AI removed the old warning signs. The bad grammar and the dodgy address are gone, so your defence has to change.
Resources / Deepfakes and AI Scams: How Do I Protect My Business?
The same way you stop ordinary scams, with two additions: a verify-by-callback rule for any request to move money or change bank details, and multi-factor authentication on every account. AI now writes flawless phishing emails and can clone a voice from seconds of audio, so "it sounded like the boss" and "the email looked perfect" are no longer proof of anything.1 The good news: the defences are process and habit, not expensive gadgets.
average cost of a cybercrime report to an Australian business in 2024-25, up 50%
cybercrime reports to the Australian Signals Directorate in 2024-25
callback verification and MFA stop the large majority of it
For years the advice was to watch for clumsy grammar, odd sender addresses and generic greetings. AI has erased those tells. A scammer can now generate a personalised, perfectly written email in your industry's language, clone a familiar voice from a short clip pulled off social media or a voicemail greeting, and even fake a live video call. The trick is the same as it always was, convincing you to trust a message; what changed is that the message now looks and sounds genuine.
Four patterns cover most of it. A supplier invoice arrives with the bank details quietly changed, so your payment lands in a criminal's account. A voice message or call that sounds like the owner asks a staff member to pay something urgently and quietly. A login page that mimics Microsoft 365 or your bank harvests a password. And business email compromise, where an attacker gets into one mailbox and uses it to redirect real invoices. None of these needs the victim to be careless, only to trust what they see and hear.
Because small businesses move real money and usually have lighter controls than a big company. The national picture backs this up: the Australian Signals Directorate received more than 84,700 cybercrime reports in 2024-25, roughly one every six minutes, and the average self-reported cost per business report rose fifty per cent to $80,850.2 You are not too small to be a target. You are the target profile.
Make it a standing rule that any request to pay a new account, change bank details, or move money urgently is confirmed by calling the person back on a number you already have, never the number or link in the message. AI can fake the email and the voice on the incoming channel; it cannot answer the known desk phone of your real supplier. This single habit defeats invoice fraud and "urgent boss" scams, which are the ones that actually empty accounts.
Turn on multi-factor authentication everywhere it is offered, especially email, banking and Microsoft 365; it blocks the overwhelming majority of password-based attacks even when the password is stolen. Lock down your email authentication so criminals cannot easily impersonate your domain, our free email security checker tests exactly that in a few seconds. And spend twenty minutes teaching the team the callback rule above, which is worth more than any product.
Move fast in the first hour: change the password on any exposed account, contact your bank if money or details were shared, and report it. Our guide on what to do in the first hour after clicking a phishing link walks through the steps. Speed limits the damage far more than anything you do the next day.
You clicked a phishing link: the first hour: the steps that limit the damage.
Free email security checker: test whether criminals can spoof your domain.
The Essential Eight for small business: MFA and the rest of the baseline.
Yes. A few seconds of clear audio, which is easy to find on social media or a voicemail greeting, is enough for convincing voice cloning. Treat a familiar voice as a claim to verify, not proof.
Call the person or supplier back on a number you already hold, not one supplied in the message, and confirm before you act. This single habit stops most invoice and 'urgent boss' fraud.
It stops the account-takeover half, where a stolen password is used to get into your email or systems. Pair it with the callback rule to also cover payment and impersonation fraud.
Yes. Australian businesses reported cybercrime roughly once every six minutes in 2024-25, and small businesses are attractive because they move money with lighter controls.
Change the password on any exposed account, contact your bank if money or details were shared, and report it to Scamwatch and the ASD. Acting in the first hour limits the damage.
General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. If you have been scammed or breached, contact your bank, call IDCARE on 1800 595 160, and report it via ReportCyber at cyber.gov.au. For help securing your business, get in touch.
We will set up multi-factor authentication, lock down your email against impersonation, and give your team the simple callback rule that stops the expensive scams. Tell us your setup and team size.
Prefer to talk? Call (02) 9053 8789.