The Growing Tug-of-War Between Scammers and Defenders: What Australian Businesses Need to Do to Stay Safe
Scams are no longer on the fringes of criminal activity. They have become a mainstream threat for Australians, targeting both consumers and businesses with increasing sophistication. According to Scamwatch, Australians lost $2.03 billion to scams in 2024. This year’s Scams Awareness Week (25-29 August 2025) highlights this escalating issue and shows that as scams evolve in […]
Posted: Monday, Aug 25

i 3 Table of Contents

The Growing Tug-of-War Between Scammers and Defenders: What Australian Businesses Need to Do to Stay Safe
Scams are no longer on the fringes of criminal activity. They have become a mainstream threat for Australians, targeting both consumers and businesses with increasing sophistication. According to Scamwatch, Australians lost $2.03 billion to scams in 2024.
This year’s Scams Awareness Week (25-29 August 2025) highlights this escalating issue and shows that as scams evolve in type and scale, our strategies to combat them must also adapt.

The changing face of scams

Scams are expanding beyond traditional phishing and purchase fraud into more complex and emotionally manipulative schemes. The most common types currently affecting Australian businesses include:
  • Investment scams, which range from fake property opportunities to cryptocurrency fraud, have been on the rise with the latter skyrocketing. Victims are often lured with promises of “too good to be true” returns.
  • Payment redirection or invoice scams pose a growing risk for small and medium businesses, where fake invoices or altered account details trick companies into transferring funds to offshore criminals. Victims may also be directed to pay via account details or QR codes, which can be randomly generated. This tactic is effective as many people don’t verify QR codes before paying.
These scams exploit trust in familiar systems, whether in financial transactions, business supply chains, or government processes, making them harder to spot.

How AI is fuelling the scam economy

Artificial Intelligence (AI) is increasingly exploited by scammers to target victims. Automating scams enables bad actors to generate more sophisticated attacks more quickly and effectively, resulting in far-reaching effects. Cybercriminals are using AI in various ways:
  • Offering scams “as-a-service”: Sophisticated cybercriminals develop complete AI-powered phishing kits which are sold to less experienced scammers, lowering the barrier to entry for would-be cybercriminals while exponentially increasing the number of scams.
  • Personalised attacks: Scammers use AI to research and gather information from social media and the internet to build rich and detailed profiles of targets quickly.
  • Generating convincing content: Cybercriminals use AI to develop realistic phishing emails, deepfake audio and malicious QR codes to target victims.
  • Scaling of operations: Small scam rings can now reach a wider number of victims by automating multiple social engineering campaigns.

Using AI to combat scams

On the flip side, AI is also being increasingly used to defend against scams. In Australia, financial institutions and businesses are deploying AI in three, key ways:
  1.  Detecting scams in real-time by monitoring transactions, verifying account and payment details, and blocking high-risk payments instantly.
  2. Improving human decision-making: some banks now use AI to listen in on customer calls and transcribe conversations, alerting staff to suspicious cues.
  3. Identifying patterns of fraudulent behaviour from bot-led account takeovers to anomalies in business payment flows.
This creates a constant “arms race”, offensive AI versus defensive AI, with both sides innovating rapidly.

What Australian businesses can do to mitigate scams

With scams evolving, awareness and preparation are critical. To defend themselves from scams, businesses should follow this checklist:
  • Verify invoices: Cross-check large or unusual payments with partners, suppliers and financial institutions directly before processing.
  • Train staff and frontline workers: Provide training for finance, customer service, and IT staff to spot scams and anomalies and know the right course of action.
  • Protect customer data: Layer defences with AI-driven fraud detection, bot protection, and multi-factor authentication.
  • Establish a scam response playbook: Know who to alert (IT, legal, communications, law enforcement) and how to respond if fraud occurs.
  • Educate customers and partners: Proactively communicate about emerging scams to the various stakeholders in your organisation to strengthen your supply chain.

What to do if you fall victim

Businesses should act quickly if they fall victim to a scam. Ensure the following steps are taken:
  • Follow established procedures with haste but do not panic.
  • Notify affected partners and customers immediately.
  • Contact their bank to attempt to block or recall fraudulent transactions.
  • Report the incident to Scamwatch, the Australian Cyber Security Centre (ACSC) and relevant authorities.
  • Review internal processes to prevent recurrence.

A shared responsibility

Scams are not just an IT issue, they’re a people, process, and ecosystem issue. Protecting Australians requires vigilance, technology, and collaboration across businesses, government, and consumers.
While scams will continue to evolve, Australian businesses armed with the right tools, awareness, and response plans can stay one step ahead. It’s not a matter of if they fall victim to a scam, but when and how they respond.
Reuben Koh
Reuben Koh is a Director of Security Technology & Strategy at Akamai Technologies where he provides deep thought leadership and advisory in helping clients align security strategies with their core business initiatives and digital transformation processes. He also works with Fortune 1000 enterprises and business partners across Asia Pacific & Japan in providing cybersecurity guidance and expertise, especially in domains such as Web Security, Zero Trust, SASE, XDR, network security and Security Operations. With close to 20 years of experience in cyber security, Reuben previously held prominent leadership roles with industry leaders such as Symantec, CA Technologies, VMware and Cisco Systems. Reuben also holds various industry certifications such as CISSP, CISA, CISM and ITIL.
Share This