By Joshua Clouston, Head of Product, ezyshield

News 7 min read

Your Next Invoice Could Be a Deepfake: AI Fraud Targets Australian Businesses

AI deepfakes and voice cloning are behind a new wave of payment fraud hitting Australian businesses in 2026. Here's what changed, what it costs, and how to stop it.

Over-the-shoulder view of a woman on a laptop video call showing a grid of multiple participant tiles, in an open-plan office

In February 2024, a finance employee at Arup - one of the world’s largest engineering firms - joined a video call with the CFO and several senior colleagues. They discussed a confidential transaction. The employee transferred $25 million. Every person on that call was a synthetic deepfake.

That was two years ago. The tools have gotten cheaper, faster, and more convincing since.

Today, in July 2026, Australian businesses are facing a fraud environment that has fundamentally shifted. Attackers are no longer writing broken-English phishing emails. They are cloning voices from three-second audio samples, generating photorealistic video avatars from publicly available footage, and producing invoices indistinguishable from the real thing. Seventy-one per cent of Australian organisations reported an increase in AI-powered fraud attempts over the past 12 months.

The money at stake is not hypothetical. Australians lost $2.18 billion to scams in 2025. Authorised push payment fraud - where victims are tricked into approving a transfer themselves - is forecast to hit $1.76 billion annually by 2028. The median loss per business fraud incident tracked by the AFP is $120,000. These are not rounding errors. These are businesses that do not recover.

How the Attack Actually Works

The modern payment fraud playbook has three moves.

Reconnaissance. Attackers mine LinkedIn, company websites, social media, and leaked databases to map the org chart - who approves payments, who talks to suppliers, who has authority to request account changes.

Impersonation. They clone the voice of a CEO or CFO (three seconds of audio is enough, according to FS-ISAC), or generate a deepfake video avatar from conference footage. They send an AI-crafted email that mirrors the real person’s tone, references live projects, and arrives from a convincing spoofed or compromised domain. Human listeners correctly identify cloned voices only 37.5% of the time in controlled tests.

Redirect. They ask for a payment to a new account - a supplier that “changed banks,” an urgent invoice needing same-day settlement, a tax obligation, a confidential acquisition. The request bypasses normal process because it appears to come from someone trusted.

The entire attack is social engineering, amplified by AI. The finance team sees a known face, hears a known voice, reads a known writing style. The one thing they cannot see is who actually owns the destination account.

Why Australian Businesses Are in the Crosshairs Right Now

Several factors make Australian businesses particularly exposed in mid-2026.

The New Payments Platform (NPP) and PayTo enable real-time, irrevocable transfers. Once money moves, recovery is the exception - the AFP estimates only 22% of business fraud victims recover most of what was stolen, and the window to freeze funds is measured in hours, not days.

On 1 July 2026, approximately 80,000 new businesses entered Australia’s anti-money laundering regime for the first time. Under AUSTRAC’s Tranche 2 AML/CTF reforms, lawyers, accountants, conveyancers, real estate agents, trust and company service providers, and dealers in precious metals and stones are now subject to AML/CTF obligations. AUSTRAC chief executive Brendan Thomas put it plainly at commencement: “For too long, criminals have been able to take advantage of so-called ‘gatekeeper professions.’”

These are precisely the professions that handle the largest single-transaction payments in the Australian economy: property settlements, business sales, trust distributions, estate disbursements. A conveyancer redirecting a $1.2 million settlement to the wrong account does not discover the error until it is too late. An accountant approving a supplier payment to a BEC-compromised account faces the same outcome.

Fraud actors know this. And many of these firms are only now starting to build compliance infrastructure - which means controls around payment verification are still immature.

What Changed on 1 July 2026

Two things landed simultaneously this month, and together they raise the stakes for every business in the payments chain.

