The email is sitting on your office manager's screen right now, and there is nothing wrong with it.
It comes from your steel supplier. It uses your rep's name, the one who has been walking through your door for six years. It references a PO number for a job you actually have running and a delivery date you actually agreed to. The spelling is clean, the tone is right, and the signature block matches down to the cell number. Halfway down, it mentions that they switched banks over the summer, and asks that this invoice go to the account listed below.
She pays it. Everything about it was right.
Three weeks later the real past-due notice shows up for the same invoice, and the money is sitting in an account nobody can trace. Nothing on your floor broke. Nobody clicked a virus. The shop simply paid the wrong bank, because the message that told it to looked exactly like every other message that supplier has ever sent.
That is why the old advice about how to spot a scam email no longer protects anybody. For twenty years the tell was bad spelling and clumsy grammar, and now the tell is gone.
The numbers say the rest. The FBI's Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025 with $3.046 billion in reported losses, which works out to roughly $123,000 per complaint filed. The same 2025 IC3 Annual Report added an AI-related category for the first time, covering 22,364 complaints and about $893 million in losses. Your shop does not have to be singled out to end up in that column. It just has to pay invoices like everybody else.
Here is the plain-English version we walk through with shops around Parkesburg and across Chester and Lancaster County.
Why the Spelling Test Stopped Working
The spelling test worked for a boring reason: a lot of these messages used to be written by people working in a language that was not their own, and the seams showed. Teaching people to look for the seams was cheap, fast, and effective.
AI removed the seams. The UK's National Cyber Security Centre assessed that generative AI already lets attackers produce convincing lure documents without the translation and grammar errors that used to reveal phishing (Impact of AI on cyber threat). The FBI has said the same thing about criminals in the United States. Both agencies expect more of it, not less.
So the one thing your team was trained to watch for tells them almost nothing now. Worse, it works backwards: a clean, professional email reads as more trustworthy to somebody who was taught that scams look sloppy. AI phishing emails do not just slip past the old rule. They exploit it.
Three things changed at once:
- The writing is clean. A machine drafts it in seconds, in whatever tone the attacker asks for.
- It is specific to you. Your website, your team's LinkedIn profiles, a trade listing, or an equipment announcement give an attacker the names, the titles, and a believable reason to be in touch.
- There is far more of it. Each message costs the attacker almost nothing to produce, so they send volume.
Why Your Shop Is an Easy Target for a Fake Supplier Email
Owners tend to assume attackers chase big companies with big balances. The opposite is true for this particular scam, because what it needs is not a big target. It needs a predictable payment routine and a small office.
A 20-person machine shop offers both:
- You pay real invoices to a short list of real suppliers every single week: material, tooling, coatings, heat treat, freight.
- Your purchasing, shipping, and quality paperwork all move by email, so a PO number or a job reference in a message looks completely normal.
- The office is one or two people. There is no accounts payable department, no second approver, and nobody whose entire job is to be suspicious.
- Your shop runs second and third shift, so email gets read at hours when nobody can walk down the hall and ask somebody.
The scam has a name, and it is worth knowing because it is what your insurance policy and your bank will call it: business email compromise. When the message impersonates a supplier and targets an invoice payment, it is invoice fraud, and it is the version that hits manufacturers hardest. A fake supplier email does not need to breach anything. It needs one person to believe a bank changed processors.

How to Spot a Scam Email When the Writing Is Perfect
If you cannot judge a message by how it reads, judge it by what it wants. That is where the real signals live, and AI has not changed a single one of them.
Teach the office to stop at any message that does one of these:
- Asks to change bank details, routing numbers, or where an invoice gets paid. Treat this as invoice fraud until a phone call proves otherwise. No exceptions, no matter how well you know the sender.
- Asks for a payment to a new account, a gift card purchase, or a wire that is not on the normal schedule.
- Asks for a login, a password reset, or a verification code. Nobody legitimate needs your MFA code.
- Applies pressure. A deadline, a threat, a shipment supposedly on hold, or a "before you leave today."
- Carries a link or attachment you were not expecting, including a shared document you did not ask for.
- Shows a display name that does not match the real address behind it. Have your team check the actual address and the reply-to field, not the friendly name.
Every one of those is about the request, not the prose. So the rule that fits on an index card by the phone is this: when a message involves money, logins, or how you pay somebody, slow down and confirm it another way.
That is the whole answer to how to spot a scam email in 2026. It is less about inspecting the message and more about having one habit that the message cannot talk you out of.
Your Spam Filter Will Not Catch Them All, and Neither Will Caller ID
Filtering is worth having and you should keep it on. It kills the high-volume junk before anybody sees it.
But a well written, personalized message with no attachment, no malicious link, and a perfectly ordinary business question does not look dangerous to a filter. There is nothing technical in it to catch. It is a normal email that happens to be a lie, which is exactly why this scam keeps working against companies that already bought security tools. If you are sorting out where your other layers sit, the difference between antivirus and EDR is a useful place to start, but understand that neither one reads intent.
