← Back to all posts A glowing amber envelope shaped like a baited fish hook hangs over a small figure at a desk while a teal shield of light rises between them, blocking it

My AI caught a phishing attempt dressed up as a $20K client

Yesterday a new enquiry came through our website. Ninety consultants, three offices, a real-sounding company, and a project brief for exactly the kind of work we do. It looked like a great lead. It was a trap, and the thing that caught it was the intake step our own AI runs on every enquiry.

The bait

It had everything a real lead has. A name, a phone number, a company you can look up, and a message that named our exact services back to us. The only thing off was a link to a project brief and an email on a domain I did not recognize.

What the AI checked

Before anything reached me, our intake tool ran three quiet checks. Where the email really comes from, whether the company's real domain matched, and where that brief link was actually hosted.

The link was on a server in Indonesia. The email was a throwaway. The real company it was pretending to be uses a completely different, verified domain. Three strikes, and the whole thing was flagged before I ever saw it.

Three amber magnifying lenses hover over a torn document, each lighting up a small red warning mark hidden in the text

Why this matters for you

Every business with a contact form gets these. Most of the time a human is the filter, and humans are busy and trusting. A cheap AI step that verifies who is really contacting you, before it lands in your inbox, turns a dangerous click into a logged and labelled piece of junk.

That is the whole idea. Not AI that replaces you. AI that quietly stands between you and the stuff that wastes your time, or worse.

We build AI that stands between you and the busywork. Ask me what that looks like.

← Back to all posts