to do a new creative brainstorming to probably get everybody in the firm together to bring in, to get Taco Tuesday and have everyone do a creative brainstorming together. And some of our other clients, they are sales-focused organizations and they like to do a power hour where if we’re going to do cold calls, let’s get everybody together. Let’s do all the cold calls together. Nobody likes doing it, so some shared misery can make it go better. And similarly here, nobody really likes doing their cybersecurity online training. So again, if we can do that together and get some cultural build out of it, I think that’s a nice way to move it forward and advance it.
Linda:
No, that’s great. And then inside your book, you really talk about this in more detail, which like I said earlier, we’ll cover that in another podcast, which I’m also looking forward to, but maybe you can just give us a quick synopsis of the book and what’s inside.
Jonathan:
Sure. So Linda, at the end of June of this year, we published Rock Your Business, and this is our second book in the Rock series. So we published Rock the Recession, and now we’re back with Rock Your Business. And it’s really what we’ve learned about how companies can grow from 50 million to 500 million. So for the companies in your audience that are either aspiring to get to 50 million or at 50 and want to go beyond towards 500 million, it’s everything we’ve learned over the past decade. And it’s not just me talking. I figured that would bore people. So we actually, our firm, Audubon, has 21 team members here, and we all got together and teamed up. So 10 teams and each team wrote a chapter in the book. And then I do some of the intros to the chapters just to bring it together.
Linda:
No, that sounds great. I’m sure that was probably a good exercise. So it’s probably a great team building exercise in addition to actually being able to publish something of value to the audience.
Jonathan:
Yeah, we had a lot of fun with it, and it goes back to a lot of people. We shared our bucket lists with each other at Audubon, and we discovered a lot of people had it on their bucket list to publish a book. And we were like, okay, well, that seems like one we could knock off together. So we were able to have some fun writing it. And then probably the most fun was that we decided to all go to the studio and read our own chapters for the audiobook. So if you’re more into audiobooks than you are a book book and reading it yourself, that can be a fun way because you can hear accents. You’ve got my flat Midwestern nasal accent that you get to enjoy. We’ve got some South Africans on the team, some Mexicans on the team. So a lot of different fun accents while you’re listening to Rock Your Business.
Linda:
No, that’s great. And like I said, we’ll cover that, so I’m looking forward to that. So I’d love to do some rapid fire questions. You can answer them in a sentence or two.
Jonathan:
Great. Let’s do it.
Linda:
Alright. The biggest myth leaders believe about AI-enabled fraud.
Jonathan:
The biggest myth is that they’re immune. So speaking for myself, I thought I was really ahead of it. It’s a lot of our business. I never thought the bad guys could trick me. So the myth is thinking that we’re immune to it.
Linda:
Yep. Okay. Awesome. The wrong fixed companies throw at a fraud and structure problem.
Jonathan:
Yeah, I think it’s not necessarily a process solution. So there are some process steps you can take, but I think this one comes back to the people. And so again, for me, it’s what could we do to better train our people and not necessarily just fix our process because I think that the bad guys will be able to keep attacking the process. We need vigilant people.
Linda:
Okay, great. And one question every CEO should ask before approving the next large payment.
Jonathan:
The question there is just, do I know what this is? Have I done my due diligence? And then I’m also a big fan, like I said, of using AI to help now as a double check. So using AI on your own side to double check things going out helps avoid fatigue. Because if you’re in the midst of approving lots of payments, how many good decisions can you make in a row? I think the AI can really help us because AI doesn’t get tired. It doesn’t have bias. It doesn’t have emotion.
Linda:
Yeah, that’s great. So Jonathan, this is a real shift. I think it’s because it’s not about getting paranoid about technology. It’s about recognizing AI and it’s changed the risk game quite a bit with everybody’s systems and training and accounting. So I would love for you to share how individuals can get in touch with you and also mention your book again. That would be great.
Jonathan:
Sure. Our website is autobahnconsultants.com, spelled just like the highway in Germany. So autobahnconsultants.com. And the book is Rock Your Business. It’s available on Amazon. And those are the two best ways to learn more about us and to get in touch.
Linda:
Awesome. Well, you heard it today from Jonathan Slain. There’s a lot of great tips in here. Definitely listen to it twice, three times to make sure you get everything out of this episode. And if you like what you heard today, hit like, share, comment, or subscribe.