The same goes for the phone. The FBI has warned that a short audio clip is enough for criminals to clone a voice, which means a voicemail that sounds like you asking the office to release a payment is now within reach of an ordinary crook. Caller ID has never been proof of anything, and now the voice is not either. If a call or voicemail is about money or logins, hang up and call back on a number you already had.
The Rules to Give Your Office This Week
None of this requires new software. It requires six decisions.
1. Confirm every payment change by phone, on a number you already have
Any change to bank details, routing, or a payment address gets verified by voice, using a number from your existing records. Never a number from the email, and never a reply to the email. This one rule stops most invoice fraud on its own.
2. Retire the spelling test
Tell the shop directly that scam emails read perfectly now. If your last training said otherwise, correct it out loud, because people are still running that old checklist in their heads and passing everything that spells correctly.
3. Put a second set of eyes on new bank details
Two people sign off before any new account gets paid the first time. In a small office that is the owner and the office manager. It costs a two-minute conversation and it removes the single point of failure.
4. Turn on MFA everywhere, and use the phishing-resistant kind where you can
Passkeys or an app-based prompt beat texted codes. A stolen password should not be enough to read your quoting history or send mail from your own domain. Your carrier is going to ask about this anyway.
5. Lock down your own domain
The flip side of this problem is attackers using your shop's name to bill your customers. SPF, DKIM, and DMARC are the records that stop scammers from sending email in your shop's own name, and most small manufacturers have never had them set correctly.
6. Make reporting easy, and keep phishing training short and regular
Nobody should feel foolish for asking. The office manager who forwards a legitimate invoice to be double-checked is doing the job right. Fifteen minutes of phishing training once a quarter, plus an occasional test message to the people who handle payments, keeps it current without costing a shift.
What This Has to Do With Your Renewal Application
Every item above shows up somewhere on your cyber insurance application: is MFA enforced, do you train staff, do you have a verification process for payment changes. Carriers have stopped taking a checkbox as an answer, and the same questions land again on the vendor security questionnaires that Tier-1 customers send.
There is a sharper reason to care. If money does go out the door to a fake account, coverage for that loss usually sits under a separate social engineering or funds transfer fraud sublimit, and it is often a fraction of your headline policy limit. Some carriers also expect you to prove you had a callback procedure. It is worth reading what cyber insurance carriers now expect from manufacturers before renewal season, not during it. We put together a cyber-insurance compliance package for exactly this reason: the MFA, training, and payment-control answers documented once, in a form you hand to your broker.
How to Spot a Scam Email: FAQs for Small Manufacturers
Can you still spot a scam email by bad spelling and grammar?
No, not reliably. Attackers use AI to write their messages now, so a scam email can arrive with clean spelling, correct grammar, and the right industry vocabulary. Judge the message by what it asks you to do instead: money, bank details, logins, or urgency. Those signals have not changed.
What are the warning signs in a scam email that still work?
The request itself. Watch for anything that asks you to change bank or routing details on an invoice, pay a new account, send gift cards, hand over a password or verification code, or act before a deadline. Also check whether the real address behind the display name matches the supplier you deal with.
Will our spam filter stop AI phishing emails?
It stops a lot, and you should keep it on. But a well written, personalized message with no attachment and no obvious bad link often looks like ordinary business mail to a filter. That is the whole design of business email compromise. Treat the filter as one layer and a trained office as the backstop.
How often should a small shop run phishing training?
Once a quarter for 15 minutes, plus a simulated phishing email once a month for anyone who touches payments or purchasing. That is enough to keep it current without eating a shift. Four short sessions a year beat one long annual meeting nobody remembers by March.
Someone in our office already paid a fake invoice. What do we do first?
Call your bank immediately and ask them to recall the wire or ACH, then report it at ic3.gov. Speed decides everything here. The FBI's recovery team has the best odds inside the first 24 to 72 hours, and the odds drop sharply once funds move overseas. Tell your IT provider and your insurance broker the same day.
Does cyber insurance cover money wired to a fake supplier?
Sometimes, and usually not under your full policy limit. Many policies handle this under a separate social engineering or funds transfer fraud sublimit that is much smaller than the headline number, and some require documented payment verification controls. Ask your broker to show you that specific sublimit and its conditions before you need it.
Would Your Office Catch One?
Starlux IT provides managed IT built for manufacturers across Chester and Lancaster County: job shops, fabricators, and every machine shop in Parkesburg, Coatesville, Downingtown, Gap, and the surrounding towns. Our techs are local and on-site the same day, and our monitoring covers the second and third shift hours when the office is empty and email still gets read.
If you are not sure whether your office would catch a fake supplier email, or whether your MFA and training would hold up on your next renewal application, let's spend 30 minutes on it. Free, no pressure. We'll look at what you have, show you the gaps, and you'll know exactly where you stand, whether you hire us or not.