AI Scams and Deepfakes: The New Threat Targeting Small Businesses and How to Protect Yourself
He’d been on plenty of video calls with the CFO. This one felt normal. The CFO was there, two colleagues he recognised were there, everyone said hello, everyone looked and sounded exactly like themselves. There was a transfer to approve, it was urgent, and he approved it.
But nobody on that call was real.
That happened to a finance worker at global engineering firm Arup in January 2024. He made 15 transfers totalling HK$200 million – about US$25.6 million. Arup confirmed the incident to CNN in May that year, saying fake voices and images had been used. Every face on the screen was generated. And before you decide that’s a big-corporate problem – it isn’t. The same tools that built that call are now cheap, fast, and pointed squarely at businesses your size.
Here’s the good news, and it’s better than what most articles will tell you: you are never going to out-eyeball a deepfake, and you don’t have to. The businesses that survive this don’t have sharper staff. They have a better process. Let’s build you one.
What We’re Talking about
When most people hear the term deepfake, they think of AI-generated videos, images, or audio recordings that make someone appear to say or do something they never did. While that’s certainly part of the problem, it’s only one piece of a much larger threat landscape.
The broader category is AI scams. These scams use artificial intelligence to make deception more believable, more personalised, and far easier to scale than traditional fraud. That can include cloned voices, AI-generated video calls, highly convincing phishing emails, fake invoices, synthetic supplier identities, and even entire fraudulent websites that criminals can create in a matter of hours.
The Australian Cyber Security Centre has warned that AI is making social engineering attacks easier to execute and scale, particularly through sophisticated phishing campaigns and voice impersonation techniques.
As a result, businesses need to start asking a different question. Instead of focusing solely on whether employees can identify a scam, leaders need to consider what happens when a convincing scam inevitably slips through. The real challenge is no longer spotting every threat. It’s building processes, controls, and safeguards that minimise the damage when someone encounters a scam that looks genuine.
That’s the shift this article explores.
Why Scammers Suddenly Love Small Businesses
The economics of fraud have changed, and they’ve changed fast.
A few years ago, creating a fake voice or video required specialist skills and expensive software. Today, scammers can clone a voice from a short webinar clip, LinkedIn video, or voicemail greeting. A single photo from your website can help create a convincing fake image or video.
At the same time, large organisations rely on approval chains, payment controls, and documented processes. Small businesses often run on trust, speed, and direct communication. That’s what makes them efficient, but it’s also what makes them attractive targets.
Business Victoria notes that small business owners make hundreds of decisions under constant pressure, giving scammers opportunities to exploit urgency. In 2025, Australian small businesses lodged 2,228 reports to Scamwatch, with 287 cases involving financial losses totalling $9.5 million. False billing scams were the most commonly reported.
The pattern is clear. Most losses don’t start with sophisticated hacking. They happen because someone receives something that looks legitimate and acts on it.
This isn’t just a cybersecurity problem. It’s a trust problem. For a large corporation, a fraudulent payment may be a setback. For a small business, it can be payroll, cash flow, or the difference between a profitable month and a difficult one.
The five AI scams hitting Australian businesses right now
Why “spot the fake” advice is already obsolete
You’ve read the listicles. Count the fingers. Watch for weird blinking. Check whether the ears look funny.
Please stop.
That advice was written for 2023 technology and it’s now actively dangerous, because it teaches your team that a clean-looking video is proof. Even purpose-built detection struggles: Intel’s FakeCatcher hits around 96% accuracy in lab conditions, but real-world performance drops by 45–50 percentage points. Roughly half of live deepfakes get past the professional tools.
Your accounts coordinator at 4:45pm on a Friday has no chance, and shouldn’t be expected to. Staff awareness matters – but making one busy human the entire control is not a security strategy. People get tired. People get rushed. Scammers deliberately engineer situations where nobody has time to think.
So change the question. It isn’t “Is this person real?” – that’s unanswerable. It’s:
Did this request arrive through a channel I can independently verify?
That question is always answerable. And it’s free.
The 20-minute fix: your verification process
“Out-of-band” just means verify through a different channel than the one the request came in on. If it arrived by email, confirm by phone. If it arrived by phone, confirm through a known internal channel. The attacker controls one channel. They almost never control two.
Here’s what to implement this afternoon:

- Set a dollar threshold.
