Deepfakes and AI Scams: How Do I Protect My Small Business?

AI removed the old warning signs. The bad grammar and the dodgy address are gone, so your defence has to change.

Resources / Deepfakes and AI Scams: How Do I Protect My Business?

The same way you stop ordinary scams, with two additions: a verify-by-callback rule for any request to move money or change bank details, and multi-factor authentication on every account. AI now writes flawless phishing emails and can clone a voice from seconds of audio, so "it sounded like the boss" and "the email looked perfect" are no longer proof of anything.1 The good news: the defences are process and habit, not expensive gadgets.

$80,850

average cost of a cybercrime report to an Australian business in 2024-25, up 50%

1 every 6 min

cybercrime reports to the Australian Signals Directorate in 2024-25

2 rules

callback verification and MFA stop the large majority of it

What makes an AI scam different?

For years the advice was to watch for clumsy grammar, odd sender addresses and generic greetings. AI has erased those tells. A scammer can now generate a personalised, perfectly written email in your industry's language, clone a familiar voice from a short clip pulled off social media or a voicemail greeting, and even fake a live video call. The trick is the same as it always was, convincing you to trust a message; what changed is that the message now looks and sounds genuine.

What do these attacks look like for a small business?

Four patterns cover most of it. A supplier invoice arrives with the bank details quietly changed, so your payment lands in a criminal's account. A voice message or call that sounds like the owner asks a staff member to pay something urgently and quietly. A login page that mimics Microsoft 365 or your bank harvests a password. And business email compromise, where an attacker gets into one mailbox and uses it to redirect real invoices. None of these needs the victim to be careless, only to trust what they see and hear.

Why would a scammer bother with a small business?

Because small businesses move real money and usually have lighter controls than a big company. The national picture backs this up: the Australian Signals Directorate received more than 84,700 cybercrime reports in 2024-25, roughly one every six minutes, and the average self-reported cost per business report rose fifty per cent to $80,850.2 You are not too small to be a target. You are the target profile.

The one rule that beats most of it: verify out of band

Make it a standing rule that any request to pay a new account, change bank details, or move money urgently is confirmed by calling the person back on a number you already have, never the number or link in the message. AI can fake the email and the voice on the incoming channel; it cannot answer the known desk phone of your real supplier. This single habit defeats invoice fraud and "urgent boss" scams, which are the ones that actually empty accounts.

The technical baseline everyone should have

Turn on multi-factor authentication everywhere it is offered, especially email, banking and Microsoft 365; it blocks the overwhelming majority of password-based attacks even when the password is stolen. Lock down your email authentication so criminals cannot easily impersonate your domain, our free email security checker tests exactly that in a few seconds. And spend twenty minutes teaching the team the callback rule above, which is worth more than any product.

What if you think you have already been hit?

Move fast in the first hour: change the password on any exposed account, contact your bank if money or details were shared, and report it. Our guide on what to do in the first hour after clicking a phishing link walks through the steps. Speed limits the damage far more than anything you do the next day.

References

  1. Australian Signals Directorate, Annual Cyber Threat Report 2024-25, cyber.gov.au.
  2. Australian Signals Directorate, ASD releases the Annual Cyber Threat Report 2024-25, asd.gov.au.
  3. Scamwatch, Scam types and reporting, National Anti-Scam Centre.

Related resources

You clicked a phishing link: the first hour: the steps that limit the damage.
Free email security checker: test whether criminals can spoof your domain.
The Essential Eight for small business: MFA and the rest of the baseline.

Frequently asked questions

Can AI really clone someone's voice?

Yes. A few seconds of clear audio, which is easy to find on social media or a voicemail greeting, is enough for convincing voice cloning. Treat a familiar voice as a claim to verify, not proof.

How do I verify a payment or bank-detail request?

Call the person or supplier back on a number you already hold, not one supplied in the message, and confirm before you act. This single habit stops most invoice and 'urgent boss' fraud.

Does MFA stop deepfake scams?

It stops the account-takeover half, where a stolen password is used to get into your email or systems. Pair it with the callback rule to also cover payment and impersonation fraud.

Are small businesses really targeted?

Yes. Australian businesses reported cybercrime roughly once every six minutes in 2024-25, and small businesses are attractive because they move money with lighter controls.

What should I do first if I have been scammed?

Change the password on any exposed account, contact your bank if money or details were shared, and report it to Scamwatch and the ASD. Acting in the first hour limits the damage.

General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. If you have been scammed or breached, contact your bank, call IDCARE on 1800 595 160, and report it via ReportCyber at cyber.gov.au. For help securing your business, get in touch.

Worried your team could fall for an AI scam?

We will set up multi-factor authentication, lock down your email against impersonation, and give your team the simple callback rule that stops the expensive scams. Tell us your setup and team size.

Prefer to talk? Call (02) 9053 8789.