By Joshua Clouston, Head of Product, ezyshield

News 8 min read

AUSTRAC's Warning: AI Is Now Forging the Identities Your Payments Land With

AUSTRAC warns AI is fabricating identities to launder $166.8M in redirected payments. Here is what breaks the chain before money leaves your accounts.

Two people at an office desk reviewing a printed form together, one pointing at a line item, with a phone and tablet on the table

A payment arrives at a bank account. The name on the account looks right. The ABN checks out. The BSB resolves to a legitimate institution. Nothing flags. The money settles.

Except the identity behind that account was fabricated - generated, forged, and submitted by a criminal network using AI tools that cost less than a coffee per run. The scam proceeds are already gone.

That is the scenario Australia’s financial intelligence agency, AUSTRAC, put into plain language on 12 May 2026. CEO Brendan Thomas was direct: “Criminals are increasingly using AI as a part of their money laundering toolkit - fabricating identities, forging documents and rapidly disguising the proceeds of scams.”

Three days later, the numbers behind that statement still haven’t landed in most finance teams. Payment redirection scams cost Australian businesses and individuals $166.8 million in 2025 alone. Business email compromise losses hit $152.6 million in 2024 - a 66 per cent jump from the year before. And an increasing share of those losses are now being laundered through AI-fabricated identities that pass the checks most organisations actually run.


Why AI Changes the Laundering Problem

Business email compromise and payment redirection scams have always had a downstream bottleneck: once the money moves, it needs to land somewhere and then disappear. Traditional mule networks - real people opening accounts to receive and forward stolen funds - are slow to set up, easy to trace, and require constant recruitment.

AI removes two of those constraints.

First, document forgery. Generating a convincing identity document - a driver’s licence, an ABN registration screenshot, a utilities bill - used to take specialist tools and real effort. Today it takes a prompt and seconds. The documents produced are good enough to pass onboarding checks at many financial institutions, particularly those relying on automated document verification without liveness detection or independent data matching.

Second, scale. Instead of running five mule accounts, a criminal network can now attempt to open fifty or five hundred. Most will be caught. The ones that slip through are enough.

AUSTRAC’s May 2026 national risk assessment update noted that criminal networks are also embedding themselves inside lawful financial systems - hiding illicit flows within “routine, low-value transactions that appear indistinguishable from normal business.” An invoice for $4,800 moving between an SME and what looks like a legitimate subcontractor won’t raise an automated alert. That is the design.


The Chain That Leads Back to the Invoice

It helps to trace how these scams connect - from the initial payment diversion to the laundering endpoint AUSTRAC is now flagging.

Take a construction firm in Queensland. A project manager receives an email from what appears to be a trusted subcontractor advising that their bank account details have changed. The email domain is one character off the real one; the signature block is identical. The project manager updates the payee record and approves the next progress payment - over $1 million, in one AFP-documented case from its October 2025 construction sector BEC warning.

That payment hits an account opened with a fabricated identity. The controller of that account - or the automated system behind it - moves the money again within hours, splitting it across three or four accounts, often offshore. By the time the real subcontractor follows up on the missing payment, the trail is cold.

A Tasmanian homeowner in the same AFP report lost $120,000 and could not recover it because they reported too late. A South Australian conveyancing firm had $338,000 intercepted and returned because they reported fast enough for the AFP to act.

AI is accelerating the downstream half of this chain - the part that used to be the bottleneck.


$2.18 Billion and the Scams That Drive It

The ACCC’s 2025 Targeting Scams Report, released on 30 March 2026, recorded $2.18 billion in total scam losses for 2025 - a 7.8 per cent increase on the prior year despite a stabilisation in report volumes. Payment redirection came in as the second-largest category at $166.8 million, up 9.3 per cent year-on-year.

These are the losses people reported. The actual number is higher. AUSTRAC’s view is that a meaningful portion of those proceeds are now moving through AI-assisted identity fabrication before reaching offshore accounts or being converted into virtual assets - another avenue the May 12 update flagged explicitly.

The picture AUSTRAC paints is one where the scam, the mule account, and the laundering mechanism are increasingly a single automated workflow. The human in the loop is the Australian business or individual who clicks approve on the payment.


