Your attacker has an AI assistant too — what a security demonstration this month means for the way you approve payments
Every week this column shows what AI can do for a finance team. This week, the other side of the table: researchers used an AI assistant sitting inside a hacked mailbox to map a company, impersonate its chief executive, find a US$247,500 wire transfer waiting for approval, and redirect it. The controls that stop this cost nothing
A company approves a wire transfer to an overseas supplier. The invoice is real, the supplier is real, the amount matches the contract. The only thing that changed is the bank account number, and it changed because an email arrived from the managing director’s own address, in his own phrasing, referring to a thread the two of them actually had a few weeks earlier. Nobody picked up the phone. The money left the island.
On 4 August, during Black Hat week in Las Vegas, the red team at security firm Barracuda published a step by step demonstration of exactly that sequence. What they used to pull it off was not malware. It was an AI assistant, the same kind your business may have switched on last quarter.
For eleven weeks this column has been about pointing AI at your own work. This week, the other side of the table. The tools that make your finance team faster are making fraud faster in the same way, and the gap between those two speeds is where the money goes missing.
Seven steps from one compromised mailbox to a redirected wire transfer, with the AI assistant
doing the work at every stage. (Branded graphic by PGH Consulting, LLC)
What the researchers actually did
The attack began with something ordinary: one employee’s email account was compromised. That is the boring part, and it happens every day through a convincing login page.
What happened next is the new part. Instead of a person reading through months of email looking for something useful, the attackers put the account’s own AI assistant to work. They had it create an inbox rule that pushed sign-in alerts straight to Deleted Items, so the employee never saw the warnings. They asked it to summarise the mail history and map who reported to whom, which surfaced the chief executive as the target worth having. Then they asked it to draft a phishing email in the employee’s natural writing style, referencing a real conversation the two had already had. The chief executive clicked, and a lookalike site sitting between him and the real login page captured his session token, letting the attackers walk past multifactor authentication without ever needing the password.
From inside the executive’s mailbox, they asked the assistant to summarise financial correspondence. It found a wire transfer of US$247,500 awaiting final approval. They had it draft an email asking the finance team to update the recipient’s banking details, added a second rule diverting finance’s confirmation away from the executive, and finished by asking the assistant to delete the messages that would have given the whole thing away.
The demonstration used Microsoft Copilot, and Barracuda was clear that it “applies equally to other widely available AI assistants”. Their own conclusion is worth quoting: the primary risk is not that these tools create new privileges, but that they “dramatically increase the speed, scale and effectiveness with which attackers can exploit the privileges they already obtain”.
Read that again, because it is the whole point. Every step in that chain was possible five years ago. It just needed a patient, skilled human being with weeks to spend understanding your company. Now it needs a prompt.
Fewer people, more access, fewer eyes — set against US$3.05 billion in reported business
email compromise losses and 46.7 million attempted attacks on Jamaica in a year. (Branded graphic by PGH Consulting, LLC)
Why a small finance team is the soft target
There is a comfortable assumption that this sort of thing happens to multinationals. The numbers do not support it.
The FBI’s Internet Crime Complaint Center published its 2025 figures in April. Reported cybercrime losses reached US$20.9 billion, up 26 per cent on the prior year, and business email compromise alone accounted for US$3.05 billion. Of reported business email compromise transactions, 86 per cent moved by wire or ACH, the category you almost never get back. The report also added a formal category for AI-driven crime for the first time: more than 22,000 complaints and close to US$900 million in losses.
Closer to home, this paper reported in July that Fortinet’s FortiGuard Labs recorded 46.7 million attempted cyberattacks against Jamaica during 2025, with a further 5.4 million in the first quarter of 2026 alone. Readers will also remember what followed Hurricane Melissa last October, when the Jamaica Cyber Incident Response Team had to warn the public about fraudulent relief donation websites, with at least 28 identified within days. Criminals here are fast, opportunistic and already working the local context.
A small finance team is attractive precisely because it is small. One person often prepares and approves payments. Supplier bank details get updated by email because that is how they have always been updated. Nobody is watching for a strange inbox rule at nine on a Friday night. US$247,500 is not a rounding error for a business this size.
