I almost lost one of my companies. Not to a market crash, not to a competitor, but to a fake voice message that sounded exactly like me.
It was a simple, urgent request to my CFO for a wire transfer. The amount was $45,000. Not huge, but not small either. Just under the amount that required my manual sign-off. It was my voice, my intonation, my typical sense of urgency. The only reason the transfer didn't happen was because my CFO had a nagging feeling and called my personal cell. We got lucky. A few minutes later and that money would have been gone forever, wired to an account in Eastern Europe.
The biggest threat to your startup in 2026 isn't running out of cash. It's AI-powered phishing, and almost every founder I talk to is completely unprepared for it.
Everyone is talking about AI phishing, but 99% of what you hear is wrong. People think it's just a slightly more convincing email scam. It’s not. This isn't just a better scam. It's a completely new weapon. I learned that the hard way, and I’m writing this so you don’t have to.
The Day We Almost Wired Away $45,000
Back when I was running RemoteTeam, we were growing fast. We were hiring people all over the world, and our internal systems were a mix of Slack, email, and a dozen other SaaS tools. It was organized chaos. The good kind. The kind that means you're growing fast.
One afternoon, our head of finance got a Slack message from my account. It had my profile picture, my name. The message was simple: "Hey, I'm in a meeting and need you to process an invoice for a new contractor ASAP. Can you handle it? Link in email." An email arrived seconds later from my address with a PDF invoice. It all looked legit.
The scary part? The initial entry point was a junior marketer's Slack account, compromised through a simple phishing link they clicked in their personal email. From there, the AI took over. It had been observing our internal communications for weeks. It learned how I talk, how I delegate tasks, even the emoji I use. It knew I was in a "meeting" because it saw my public calendar.
The invoice was for a real-sounding marketing service. The amount was just under our threshold for secondary approval. It was perfect. Our finance lead was minutes away from sending the money. What stopped him? He remembered a rule I had drilled into everyone: Any payment request, no matter how small or urgent, that comes through a digital-only channel must be verbally confirmed over the phone.
He called me. I had no idea what he was talking about. We dodged a bullet that would have cost us tens of thousands of dollars and, more importantly, a massive loss of trust.
Why 99% of Founders Are Getting It Wrong
When I tell this story, most founders nod along. Then they tell me about their "security training" and their "advanced email filters." That’s the problem. They’re fighting the last war.
Here’s what they don’t get:
- It’s Not Just Email: Forget the Nigerian prince. Adversarial AI uses every channel you do. Slack, Microsoft Teams, SMS, social media DMs, and now, deepfaked voice and video calls. As an investor in companies at the heart of the AI revolution like Anthropic and Scale AI, I see how fast this technology is moving. The tools to create these fakes are getting better and cheaper every single day.
- Your Tools Are Obsolete: The best security filters are trained on yesterday’s attacks. These new threats are what we call "zero-day AI"—models that generate novel attack vectors on the fly. They’ve never been seen before, so there’s no signature to detect.
- Training Isn’t a Silver Bullet: You can’t train an employee to spot a perfect fake. When an AI can replicate your CEO’s voice asking for a password reset, telling your team to "be vigilant" is useless advice. It creates a culture of paranoia that slows everything down.
The Real Threat: Adversarial and Zero-Day AI
Let’s get a bit technical for a second. The attacks I’m talking about aren’t just scripted bots. They are powered by adversarial AI. Think of it as two AIs playing chess. One AI (the defender) is your standard security system. The other AI (the attacker) is constantly probing that system, learning its rules, and creating moves the defender has never seen before.
These attacker AIs are trained on a massive diet of public data—your LinkedIn profiles, your company’s blog posts, your personal social media, breached databases from other services. They learn your relationships, your communication style, and your company’s org chart. Then they craft an attack.
Here’s a common attack flow in 2026:
- Reconnaissance: An AI scrapes LinkedIn and identifies a new junior engineer at your company.
- Personalization: It finds their personal email from a past data breach and scours their social media, learning they just moved to a new city and are excited to start.
