Scams Awareness Week 2026 (24–28 August) is a useful reminder — and a slightly uncomfortable one. The old advice still gets repeated: look for spelling mistakes, awkward grammar, and dodgy email addresses. That advice is no longer enough.
Attackers now use AI to write fluent, personalised messages that look like they came from your supplier, your bank, or your boss. Australians lodged more than 91,000 reports with Scamwatch in the first half of 2026, with $157 million reported stolen. This guide is what homes and businesses — in Melbourne and across Australia — should actually train people to check.
Quick Navigation
What Changed in 2026
Scammers used to choose between volume and personalisation. AI removed that trade-off. A message can now be fluent, on-brand, and tailored to your business in seconds — including invoices that match a real supplier name, and voice clones that sound like someone you know.
The old tells are gone
Spelling mistakes, broken English, and obviously fake logos used to be the giveaway. Large language models write clean Australian English and can copy the tone of a real email thread.
Attacks now persist
AI agents can research a target, try one approach, fail, then try another without getting tired. One failed invoice scam does not mean they will stop.
The Attacks We See Most
For Aussie small businesses, the expensive scams are rarely random prize emails. They impersonate people you already trust, usually around money, logins, or a “urgent” request.
Fake invoices and changed bank details
You get an email that looks like a regular supplier invoice, or a polite note that “we’ve updated our account details.” The language is perfect. The ABN looks right. The only thing that changed is the BSB and account number.
The “boss” call or Teams ping
A voice note, phone call, or chat message asks accounts to pay a supplier now, buy gift cards, or share a one-time code. Deepfake audio is good enough that staff should not rely on “it sounded like them.”
Login pages that look like Microsoft 365
A shared document, voicemail, or “your mailbox is full” email sends you to a login page that looks identical to Microsoft. Once you type the password — and the MFA code — the attacker is in.
Checks That Still Work
Stop looking for typos. Start looking for process breaks. If a request is about money, credentials, or changing how you pay someone, slow it down.
- 1. Verify on a second channel. Call the supplier on the number you already have — not the number in the email. Walk down the hall. Start a new Teams chat with the real person, don’t reply in the suspicious thread.
- 2. Never change bank details from email alone. Treat every “new account” request as a potential scam until you confirm it independently.
- 3. Hover before you click. The display name can say “Microsoft” or “ATO.” The actual link often isn’t. Type the real site yourself if you need to log in.
- 4. Nobody legitimate will ask for your MFA code. Microsoft, your bank, and your IT provider will not ring you and ask you to read out the six-digit number on your phone.
- 5. Urgency is the tell. “Pay this in the next 20 minutes or the account gets locked” is designed to skip your usual checks. That pressure is the scam.
Make It a Team Habit, Not a Lecture
One staff member who feels silly asking “is this real?” is how invoices get paid to the wrong account. Praise people for checking. Do not punish them for pausing a payment.
Accounts
Dual approval on new payees and any bank-detail change. No exceptions for the owner being “in a meeting.”
Everyone else
A simple rule: unexpected login links and unexpected payment requests get forwarded to a named person, not actioned solo.
IT basics
MFA on email, a password manager, and a way to report a suspicious message without waiting until Monday.
If Someone Already Clicked
Act in the first hour
Change the password from a device you trust, revoke sessions, tell your bank if money moved, and contact your IT provider. Do not wait to see if “anything happens.” With stolen Microsoft 365 access, attackers often sit quietly, then send invoices from the real mailbox.
If you are unsure whether a message is real, The Nerd Herd can take a look. Local support beats guessing — especially when the email looks perfect.
Want a Security Sense-Check?
We’ll review how your team handles invoices, email logins, and MFA — and close the gaps attackers actually use.