The break-in was old-fashioned. The acceleration was new. What happened, and what stops it. (Branded graphic by PGH Consulting, LLC)
What AI did not do here, and what it will not do for you
The temptation is to read this and blame the assistant, so it is worth being precise. The AI did not break into anything. The initial compromise was old-fashioned credential theft. The assistant only became dangerous once someone was already inside, and at that point it was doing exactly what it was designed to do: read the mailbox it had been granted, answer questions about it, and write in the voice of the account holder. It had no way to know the person typing was not the person who owned the account.
That cuts both ways for your defences. Multifactor authentication is still worth having, but this attack walked around it by stealing a live session rather than a password, so treating MFA as the finish line is a mistake. No tool on the market will reliably tell your accounts payable clerk that a well-written email from a legitimate internal address is fraudulent, because on every technical measure it is not fraudulent. The account really did send it.
What actually stops this is process, and process is free.
What your assistant is allowed to see
Before switching on an AI assistant across your organisation, ask a plain question: which mailboxes, folders and files can it read, and for whom? Most businesses turn these tools on with default permissions and never revisit them. Broad access to executive mail is a real asset for the executive and a real liability the moment that account is compromised. Grant the narrowest access that still makes the tool useful, and review it when people change roles.
The same logic applies to the accounts themselves. The mailbox that approves money is a financial control, not a convenience, and it deserves the tightest settings in the business: alerts on new inbox rules, short session lifetimes, and a periodic look at who holds delegate access. Ask your administrator to show you those screens once.
Nothing in the last eleven weeks becomes unsafe because of this. Your figures, your verification, your judgement, your signature: all of that still holds. What changes is that the same capability now sits on both sides of the transaction, and the response is not to use less AI. It is to make sure decisions that move money never rest on a single message in a single channel.
Five actions, none of which cost anything, and one standing rule about how money instructions
are confirmed. (Branded graphic by PGH Consulting, LLC)
What to try this week
1. Write down a bank-change rule and circulate it: any change to a supplier, contractor or payroll account is verified by voice, on a number already on file, never a number contained in the email requesting it. Set a value above which two people must sign off.
2. Check inbox rules and forwarding on the accounts that matter: yours, the executives’, and anyone who prepares or approves payments. You are looking for rules that move sign-in alerts, invoices or bank correspondence to Deleted Items or an outside address.
3. Ask whoever administers your Microsoft 365 or Google Workspace to show you what your AI assistant is permitted to read, then cut it back to what each role actually needs.
4. Move your payment approvers off text-message codes to phishing-resistant sign-in, meaning passkeys or a physical security key. These refuse to sign in to a lookalike domain, the exact step that would have blocked the token capture above.
5. Save the Jamaica Cyber Incident Response Team’s details at cirt.gov.jm where your team can find them, and agree now who calls the bank if a payment goes out wrong. Speed of reporting decides whether a wire can be recalled.
No control on this list is a guarantee on its own; passkeys will not protect a session already hijacked by other means, and these work as layers. None of it requires a security budget. It requires deciding, once, that no instruction about money is confirmed on the same channel it arrived on.
Peta-Gaye Hardy is the founder of PGH Consulting, LLC, where she helps finance and operations teams adopt AI in practical, low-risk ways. She writes the weekly AI in Finance & Business column and is based between Jamaica and the United States. Learn more at www.pghconsultinggroup.com. Follow on Instagram and YouTube @pghconsultinggroup, and connect on LinkedIn at linkedin.com/in/peta-gaye-hardy.
Disclosures: This article is informational and does not constitute investment, tax, legal, accounting, or security advice. Readers should consult a qualified professional before acting. The Barracuda research described was published by the company on 4 August 2026 and is summarised here as reported; readers should confirm the current position on the vendor’s own pages. Figures attributed to the FBI’s Internet Crime Complaint Center are from its 2025 annual report, published April 2026, and figures attributed to Fortinet’s FortiGuard Labs are as reported in this newspaper in July 2026. AI tools can produce errors, and every figure, clause, or claim they produce should be verified against a source before being shared or acted upon. The author has no commercial relationship with Barracuda Networks, Microsoft, Google, Anthropic, OpenAI, or any product mentioned and was not compensated by them. All product names, logos, and trademarks are the property of their respective owners and are referenced for editorial purposes. The examples described are illustrative and do not depict any real business.