Introduction

Imagine receiving an email from your CEO requesting an urgent funds transfer. The wording looks familiar, the request appears routine, and the email does not show the usual signs of phishing. Before you can verify the request by phone, your CEO appears to call and confirms the urgency. You approve the transfer. Only later do you discover that the voice was cloned from a public recording and the money has already moved beyond reach.

The Scale of the Problem: Australian Fraud in 2025

The National Anti-Scam Centre’s (NASC) Targeting Scams report identified that, in 2025, Australians reported $2.18 billion in scam losses, a 7.8% increase on the previous year. Across the reporting bodies included in the report, 481,523 scams were reported, with 274,577 reports involving direct financial loss. On a personal level, the Australian Bureau of Statistics reported that 15% of Australians aged 15+ experienced one or more types of personal fraud, including card fraud, scams, identity theft, and online impersonation.

For Small-Medium Entities (SMEs), the cybercrime landscape remains a pressing concern. Cybercriminals continue to target smaller businesses because approval processes may be less formal, staff may have broader responsibilities, and security controls may be less mature than in larger organisations. Social engineering attacks, where criminals manipulate people into handing over money or information, remain particularly relevant because they exploit trust, urgency, and routine business processes rather than technology alone.

The consequences can extend well beyond the initial loss. Businesses may face operational disruption, compromised data, lost revenue, notification and legal costs, insurance complications, and reputational damage. In many cases, the greatest weakness is not the technology itself, but the point where people, pressure and payment processes intersect.

How AI Makes Fraud Harder to Spot

AI is changing how criminals operate. It allows fraud attempts to be faster, more personalised, and more convincing. Feedzai’s 2025 AI trends report, based on a survey of financial professionals, reported that more than 50% of fraud involved the use of AI. The report also identified deepfakes, voice cloning, social engineering, and AI-powered phishing as emerging fraud tactics. While this is not an Australia-specific statistic, it reflects the direction of financial crime risk.

Deepfakes

A deepfake is an AI-generated photo, audio or video that can mimic a trusted person, in some cases from only a short audio sample. Cybercriminals may combine emails, business email compromise, phone calls, and urgency to exploit human approval processes, payment workflows, and insufficient fraud controls.

Malware

Cybercriminals can use AI to modify malicious software, including viruses, trojans, and worms, so that it is harder for security tools to recognise. These modified variants may look different from known versions, increasing the risk that they bypass basic detection controls.

Advanced Phishing

Phishing is when a cybercriminal uses emails, text messages, or other communication methods to mimic a trusted person or organisation to steal personal, business, or financial information. AI enables cybercriminals to avoid the typical ‘tells’, such as poor grammar and spelling, and to adapt messages to the context, making them harder for employees to detect.

Document Manipulation

Cybercriminals use AI to forge or manipulate documents such as driver licences, tax invoices, and payslips. Some AI-assisted forgeries can be difficult to detect through basic visual checks and may bypass weak onboarding or document review processes. Entrust’s Identity Fraud Report 2025 reported that digital document forgeries increased by 244% year on year.

Ungoverned AI Use

Many businesses allow, and encourage, their teams to use AI. However, ungoverned use can create confidentiality and data protection risks. If staff enter client details, financial data, or internal documents into unmanaged AI tools, that information may be retained, reviewed, or reused depending on the tool’s terms, settings, and governance controls.

Where Businesses Are Most Exposed

For small and medium businesses, scams and fraud can be debilitating. The Australian Signals Directorate’s Australian Cyber Security Centre reported that, in 2024–25, the average self-reported cost of cybercrime per report was $56,600 for small businesses, $97,200 for medium businesses and $202,700 for large businesses. For many SMEs, even one incident can cause significant financial and operational disruption.

When to Bring in a Specialist

You do not need to wait until something goes wrong. A forensic accountant can review existing financial controls, identify exposure points, and help build processes that make fraud harder to execute and easier to detect. This may include reviewing payment approvals, testing vendor master file controls, analysing transaction data for unusual patterns, and helping staff understand the warning signs of fraud.

For many businesses, the objective is not to add unnecessary red tape. It is to design proportionate controls that protect cash, strengthen accountability, and support timely decision-making. Regular review can also help identify weaknesses before they are exploited, rather than after an incident has occurred.

Forensic specialists bring an investigative lens to financial systems, combining accounting expertise, evidence preservation, data analysis, and practical fraud-risk advice. Used early, that expertise can provide clarity, confidence, and a defensible basis for next steps.

Five Steps You Can Take Today

Reduce exposure to AI-enabled fraud and financial crime with our top tips:

  1. Verify Every Payment Change: independently verify changes to bank account details, supplier information or payment instructions using pre-existing, approved contact details. Do not rely on email chains, attachments or phone numbers provided in the change request.
  2. Strengthen Approval Processes: focus on effective controls, not simply more approvals. Segregation of duties, threshold-based approvals and dual authorisation can reduce the risk of rushed decisions, human error, and unauthorised payments.
  3. Train Your Team: provide regular, scenario-based training so staff can recognise current fraud tactics, including deepfake calls, business email compromise, phishing, and manipulated invoices. Controls are more effective when people understand the rule and the risk.
  4. Review Your Fraud Control Framework: treat fraud control as a living framework, not a one-off exercise. As technology, suppliers, systems, and staff responsibilities change, your controls should be reviewed and updated to remain effective.
  5. Get Help Early: if something does not feel right, whether it is an unusual payment request, a suspicious email, or a transaction you cannot explain, act quickly. Early intervention can limit financial loss, preserve evidence, and improve your chances of recovery.

Contact your bank immediately if money has moved, report scams to Scamwatch, report cyber incidents and cybercrime through ReportCyber, and speak to a forensic accountant if you suspect internal fraud.

Many of these actions require more discipline than cost. Multi-factor authentication, email domain monitoring, vendor master file controls, payment verification procedures, and simulated phishing exercises are practical ways to reduce risk without overcomplicating your business operations.

How Moore Australia Can Help

Fraud prevention is most effective when it is proactive. Our team can help you assess your current controls, identify high-risk payment and supplier processes, investigate suspicious activity, preserve evidence, and respond quickly if an incident occurs.

AI-enabled financial crime is evolving quickly, but businesses are not powerless. Clear processes, well-trained staff, and timely specialist advice can make the difference between a near miss and a significant loss. If you are unsure whether your current controls are keeping pace with the risk, now is the time to act.

Contact our forensic services team for a confidential discussion about strengthening your fraud resilience.

About the Author

Duane Cloete

Manager, Forensic Services
Moore Australia (WA)

Duane Cloete is a Manager for Forensic Services at Moore Australia (WA). He has extensive investigatory experience having worked alongside law enforcement agencies to manage investigations, surveillance, reporting and prosecutorial processes. This experience ranges from investigative and analytical roles, with an ability to assess criminal and commercial risk, produce detailed reports and provide guidance and advice to clients.