Above a certain amount – $2,000 is a fine start – nothing moves on a single approval. Ever. Including from the boss. Especially from the boss. - Require two approvers on high-value or unusual payments.
This does something subtler than adding a checkpoint: it means a junior staff member never has to personally challenge a senior person. The process does the challenging for them. That’s the difference between a policy that works and one that quietly gets skipped. - Make callbacks mandatory, on a known number.
Not the number in the email signature. The one already in your records. This single rule kills most voice clones. Give your team the script so it doesn’t feel rude: “Thanks – I’ll confirm this through our normal payment process and call you back on the number we have on file.” - Freeze all bank-detail changes for 24 hours,
verified by voice on a previously known number. No exceptions for urgency. Urgency is the attack. - Lock the front door.
MFA on email, Microsoft 365 or Workspace, banking, accounting platforms and remote access and move to phishing-resistant options like passkeys or security keys where you can. Get DMARC, SPF and DKIM configured properly. Most business email compromise starts with one mailbox. Aligning to the Essential Eight and getting an honest read on your security posture is the highest-leverage hour you’ll spend this quarter. - Train on scenarios, not screenshots.
Showing staff a dodgy email teaches recognition, which no longer works. Instead, drill the response: The director rings asking for an urgent payment. A supplier emails new bank details. Someone messages on Teams asking for a password reset. A stranger on a video call asks for confidential information. For each, your team should know the exact next step without thinking. The goal isn’t turning everyone into a security expert. It’s making the safe response automatic. - Audit what’s public.
- Your voice is biometric data now.
Long video interviews, podcasts and voicemail greetings are free training material. You don’t have to go dark, just know what’s out there. - Watch the systems overnight.
Compromised mailboxes announce themselves through odd login locations and quietly created forwarding rules, usually at 2am when nobody’s looking. That’s what 24/7 NOC and SOC monitoring exists to catch.
If it’s already happened: the first 60 minutes
- Ring your bank immediately.Recall windows are measured in hours, not days. This is the only step where speed genuinely changes the outcome.
- Preserve everything.Emails, screenshots, phone numbers, invoices, chat messages, timestamps, affected accounts. Don’t delete it out of embarrassment because your bank and investigators need it.
- Report it.ReportCyber at cyber.gov.au for cybercrime, Scamwatch for scams.
- Reset credentials and check mailbox rulesfor forwarding the attacker left behind.
- Check your insurance.Most cyber policies exclude social engineering fraud unless you’ve specifically bought that cover. Find out now, not after.
- Tell your team what happened.Quietly burying it is how it happens twice.
Scamwatch’s own advice compresses neatly: Stop. Check. Protect. Stop before money or information moves. Check the person is genuine through a channel you trust. Protect yourself and others by reporting it quickly.
AI isn’t the enemy. Unverified trust is.
Don’t let any of this scare you off using AI because it’s genuinely good at writing, analysis and killing off repetitive admin. The problem is that the same technology works just as well for criminals.
Which means security in 2026 isn’t only firewalls and antivirus. It’s trust management. Who is making this request? Are they authorised to make it? Does it match our normal process? Can I verify it independently?
Because a message can look perfect and still be fraudulent. A voice can sound familiar and still be fake. A video call can show a trusted executive and still be an impersonation.
The biggest mistake isn’t falling for a sophisticated scam. It’s assuming it won’t happen to us. AI has collapsed the cost of convincing fraud, so you no longer need to be big or famous to be worth targeting. Sometimes the target is simply the business with one person approving payments, no verification rule and shared passwords.
You cannot buy your way out of this with software, and you cannot train your way out of it with “be more careful.”
It’s a process problem — and processes only work when somebody actually owns them. Someone watching for the odd login at 2am, keeping MFA enforced across every new starter, and running the help desk that handles the password resets and access requests where these attacks so often begin. For most growing Australian businesses, that’s a full-time job nobody currently has.
That’s the gap SupportHub360 fills. We help Australian MSPs and businesses stand up the security consulting, round-the-clock monitoring and service desk capability that turns verification into a habit rather than a hope.
Book a free consultation
Or browse the blog for more practical guidance on protecting and scaling your business.
Because when a scammer only needs one convincing message to get through, good instincts aren’t enough. You need a system that makes the wrong decision harder to make.