- The Hook: It sends a hyper-personalized email from the "Head of HR" (spoofing the real email address) with the subject: "Welcome! Your Day 1 Onboarding Guide." The email mentions their new city and references a post they "liked" on Twitter.
- The Payload: The email contains a link to a fake onboarding portal that looks identical to your real one. The moment they enter their credentials, the AI has access.
- Escalation: Now inside, the AI uses that engineer’s account to observe internal chatter, identify a high-value target (like a finance manager), and prepares the next stage of the attack.
This entire sequence is automated and can be executed at scale against hundreds of companies at once.
My Guide to Actually Surviving AI Phishing
So, how do you defend against an enemy you can’t see? You stop playing by the old rules. You need to build a new foundation based on process and verification, not just technology.
1. Zero Trust for All Inbound Communication
This is my #1 rule. Trust nothing. Verify everything. Any request for money, data, or credentials must be verified through an out-of-band channel. That means if a request comes via email, you verify it with a phone call to a known number. If it comes via Slack, you walk over to their desk or start a video call.
This isn’t about paranoia; it’s about process. It has to be a non-negotiable rule for everyone, from the intern to the CEO. No exceptions for urgency. In fact, urgency is the biggest red flag.
2. Proactive Adversarial Simulation
You can’t wait to get punched in the face. You have to punch yourself first. I’m an investor in two companies that do exactly this. They run sophisticated, continuous AI phishing simulations against our own portfolio companies. They use the same adversarial techniques as the real attackers.
These aren’t the dumb, easy-to-spot phishing tests of five years ago. These are brutal, realistic attacks that regularly fool even the most technical employees. The point isn’t to shame people who fail. It’s to find the cracks in your processes before the real attackers do.
3. The Human Firewall is Your Last Resort
Your people are not the first line of defense. They are the last. Your processes and systems should be so robust that a malicious link is never the single point of failure.
For example, at all my companies, we have a simple rule: any wire transfer over $10,000 requires dual, real-time voice confirmation from two separate executives on a recorded line. It adds 5 minutes of friction. It has saved us millions.
Another example: We use password managers with hardware key (YubiKey) requirements for all critical systems. An AI can steal a password, but it can’t steal a physical key from your pocket.
4. Invest in Defensive AI
The only way to fight an AI is with an AI. A new generation of "defensive AI" tools is emerging. Instead of relying on signatures, they model the normal behavior of your organization and flag anomalies. For instance, it might learn that your CFO never approves wire transfers after 8 PM on a Friday. So when a request comes in at 8:05 PM, it gets automatically flagged and locked down, even if it looks legitimate.
These systems are the future. They act as an intelligent immune system for your entire organization.
Your Wake-Up Call
Stop thinking about AI phishing as a nuisance. Start thinking of it as the most sophisticated and dangerous threat your company will face. The barrier to entry for attackers is now zero. Anyone with a few hundred dollars can rent a powerful adversarial AI and launch a campaign.
I wrote my book, Becoming Top 1%, for engineers who want to build great things. But you can't build anything if your foundation is rotten. Securing your company isn't someone else's job. It's your job. Don’t be one of the 99% of founders who are caught off guard. Your company’s survival depends on it.
Frequently Asked Questions
How should I work through this guide?
Don't try to absorb everything in one sitting. Read through once to get the big picture, then go back and work through each section as it becomes relevant to your current challenges. Bookmark it and return to it regularly.
What if I disagree with some of the advice?
Good. That means you're thinking critically, which is exactly what a good founder should do. Take what resonates, test it, and discard what doesn't work for your specific situation. No advice is universal.
How often is this guide updated?
I revisit and update my guides regularly as I learn new things and as the market evolves. The core principles tend to stay stable, but specific tactics and tools get refreshed based on what's working right now.
Is this guide based on real experience?
Every recommendation in this guide comes from direct experience, either from building and selling my own companies, or from patterns I've observed across 200+ angel investments. I don't write about things I haven't personally tested.