Issue #3 · July 9, 2026 · 7 min read
Issue #3 — AI voice cloning, fake job listings, and who still has your old logins
This week: a scam that uses a cloned voice instead of an email, why some job postings exist only to collect your personal information, and a 15-minute account clean-up worth doing every quarter.
Advice checked against current FTC and CISA guidance; AI voice-cloning section describes a documented general scam pattern, not a specific incident.
8 sources cited across this issue
top story The Big One: AI voice-cloning scams are targeting business owners
The “grandparent scam” — a panicked phone call claiming to be a family member in trouble — has a business version now, and it’s more convincing because of AI. Tools that clone a voice from a short public sample (a video interview, a voicemail greeting, a podcast clip) let a scammer call an employee sounding exactly like their boss or a company owner, urgently requesting a wire transfer or gift cards “before the bank closes.”
This works precisely because it defeats the advice we’ve given for phone scams for years — “would you recognize a stranger’s voice?” doesn’t apply when the voice is genuinely, audibly the right person. The tell isn’t in how it sounds anymore; it’s in the ask itself.
What it means for you: any urgent, unusual payment request — even one that sounds exactly like you, or your business partner, or your boss, on the phone — needs a second channel of confirmation before anyone acts on it. Voice alone is no longer proof of identity.
What to do: agree on a simple rule with anyone who can move money for your business: any urgent phone request for a payment or gift cards gets confirmed by a callback to a known number, or a message on a separate channel (text, a messaging app), before it’s acted on — no exceptions, regardless of how urgent it sounds or how certain you are it’s really them.
Sources
Checked 2026-07-09 — describes a documented, general scam technique per current FTC consumer guidance; no specific victim or amount claimed.
cyber Threat Radar: fake job postings that exist to harvest your data
Not every scam targets your business’s money directly — some target the personal information of people applying to work for you, or target you as an applicant elsewhere. Fake job listings, sometimes posted using a real company’s name without permission, collect applicants’ names, addresses, bank details (“for direct deposit setup”), and copies of ID — all before any real interview happens. If your business posts jobs online, scammers may also impersonate your company to run this same scheme against unsuspecting applicants, which can damage your reputation even though you did nothing wrong.
What it means for you: as a hiring business, monitor for your company name being used on job boards you don’t actually post to, and never ask real applicants for bank details or ID scans before an offer is made. As anyone applying elsewhere, treat a request for banking information or a fee “for training materials” before you’ve had a real interview as a hard stop.
Sources
Checked 2026-07-09 — matches current FTC guidance on employment scam patterns.
ai AI at Work: what to check before you connect an AI tool to your inbox
AI email assistants that draft replies, summarize threads, or triage your inbox can save real time, but “connect to your email” is one of the broadest permissions you can grant any tool — it typically means read access to your entire mailbox history, not just new messages going forward.
Before connecting one, it’s worth understanding three things the tool’s privacy page or authorization screen should tell you: whether it stores a copy of your email content (versus just processing it in the moment), whether that content is used to train underlying AI models, and whether you can revoke access cleanly if you stop using the tool.
What it means for you: for a general assistant, this trade-off is often fine. For a mailbox that includes legal correspondence, health information, or anything under a confidentiality agreement, treat “connect your email” requests with real scrutiny, and prefer tools that clearly state they don’t retain or train on your content.
Sources
Checked 2026-07-09 — general permissions guidance; no claim made about any specific named AI email product.
privacy Privacy Watch: your phone’s ad-tracking ID, and how to turn it off
Both major phone platforms assign your device an advertising identifier — a code apps can use to recognize you across different apps for ad targeting, similar in spirit to a tracking cookie in a browser. It’s not tied to your name directly, but it can build a detailed picture of your activity over time, and both platforms let you turn it off or reset it.
What it means for you: if you use your phone for business — client calls, reading contracts, managing accounts — reducing ad tracking is a reasonable default, not just a personal preference. It’s a two-minute setting change with no functional downside for how you use your phone day to day.
What to do: on iPhone, go to Settings > Privacy & Security > Tracking, and turn off “Allow Apps to Request to Track.” On Android, go to Settings > Privacy > Ads, and select “Delete advertising ID” or the equivalent opt-out for your Android version.
Sources
Checked 2026-07-09 — setting locations reflect current, standard privacy menus on both major mobile platforms.
action Do This Now (15 min): review who still has access to shared accounts
Shared logins — a social media account, a shared email inbox, a payment platform — tend to accumulate access over time: a former employee, an old contractor, a intern from last summer. Every one of those is a working login you’re probably not thinking about. This week’s task is a quick audit, not a full security overhaul.
- List every shared account your business uses (social media, banking or payment platforms, shared email, file storage, point-of-sale).
- For each one, open its “team,” “users,” or “authorized devices” settings.
- Remove anyone who no longer works with you, and revoke any device or app you don’t recognize.
- For accounts that don’t support individual logins (a single shared password), change that password now and share the new one only with people who currently need it.
- Note the date you did this somewhere you’ll see it in three months, and repeat.
Sources
Checked 2026-07-09 — periodic access review is current CISA/NIST baseline guidance for small organizations.
explainer Plain English: what ‘social engineering’ actually means
Social engineering is the umbrella term for any attack that works by manipulating a person, rather than breaking software. Phishing emails, callback-phishing calls, voice-cloning scams, and fake tech-support pop-ups are all social engineering — they succeed by getting a real person to make a reasonable-seeming decision (click this, call this, pay this) based on false information, not by exploiting a bug in a computer system.
That’s why so much of this newsletter’s advice is about verification habits rather than software settings: no antivirus program stops a scam that talks a person into acting. The defense is procedural — a second channel of confirmation, a callback to a known number, a rule that urgent payment requests always get double-checked — not something you install once and forget.
Sources
Checked 2026-07-09 — definition and framing match current CISA usage.
roundup Quick Hits
- FTC scam alerts — updated regularly with whatever scam pattern is currently trending; worth a monthly glance.
- CISA free vulnerability scanning — a no-cost service that checks your public-facing systems for known weaknesses.
- IC3, the FBI’s Internet Crime Complaint Center — where to actually report it if your business is targeted by a scam, not just where to read about them.
Sources
Checked 2026-07-09 — all three are official, currently active government resources.