
AI Payment Fraud Is Getting Faster. Here’s What Small Businesses Should Check Now
Reviewed by a Trailhead payments advisor before publication
This is not a new fee or a new PCI rule. It is a reminder that payment fraud is becoming easier to scale with artificial intelligence, which makes basic security habits more important—not less. For a small business, the practical response is to make sure your payment system is supported, staff know how to verify unusual requests, and your processor has clear fraud and account-security controls.
The short version
- PCI SSC warned on August 31, 2026, that AI is being used to identify vulnerabilities, automate attacks, and scale fraud faster.
- The FBI’s 2025 Internet Crime Report cited 22,364 AI-related complaints and about $893 million in reported losses.
- The biggest risk for most small businesses is social engineering, not a direct attack on the card terminal.
- Practical response: keep equipment supported, enable MFA, train staff to verify unexpected requests, and review statements and fraud reports.
What changed?
On August 31, 2026, the PCI Security Standards Council said artificial intelligence is increasingly being used to identify vulnerabilities, automate attacks, and scale fraud faster than traditional defenses can respond. The Council made the warning ahead of its September North America Community Meeting, where AI and payment security are a major focus.
That does not mean every merchant suddenly needs new equipment or a different processor. It does mean the threat is changing. AI can help criminals produce more convincing phishing emails, fake login pages, voice messages, and other social-engineering attempts at greater scale.
The FBI has reported the same broader trend. In its 2025 Internet Crime Report, released in April 2026, the FBI said it received 22,364 complaints involving artificial intelligence, with reported losses of about $893 million. The agency specifically noted that AI can be used to create convincing emails, voice clones, fake identities, and other material used in fraud schemes.
What it means for your business
For most businesses, the biggest risk is not a science-fiction attack on the card terminal. It is a normal business process being manipulated more convincingly.
A manager may receive a realistic email that appears to come from the owner asking for credentials. An employee may get a call that sounds like a processor support representative asking them to “verify” access to the POS. An online store may see automated card-testing attempts—small transactions used to determine whether stolen card numbers still work.
This is why merchant services should be evaluated on more than the quoted processing rate. Ask how your provider handles account access, fraud alerts, chargebacks, terminal updates, e-commerce protections, and support when something unusual happens.
PCI DSS also applies to merchants regardless of size or transaction volume, although smaller merchants often have simpler environments and fewer systems to secure. Your processor or acquiring bank can tell you what validation requirements apply to your account.
What to do next
Start with four simple checks.
If you are not sure what security tools your current processor provides, that is a reasonable question to ask before considering a switch. Trailhead’s approach is to review the setup first and recommend a change only when the change actually makes sense.
- Keep software and equipment supportedMake sure your POS terminals, payment software, and e-commerce plugins are still supported and receiving security updates. Old equipment that still processes payments is not automatically safe equipment.
- Turn on multi-factor authenticationEnable MFA anywhere it is available for your processor portal, POS administration, business email, and online ordering systems.
- Give employees a verification ruleNo one should provide passwords, one-time security codes, remote access, or account credentials because of an unexpected phone call, text, or email. If someone claims to be your processor, hang up and call the known support number on your statement or official account portal.
- Review statements and fraud reportsA statement review is not only about finding a lower rate. It can also surface unfamiliar fees, new services, chargeback trends, or changes to the way your account is configured.
None of this means you should switch providers. It means it is worth knowing what your own agreement and statement say. Often the right answer is to stay where you are.
Sources and references
Every factual claim above traces back to one of these primary or industry sources.
- PCI Security Standards Council Celebrates 20 Years, Brings North America Community Meeting to VancouverPCI Security Standards Council ·
- Cryptocurrency and AI Scams Bilk Americans of BillionsFBI ·
- Do small merchants with limited transaction volumes need comply with PCI DSS?PCI Security Standards Council
Related from Trailhead
- Payment and POS equipment Trailhead works withTerminals, countertop systems, and mobile acceptance.
- Compare payment processors and POS systemsNeutral profiles: best for, strengths, things to consider.
- Trailhead Academy: payments educationPlain-English guides to fees, statements, and POS choices.
- Get a Free Trailhead Review™A human advisor reviews your statement and setup.
- Free statement reviewA focused look at your fees, rates, and statement structure.
Want a second set of eyes on your payment security, statement, and setup?
Free Trailhead Review™. No obligation.
Get payments insights in your inbox
Occasional updates on rate trends, POS shifts, and new Trailhead articles. No spam — unsubscribe anytime.
Keep reading

“Zombie Cards” and Tap-to-Pay: What Small Businesses Should Know
UMass Amherst researchers showed that some expired Visa contactless cards could still complete tap-to-pay transactions under specific conditions. It is a real finding — and not a reason to turn off contactless.

Square's August POS Update: What Small Businesses Should Actually Notice
Square's August 13 release added new pricing, tax, booking, inventory, and restaurant workflow controls. The bigger lesson: when comparing payment processors, operational fit can matter more than a small rate difference.