Small business owner reviewing payment security and fraud alerts on a point-of-sale system
Security & Compliance5 min readWeekly briefing

AI Payment Fraud Is Getting Faster. Here’s What Small Businesses Should Check Now

Trailhead Payments EditorialPublished

Reviewed by a Trailhead payments advisor before publication

This is not a new fee or a new PCI rule. It is a reminder that payment fraud is becoming easier to scale with artificial intelligence, which makes basic security habits more important—not less. For a small business, the practical response is to make sure your payment system is supported, staff know how to verify unusual requests, and your processor has clear fraud and account-security controls.

The short version

  • PCI SSC warned on August 31, 2026, that AI is being used to identify vulnerabilities, automate attacks, and scale fraud faster.
  • The FBI’s 2025 Internet Crime Report cited 22,364 AI-related complaints and about $893 million in reported losses.
  • The biggest risk for most small businesses is social engineering, not a direct attack on the card terminal.
  • Practical response: keep equipment supported, enable MFA, train staff to verify unexpected requests, and review statements and fraud reports.

What changed?

On August 31, 2026, the PCI Security Standards Council said artificial intelligence is increasingly being used to identify vulnerabilities, automate attacks, and scale fraud faster than traditional defenses can respond. The Council made the warning ahead of its September North America Community Meeting, where AI and payment security are a major focus.

That does not mean every merchant suddenly needs new equipment or a different processor. It does mean the threat is changing. AI can help criminals produce more convincing phishing emails, fake login pages, voice messages, and other social-engineering attempts at greater scale.

The FBI has reported the same broader trend. In its 2025 Internet Crime Report, released in April 2026, the FBI said it received 22,364 complaints involving artificial intelligence, with reported losses of about $893 million. The agency specifically noted that AI can be used to create convincing emails, voice clones, fake identities, and other material used in fraud schemes.

What it means for your business

For most businesses, the biggest risk is not a science-fiction attack on the card terminal. It is a normal business process being manipulated more convincingly.

A manager may receive a realistic email that appears to come from the owner asking for credentials. An employee may get a call that sounds like a processor support representative asking them to “verify” access to the POS. An online store may see automated card-testing attempts—small transactions used to determine whether stolen card numbers still work.

This is why merchant services should be evaluated on more than the quoted processing rate. Ask how your provider handles account access, fraud alerts, chargebacks, terminal updates, e-commerce protections, and support when something unusual happens.

PCI DSS also applies to merchants regardless of size or transaction volume, although smaller merchants often have simpler environments and fewer systems to secure. Your processor or acquiring bank can tell you what validation requirements apply to your account.

What to do next

Start with four simple checks.

If you are not sure what security tools your current processor provides, that is a reasonable question to ask before considering a switch. Trailhead’s approach is to review the setup first and recommend a change only when the change actually makes sense.

  • Keep software and equipment supported
    Make sure your POS terminals, payment software, and e-commerce plugins are still supported and receiving security updates. Old equipment that still processes payments is not automatically safe equipment.
  • Turn on multi-factor authentication
    Enable MFA anywhere it is available for your processor portal, POS administration, business email, and online ordering systems.
  • Give employees a verification rule
    No one should provide passwords, one-time security codes, remote access, or account credentials because of an unexpected phone call, text, or email. If someone claims to be your processor, hang up and call the known support number on your statement or official account portal.
  • Review statements and fraud reports
    A statement review is not only about finding a lower rate. It can also surface unfamiliar fees, new services, chargeback trends, or changes to the way your account is configured.
None of this means you should switch providers. It means it is worth knowing what your own agreement and statement say. Often the right answer is to stay where you are.

Sources and references

Every factual claim above traces back to one of these primary or industry sources.

  1. PCI Security Standards Council Celebrates 20 Years, Brings North America Community Meeting to Vancouver
    PCI Security Standards Council ·
  2. Cryptocurrency and AI Scams Bilk Americans of Billions
    FBI ·
  3. Do small merchants with limited transaction volumes need comply with PCI DSS?
    PCI Security Standards Council

Want a second set of eyes on your payment security, statement, and setup?

Free Trailhead Review™. No obligation.

Get My Free Trailhead Review™

Get payments insights in your inbox

Occasional updates on rate trends, POS shifts, and new Trailhead articles. No spam — unsubscribe anytime.