AUSTRAC Tranche 2 is live. Newly regulated firms have until 29 July 2026 to enrol with AUSTRAC and notify their AML/CTF compliance officer - no general extensions will be granted. The core obligations include customer due diligence before providing a designated service, sanctions and politically exposed person (PEP) screening, suspicious matter reporting, and seven-year record-keeping. Thomas has noted the regulator has “never penalised a small business for administrative mistakes” but made clear the expectation is now compliance, not good intentions.

The Scams Prevention Framework is moving. Treasury published draft SPF rules on 28 May 2026. The framework - which applies to banks, telcos, and digital platforms - commences 1 September 2026, with full obligations from 31 March 2027. From 1 July, AFCA became the authorised external dispute resolution scheme for scam complaints under the SPF.

The reimbursement model matters. Losses under $3,000 will be automatically reimbursed to verified victims without full investigation. Losses above that threshold trigger internal dispute resolution, and if a bank or platform failed to meet its obligations - failing to warn, failing to monitor, failing to act on intelligence - it becomes liable. Liability is shared equally when multiple entities failed in the same scam. The civil penalty for a single contravention is up to $50 million.

This is a direct shift of incentive. Banks and platforms that do not verify payees before payments move will eventually pay for it - through the complaints process and, ultimately, through enforcement.

The One Thing AI Cannot Fake

Here is the structural problem with every AI-powered payment fraud: the attack ends at the bank account.

A deepfake can clone a voice. A synthetic avatar can pass a video call. An AI can write a perfectly calibrated email referencing the right project, the right amount, the right supplier. None of that changes who actually owns a BSB and account number.

Account ownership verification - checking that the account name, BSB, and account number actually match the entity you believe you are paying, before the transfer is approved - cuts the attack at its root. It does not matter how convincing the impersonation is. If the destination account is not registered to the supplier you expect, the payment should not go.

This is what Confirmation of Payee (CoP) is designed to do. The UK mandated CoP in 2019 and recorded measurable reductions in payment redirection losses. Australia is moving in the same direction - the Scams Prevention Framework includes CoP-equivalent requirements for banks - but the mandate applies to banks, not to the businesses initiating the payments.

That gap is where business losses are accumulating. A finance team that uses a payee verification service to confirm the BSB and account match the registered business name - before hitting approve - closes that gap before the NPP settles funds in real time.

The AFP is direct about timing: businesses that recover stolen funds are those that called their bank and lodged a report with ReportCyber within 24 hours. After that, the probability of recovery drops sharply.

What to Do This Week

If you run payments for an Australian business - or advise businesses that do - five things are worth doing before next Friday.

Verify before you pay. Any request to update bank details should trigger an independent verification call using a number you hold on record, not one provided in the request. This applies to suppliers, customers, the ATO, and anyone else. One call is cheaper than a $120,000 median loss.

Check your AML/CTF enrolment. If you are a lawyer, accountant, conveyancer, real estate professional, or trust and company service provider, the AUSTRAC enrolment deadline is 29 July 2026. Missing it is a compliance breach, not an administrative oversight.

Set a payment verification threshold. Any single payment above a defined amount - many firms use $5,000 or $10,000 - should require dual authorisation and documented payee verification before approval. No exceptions for urgent requests.

Train your team on the AI threat. Staff who know that voice cloning needs only three seconds of audio, and that deepfake video already fools experienced finance professionals, approach payment requests differently. The ACCC and cyber.gov.au have current guidance.

Use a payee verification service at the point of payment. Account verification before payment is not a blanket regulatory requirement for most businesses today. It is, however, the most direct control against a fraud vector that AI has made nearly impossible to detect through human judgment alone.

The Arup incident is useful not because it is the worst case, but because it is the best-documented. The attackers spent months on reconnaissance. The deepfake was sophisticated enough to fool an experienced finance professional on a live video call. The only mistake was approving a payment to an account that had not been independently verified.

That is the one check AI cannot defeat.


ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more

Stop payment fraud before money moves

Verify the person, business, and bank account before any payment leaves your account.