Someone created a fake Gmail account and began contacting my clients while pretending to be me!
As someone who works in the digital world every day, I understand the importance of online security. But recently, my own business became the target of something that was both alarming and eye-opening.
Yep! I repeat… someone created a fake Gmail account and began contacting my clients while pretending to be me.
The emails appeared to come from someone impersonating my business and were sent to people I have genuine professional relationships with. The messages requested urgent web services and payment, attempting to exploit the trust my clients have built with me and my business.
Artificial Intelligence is increasingly being used to automate phishing, impersonation and online fraud.
And, it’s something every small business owner should be aware of.
AI Has Changed the Face of Phishing
Most of us know what traditional phishing emails look like.
- Poor spelling
- Strange grammar
- Generic greetings
- Obvious scams
For years, spotting phishing attempts was relatively straightforward.
But Artificial Intelligence is changing that.
Cybercriminals can now use AI to automate much of the lifecycle of a phishing attack — from gathering publicly available information online to creating convincing, personalised messages at scale.
Instead of sending thousands of identical emails saying:
“Dear Customer, please click here urgently…”
Modern attacks can potentially be tailored to look far more convincing.
They can include real names, genuine businesses, job roles, services and relationships.
And that’s what makes them so dangerous.
Your Digital Footprint Could Be Giving Criminals More Information Than You Think
Businesses are encouraged to have an online presence.
We build websites. We share news. We celebrate clients. We post on social media. We connect on LinkedIn.
All of this is perfectly normal — and important for marketing.
But it also means there can be a huge amount of publicly available information about a business and the people it works with.
AI-powered tools can potentially collect and analyse information from sources such as:
- Business websites
- Contact pages
- Team pages
- Client testimonials
- Case studies and portfolios
- Press releases
- News articles
- Social media profiles
- Online directories
Rather than simply collecting a list of email addresses, AI can help connect pieces of information together.
For example, it may be possible to identify:
- Who works for a business.
- Who provides services to them.
- Which businesses publicly work together.
- What services they offer.
- Who might be responsible for payments or accounts.
Suddenly, publicly available information can become a map of professional relationships.
And in the wrong hands, that information can be exploited.
From Data Scraping to Relationship Mapping
Traditional web scraping simply involved collecting information from websites. AI takes this a step further.
Artificial Intelligence can analyse large amounts of data and identify patterns and relationships much faster than a person manually researching businesses.
This is sometimes referred to as Open Source Intelligence (OSINT) — gathering information that is publicly available online.
Imagine a criminal identifying a business website.
They may then be able to find:
- The business owner’s name
- Their services
- Their social media accounts
- Their clients through portfolio pages or testimonials
- Staff members through LinkedIn
- Contact details published online
- Recent projects or announcements
AI can potentially help connect those dots.
The result is a far more detailed picture of a business ecosystem.
This makes impersonation attacks potentially much more targeted than the old-fashioned “spray and pray” phishing emails we are used to seeing.
AI Can Now Write Convincing Phishing Emails
Perhaps the most concerning development is the role of Generative AI.
Historically, phishing emails often gave themselves away because they were badly written.
- Poor English
- Strange wording
- Spelling mistakes
But Generative AI can produce polished, professional emails in seconds.
- It can adapt tone and language depending on the target
- It can create urgency
- It can sound friendly
- It can mimic corporate language
And, potentially, it can create thousands of slightly different versions of the same scam.
This means criminals no longer need to be good writers.
They simply need information.
AI can do much of the rest.
Why Business Impersonation Is So Effective
The most successful scams don’t necessarily rely on sophisticated technology.
They rely on trust.
If you receive an email from a random person asking for money, you’re likely to be suspicious.
But what if the email appears to come from:
- Your web designer
- Your accountant
- Your supplier
- Your boss
- Your bank
- A colleague
- A company you regularly work with
Immediately, the request feels more credible.
Add a sense of urgency and the chances of someone acting quickly increase.
“Can you pay this today?”
“This needs sorting urgently.”
“Please use these new payment details.”
“Can you deal with this immediately?”
This is known as social engineering — manipulating people into taking action by exploiting trust, urgency or authority.
AI has the potential to make these attacks faster, more personalised and significantly more convincing.
The Danger of the Fake Email Address
One of the simplest tricks used in impersonation scams is the use of a similar-looking email address.
In my case, the impersonator used a Gmail address.
This is important because a legitimate business should have clear and recognisable communication channels.
For that reason, I want to make my own policy absolutely clear.
Ambitious Design will only communicate with clients using:
or official communications sent via Mailchimp.
At no point would I use a free email service such as Gmail for professional client communications.
I will also never change bank details or request an urgent payment by email without prior discussion.
If you ever receive a message that appears to be from me but you’re unsure about it, please stop and contact me directly using a trusted contact method.
The Old Advice About Phishing Still Matters — But It's No Longer Enough
For years, cyber security advice has told us to look out for:
- Bad spelling
- Poor grammar
- Strange wording
- Generic greetings
That’s still useful advice.
