AI fuels targeted scams against Australian small firms
Tue, 25th Aug 2026 (Today)
Australian cyber security experts are warning that small businesses and consumers face a new wave of highly targeted scams during Scams Awareness Week. They say artificial intelligence and increasingly sophisticated identity fraud are driving the shift.
Recent analysis from online business insurance platform BizCover points to changing scam patterns in reports to the national ScamWatch service between 2024 and 2025. Small business scam reports fell 20.8% over the period, but total losses rose 3.4% and the average loss per report increased 30.4%.
Akshaye Kalkura, Chief Information Security Officer at BizCover, said smaller firms are facing fewer but more damaging incidents. Scam tactics are increasingly aimed at single high-value payments, such as altered supplier bank details or fake invoices that slip through rushed checks.
"Scams are becoming more targeted, and criminals are getting better at making their attacks look legitimate," said Akshaye Kalkura, Chief Information Security Officer at BizCover. "All it takes is one dodgy email, one fake invoice, and a successful scam can potentially cripple a small business's operations."
Attackers often impersonate trusted suppliers, company executives or existing customers. They exploit pressure on owners and finance staff to respond quickly. BizCover's data suggests many incidents now involve well-crafted messages that mimic real correspondence and use accurate business details.
Kalkura said basic process changes can reduce the risk that a single fraudulent request causes major damage.
"Lower report volumes don't mean the threat is disappearing. If you receive an unexpected request to make a payment or change bank details, take the time to verify it with the person or supplier through a separate channel before acting," Kalkura said.
Security leaders also warn that artificial intelligence is changing the scale and persistence of scams targeting both businesses and individuals. Jason Duerden, Vice President ANZ at cyber security firm SentinelOne, said large language models and AI agents are reshaping how criminal groups operate.
Machine-driven scams can combine personalised messages with continuous probing in ways that would be difficult for human fraudsters to sustain, he said.
"Scammers have traditionally faced a choice between volume and personalisation. LLMs remove that trade-off, while AI agents add something more dangerous: persistence. They can research targets, generate tailored approaches and keep testing different routes without becoming tired or deciding the effort is no longer worthwhile. We've already seen this behaviour in cyber incidents. An AI agent took around 17,600 actions during the recent Hugging Face intrusion, most of which failed, but it rebuilt tools, restored communications and continued for two and a half days.
"Applied to scams, that same persistence could allow criminal groups to pursue thousands of Australians with approaches shaped around their provider, workplace or recent activity. The Scams Prevention Framework must account for the full sequence. A social media ad, telco message, account login and bank transfer may each appear ordinary in isolation. Stopping the scam depends on connecting those signals before the money leaves, at the same speed the attacker is operating," said Jason Duerden, Vice President ANZ at SentinelOne.
While new regulation and industry initiatives focus on blocking suspicious payments, identity specialists argue that trust checks earlier in the process remain weak. Fred Slikker, Managing Director at digital identity firm Digidentity, said traditional advice to look for spelling mistakes or odd language is becoming less reliable as criminals use convincing AI-generated content and deepfakes.
Organisations need stronger ways to confirm who is on the other side of a transaction, and what authority they hold, he said.
"For years, scam prevention has relied on people noticing that something doesn't look or sound quite right. That advice is becoming less useful when a deepfake can recreate a familiar face, stolen customer data can supply the correct personal details and a spoofed number can appear to belong to a trusted organisation. Even together, those signals don't prove that someone genuinely represents the organisation they claim to, or has authority to make the request," said Fred Slikker, Managing Director at Digidentity.
"The Scams Prevention Framework should drive a much higher standard of verification by organisations, not simply when a customer is onboarded, but throughout the relationship. Organisations need to be confident not only that a person is who they claim to be, but that they are authorised to act on behalf of an organisation and that the documents, instructions or mandates they provide are genuine and current.
"The burden should not fall on consumers to make these judgements under pressure. Organisations should have robust, independent ways to verify identity, authority and the authenticity of the evidence on which transactions and decisions are based," Slikker said.
Consumer security specialist Lynette Owens, Vice President of Consumer Education and Marketing at TrendLife, said scammers increasingly target people during major life decisions such as buying a home or car, or searching for work. These moments often involve time pressure, complex processes and multiple third parties.
Her comments follow TrendLife research that found one in five Australians have either been scammed themselves or know someone who has been scammed while making a major purchase or investment.
"When we're under pressure, we're at our most vulnerable to scams. Scammers know this. That's why one in five Australians have either been scammed themselves or know someone who has been scammed while making a major purchase or investment, according to the latest TrendLife research.
"Scammers are inserting themselves into home-buying, car-buying and job-seeking processes because these moments involve urgency and fear of missing out. That makes people less likely to notice the signs of a scam or to be suspicious of unknown third parties, which are often a normal part of these processes.
"At the same time, AI is making these scams harder to recognise. Spelling mistakes, poor grammar and badly spoofed website links were once obvious warning signs. AI has removed many of those telltale signs while automating scam operations at scale. Scam sophistication has boomed.
"This Scam Awareness Week, Australians need to recognise that much of the anti-scam education we have relied on is struggling to keep pace with how quickly these tactics are evolving. Education remains an important part of online safety, but it cannot work alone. As scams become more convincing and evolve faster, consumers must combine good digital safety habits with technology that can identify threats more quickly.
"We should still stop to independently verify unexpected requests and seek a second opinion when something does not feel right. But we should also use anti-scam tools that can recognise scams better than we can," said Lynette Owens, Vice President of Consumer Education and Marketing at TrendLife.