What the Banks Are Doing - and Where the Gap Still Is

It would be unfair to say the banking sector is not responding. CBA’s April 2026 announcement of its AI-powered fraud detection agent - monitoring over 80 million signals daily across 20 million payments - showed a 20 per cent reduction in fraud losses in the first half of 2026 versus the prior year. The Australian Banking Association’s Fraud Reporting Exchange allows near real-time intelligence sharing between 17 member banks to freeze suspicious payments in flight. Australia’s Confirmation of Payee program now matches account names against bank records for outgoing NPP payments.

These are real gains.

The problem is the point at which they apply.

Bank-side fraud detection flags anomalies in transaction patterns - unusual amounts, account age, velocity, geography. It does not, in most cases, verify whether the business or person behind a receiving account is who the payer believes they are dealing with. Name-matching via Confirmation of Payee checks that the account name on the bank’s record matches what the payer typed - but if the account was opened using a convincing forged document, the match still passes.

The gap is between the account existing and the payee being legitimate.


What Actually Breaks the Chain

AUSTRAC’s warning points to a structural vulnerability, and the fix is structural.

If a payment is going to a business, that business should be verifiable - ABN active, matching name, trading status consistent with the invoice. If it is going to an individual, that individual should exist and match the account holder on record. If the bank account details have changed, that change should be verified out-of-band before money moves.

These checks break the chain at the point that matters: before the payment leaves the rail.

Organisations that have experienced BEC or payment redirection consistently point to the same failure: they trusted an email. They did not verify the account change with the supplier directly, by phone, using a number from a previous interaction - not a number in the email requesting the change. They did not check whether the ABN on the new invoice matched a legitimately trading business. They assumed that if the payment went through the banking system, someone else had checked the other side.

Nobody had.

AUSTRAC’s update specifically flags that illicit funds are being hidden within lawful financial flows. The only way to distinguish a legitimate payment from one going to a fabricated identity is to verify the payee - the person or business - independently of the payment channel itself.


What Finance Teams Should Do Right Now

The regulatory environment is tightening. Australia’s Scams Prevention Framework, which received royal assent in February 2025, is moving into sector-specific code consultations through 2026. Banks, telcos, and digital platforms face obligations to prevent, detect, and disrupt scams. ASIC demonstrated in February 2026 that it will pursue cyber and fraud failures in court - FIIG Securities was ordered to pay $2.5 million plus costs for security failures that compromised 385GB of client data from 18,000 customers.

Businesses originating payments are not yet directly regulated under the SPF. They will increasingly be asked to demonstrate reasonable precautions. Here is what that looks like in practice.

Verify before you change. Any supplier communication requesting a change of bank account details should trigger an out-of-band verification call - using a contact number sourced from existing records, not from the email or document requesting the change. This single step would have prevented most of the AFP’s documented construction sector BEC cases.

Check the business, not just the account. Before adding a new payee or updating an existing one, confirm the ABN is active, the registered business name matches the entity you believe you are dealing with, and the account details correspond. These checks take seconds and close off the most common fabricated-payee vectors.

Use name-matching on every payment. Australia’s Confirmation of Payee system is available across NPP payments. It will not catch every case - particularly where a receiving account was opened using a forged identity - but it catches the simplest substitution attacks.

Report fast. The difference between the South Australian firm that recovered $338,000 and the Tasmanian homeowner who lost $120,000 permanently was how quickly they called the AFP. With AI-automated mule networks moving funds within hours of receipt, the recovery window is measured in hours, not days.


The Regulators Are Watching

AUSTRAC’s May 2026 risk assessment updates are not academic documents. They inform supervisory priorities, examination focus areas, and enforcement action. The agency’s CEO naming AI identity fabrication as a core threat is a signal to every regulated entity - and every business with significant outgoing payment volumes - that this is now a documented, mainstream risk.

The question for every accounts payable manager, CFO, and board is whether their current payee verification process would catch a payment going to an AI-fabricated identity.

In most organisations, the honest answer is no.


ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more

Stop payment fraud before money moves

Verify the person, business, and bank account before any payment leaves your account.