But we can no longer rely on it.
AI can write better emails than many humans.
A phishing email can now be polite, well-written, grammatically correct and personalised.
So instead of asking:
“Does this email look suspicious?”
We increasingly need to ask:
“Does this request make sense?”
That small shift in thinking could prevent a serious security breach.
Always Verify Unusual or Urgent Requests
One of the most effective ways to protect yourself is surprisingly simple.
Verify important requests using another method of communication.
If you receive an unexpected email requesting:
- Payment
- A bank transfer
- New bank details
- Password changes
- Login information
- Urgent action
- Sensitive business information
Don’t simply reply to the email.
Instead, contact the person or company separately using a phone number or email address you already know and trust.
For example, if you receive an email from a supplier requesting payment, instead of replying directly to that message, call the supplier using the number on their official website.
It takes two minutes.
But it could save thousands of pounds.
How to Report Phishing and Scam Emails
Knowing how to spot a scam is important. But reporting it is just as important.
Reporting suspicious emails can help prevent other people from becoming victims and may help authorities identify and take action against malicious email addresses and websites.
If You Receive a Suspicious Email
In the UK, suspicious emails can be forwarded to the National Cyber Security Centre (NCSC) at:
You don’t need to be completely certain that an email is a scam. If something feels suspicious, report it.
Before doing so:
- Don’t click any links
- Don’t download attachments
- Don’t reply to the sender
- Don’t enter passwords or personal information
- Forward the suspicious email to report@phishing.gov.uk
The NCSC investigates reports of suspicious emails and can take action against malicious websites and infrastructure.
If You Receive a Suspicious Text Message
You can forward suspicious text messages to 7726.
This is a free reporting service used by UK mobile phone networks.
If You’ve Clicked a Link or Shared Information
Don’t panic — but act quickly.
If you’ve entered a password, change it immediately. If you use the same password elsewhere, change those too.
If you’ve provided bank or card details, contact your bank immediately.
If you’ve downloaded something or installed software after clicking a suspicious link, run a full antivirus scan and contact your IT provider if the device is used for work.
If you have lost money or believe you have been the victim of fraud, report it to the relevant fraud reporting service and contact your bank as soon as possible.
Don’t Just Delete It — Report It
It’s easy to simply delete a suspicious email and move on.
But reporting it could help protect someone else.
The information gathered from reports can help identify malicious email addresses, websites and scam campaigns.
A few seconds of your time could potentially stop someone else from becoming the next victim.
Small Businesses Are Not Too Small to Be Targeted
One of the biggest misconceptions about cybercrime is:
“Why would anyone target my small business?”
The reality is that automation changes everything.
Criminals don’t necessarily need to spend hours researching one large organisation.
AI and automated tools can potentially gather information and generate attacks at scale.
Small businesses may also have fewer dedicated security resources and less formal cyber security training.
That doesn’t mean every small business is vulnerable.
But it does mean we should all be more aware.
Cyber security is no longer something that only concerns major corporations.
Having my own business impersonated has been incredibly frustrating.
Not just because someone attempted to misuse my name, but because these scams exploit something that takes years to build:
Trust.
As a small business owner, your reputation matters.
Your clients know you.
You build relationships.
You communicate regularly.
And that’s exactly why impersonation can be so effective.
This experience has made me think differently about the information we all share online and how AI may increasingly be used to analyse and exploit publicly available data.
AI is an incredible tool.
I use it.
It helps businesses work more efficiently, develop ideas and automate tasks.
But like every powerful technology, it can also be misused.
And unfortunately, criminals are already looking for ways to do exactly that.
The Most Important Thing You Can Do? Pause.
We live in a world where everything feels urgent.
- Emails need answering
- Invoices need paying
- Problems need fixing
But scammers rely on people acting before they think.
So if you receive an unusual request — even if it appears to come from someone you know — pause.
Ask yourself:
- Was I expecting this?
- Does this request make sense?
- Is the email address correct?
- Why is this suddenly urgent?
- Can I verify this another way?
Stop. Check. Verify. Report.
Don’t click.
Don’t pay.
Don’t reply.
Verify unusual requests using a trusted contact method and report suspicious emails.
In a world where Artificial Intelligence can make scams look increasingly convincing, sometimes the best security tool we have is still a healthy dose of human scepticism.
A Final Message to My Clients
Following this incident, I want to reassure all Ambitious Design clients that I take the security of my business communications seriously.
I will only contact clients from info@ambitious-design.co.uk or through official Mailchimp communications.
I will never use a Gmail address for professional business communications.
I will never change bank details or request urgent payment via email without prior discussion.
If something doesn’t feel right, please trust your instincts.
Stop. Check. Verify. Report.
Contact me directly using a trusted contact method.
Because protecting your business isn’t just about technology.
Sometimes, it’s about taking a moment to question whether something is really what it appears to be.