Australians are being urged to rethink how they identify scams, with banks and cybersecurity experts warning that artificial intelligence has rendered some of the most widely repeated fraud-detection advice effectively useless. The caution comes as the Black Friday sales period and summer holiday season approach — traditionally the busiest time of year for scammers targeting individuals and businesses alike.

Why AI Has Changed the Scam Landscape Forever

For years, Australians were told to watch for telltale signs of a scam: clunky phrasing, broken English, obvious spelling errors. That guidance is now dangerously out of date. Large language models can generate fluent, personalised, error-free messages in any language — and run thousands of separate conversations simultaneously.

"We used to tell people to look for spelling mistakes," said Sanjay Jha, a professor at UNSW's School of Computer Science and Engineering. "What's genuinely new is three things: the impersonation of real, trusted people, real-time deepfakes, and the scale and personalisation that the technology brings to financial crime."

AI tools now allow criminals to clone voices from just a few seconds of audio, produce convincing deepfake videos of doctors, celebrities and business leaders, and impersonate executives or family members in real time. "AI has turned scamming from a craft into a factory," Jha said. "A few seconds of your voice is now enough for a criminal to become you."

The stakes are real. A 2024 case involving UK engineering firm Arup saw criminals use a deepfaked multi-person video conference call to trick staff into transferring approximately HK$200 million — around $36.5 million — to fraudulent accounts.

Your Personal Data Is Already Inside the Machine

The threat goes beyond polished messaging. Richard Buckland, a professor in cybercrime and cyberwar at UNSW, warns that AI can now aggregate scattered personal information from across the internet to build a detailed profile of any potential victim — information that previously would have been too dispersed to exploit.

"If I wanted to scam you, you might have published all sorts of stuff in your youth, your dad might have said things, your friends may have, but it's in a thousand locations, and before AI, no one would ever find it," Buckland said. "But that's actually all inside the AI now."

He added that the technology is widely accessible and the barrier to entry is low. "It's really a world of outsourcing now; you could pay someone to do it, you could buy a model that does it." Buckland said experts were "just scratching the surface" of AI's capabilities in this space.

Businesses Facing Sophisticated Targeted Attacks

ANZ has issued warnings to businesses about the elevated risk during upcoming high-commerce periods. The most common threats targeting Australian businesses include Business Email Compromise (BEC), payment redirection scams, impersonation fraud, identity theft, investment scams, and goods and services fraud.

BEC and payment redirection scams are particularly damaging — criminals either gain access to legitimate business email accounts or impersonate them convincingly enough that victims believe they are paying a trusted supplier or partner, when funds are in fact being diverted elsewhere.

The scale of the problem is significant. More than 84,000 cybercrime reports were made in 2025, according to the Australian Signals Directorate, with the average self-reported cost of cybercrime to businesses rising sharply over the same period. With new risks emerging across multiple sectors of Australian life, the cybercrime surge adds further pressure on individuals and organisations already navigating a challenging environment.

What Australians Should Do Now

Experts stress that traditional red flags are no longer reliable on their own. Verifying requests for money or sensitive information through a separate, independently confirmed contact method — rather than replying via the same channel — is now considered essential. Businesses in particular are urged to implement multi-step verification processes for any payment changes, regardless of how convincing the request appears.

With scammers able to impersonate voices, faces and email addresses with increasing precision, the message from security professionals is clear: if something feels urgent or unusual, slow down and verify independently — no matter how legitimate it looks.