5 min read
Seven harm areas, nine months of disrupted operations, and one uncomfortable conclusion. That is the short version of Anthropic’s September 2026 threat intelligence report, which documents how criminals tried to misuse AI between December 2025 and August 2026. Scams and fraud sit right alongside cyberattacks and fake news networks, including AI-operated fake personas and automated social engineering (tricking people into handing over money or access).
The line that should get every solo owner’s attention: AI has erased most of the gap in skill and staffing that used to separate a large, organized operation from a single person working alone. In plain terms, one scammer can now run the kind of campaign that once needed a team. Your business does not need to be big to be worth targeting. It just needs a bank account and an inbox.
The good news is that most defenses are simple, cheap, and fast. Here are nine you can put in place this week, most in under 20 minutes each.
Nine quick wins that make you a harder target
1. Create a “call back” rule for any payment change
AI can now write a flawless email that looks exactly like your supplier or your accountant. So stop trusting the email. Any request to change bank details, pay a new invoice urgently, or buy gift cards gets verified by phone, using a number you already had, not one in the message. Write the rule on a sticky note by your desk. Time needed: two minutes.
2. Agree on a family or team code word
Voice cloning (software that copies someone’s voice from a short recording) means a panicked call that sounds like your partner, your assistant, or your biggest client may not be them. Pick a code word with the few people who could ever ask you for money or access in a hurry. If the caller cannot give it, hang up and call back.
3. Turn on passkeys or an authenticator app everywhere money lives
Text message codes are better than nothing, but they can be intercepted. Switch your bank, payment processor, email, and domain registrar to a passkey or an authenticator app. Start with email: whoever controls your inbox can reset almost every other password you own.
4. Put a spending cap on every AI and API account
One analysis of the Anthropic report summed up a key pattern simply: for many attacks, the API key is the loot. An API key is the password that lets software use an AI service on your account, and a stolen one can rack up large bills fast. If you have ever created one for an automation, log in, set a monthly spending limit, and delete any key you no longer use.
5. Never paste keys or passwords into shared docs or AI chats
Search your Google Drive, Notion, or Dropbox for words like “password”, “API key”, and “login”. Move anything you find into a password manager. This also applies to AI assistants: treat a chat window like a postcard, not a vault. Our guide to what solo owners get wrong about putting business data into AI covers the rest of this habit.
6. Keep the approval step on every AI agent
Agents that can send emails, post content, or spend money are useful precisely because they act for you. That is also what makes them a target. Keep approval required for anything that sends, pays, or shares, at least until you have watched the agent behave well for a month. We stress-tested the idea of fully hands-off agents in AI Agents for Solo Owners: 5 Common Beliefs, Stress-Tested.
7. Audit which apps can reach your accounts
Every “Sign in with Google” or “Connect to Shopify” button creates a door. Once a quarter, open the connected apps page for your Google account, Microsoft account, and payment processor, and remove anything you do not recognize or no longer use. Ten minutes, and it closes doors you forgot you opened.
8. Slow down anything that feels urgent
Almost every scam relies on pressure: an invoice overdue today, an account suspended in one hour, a client who needs a wire before the weekend. AI makes these messages more convincing, but it cannot remove the urgency trick, because the trick is the point. Make a personal rule that urgency triggers a pause, not a payment. Wait 30 minutes and verify through a channel you control.
9. Write a one-page “if I get hacked” card
If something goes wrong, you will not be thinking clearly. Write down, in advance: your bank’s fraud number, how to freeze your payment processor, who hosts your website and email, and where your backups live. Keep a printed copy somewhere other than your laptop.
Where AI helps you defend, not just attack
The same tools criminals misuse can make you safer. A few practical ways to put AI on your side:
- Second opinion on suspicious messages. Paste a suspicious email (with personal details removed) into your AI assistant and ask: “What are the warning signs that this is a scam?” It is surprisingly good at spotting mismatched domains and pressure tactics.
- Policy drafting. Ask AI to turn this list into a simple one-page security policy for your business, even if your “team” is you and a part-time contractor.
- Practice drills. Have AI write three realistic fake phishing emails tailored to your industry, then see whether you would have caught them.
Agentic browsers and assistants that act inside your accounts raise their own questions. If you are considering one, read our guide to letting an AI browser act on your accounts first.
Start with the three that matter most
If nine feels like a lot, do these three today, in this order:
- Secure your email with a passkey or authenticator app (win 3).
- Adopt the call back rule for payment changes (win 1).
- Cap and clean up your API keys (win 4).
Together they block the most common and most expensive ways small businesses lose money. You do not need to become a security expert. You just need to be a little harder to fool than the next business on the scammer’s list.
Which of these nine do you already do, and which one will you set up this week? Tell us in the comments. Your answer might be the nudge another reader needs.



