Manegy

Deepfake & BEC Scams 2026: How Australian Finance Teams Can Stop Executive Fraud

03 September 2026

Technology

SHARE

Deepfake & BEC Scams 2026: How Australian Finance Teams Can Stop Executive Fraud

Artificial intelligence has made executive impersonation and payment fraud significantly easier to execute — and significantly harder to detect. Voice cloning, deepfake video, and AI-generated email now allow criminals to produce communications that are contextually accurate, stylistically convincing, and, in some cases, indistinguishable from the real thing. The National Anti-Scam Centre recorded $166.8 million in payment redirection losses in Australia in 2025, and a Commonwealth Bank survey conducted in January 2026 found that only 42 per cent of Australians could correctly identify AI-generated content when tested — despite 89 per cent believing they could. For back-office teams with authority over payments and access to sensitive information, the risk is direct. This article covers how these scams work, why finance and HR teams are targeted, what verification procedures provide the most effective defence, and what to do if an attempt succeeds.



What Are Deepfake & BEC Scams? How Executive Fraud Works in 2026


Business email compromise and executive impersonation are not new threats. What has changed is the technology available to carry them out — and the speed at which that technology has become accessible to criminal actors operating at scale.

Attack Vector

How It Works

Key Verification Control

BEC / Spoofed Email

AI replicates writing style and project details

Out-of-band verification: contact the sender using an independently stored number

AI Voice Cloning

Clones an executive's voice from a short audio sample

Verbal code word: use a pre-agreed passphrase to authenticate urgent requests

Deepfake Video

Generates real-time or recorded video impersonations

Out-of-band verification: confirm through a separate, pre-established channel — not the call itself

Payroll Redirection

Impersonates employees to redirect salary payments

Independent cross-check: call the employee directly on a known number before updating banking details

A Commonwealth Bank survey conducted in January 2026 found that while 89 per cent of Australians believed they could identify a deepfake scam, only 42 per cent were able to correctly distinguish between real and AI-generated content when tested. Of those who reported having witnessed a deepfake scam in the past year, 40 per cent described it as a business email compromise or payment redirection scam.


The ACSC notes that the most significant factor in successful BEC attacks is not the sophistication of the technology but the absence of a mandatory verification step before the requested action is taken. In that sense, executive impersonation is as much a process failure as a technical one.




Why Back-Office Teams Are in the Crosshairs


Executive impersonation and BEC scams do not target organisations at random. The attacks are directed at the people who have the authority to act on financial or sensitive instructions — and in most organisations, that means the accounts payable team, the payroll officer, and HR.



Access to Payment Systems and Financial Authority


Finance and accounts payable staff hold the combination of system access and transactional authority that makes them the most direct route to an organisation's funds. A successful impersonation of a CEO or CFO directed at a finance team member can result in an immediate transfer of funds that becomes increasingly difficult to recover as time passes. The National Anti-Scam Centre's Targeting Scams 2025 report recorded $166.8 million in payment redirection losses in Australia in 2025 — a 9.3 per cent increase from the prior year — making it one of the few scam categories to record year-on-year growth.

For small businesses in particular, Scamwatch data shows that false billing scams — the category that captures most BEC-style attacks — were the most frequently reported scam type, with and without financial loss.



Access to Personal and Payroll Information


HR teams hold information that is equally valuable to criminals: employee banking details, salary information, personal identification data, and the records of new starters whose details have not yet been verified by colleagues. A request to update a payroll bank account — appearing to come from the employee themselves or from a senior HR contact — is a common attack vector. The change may go undetected until the affected employee fails to receive their salary.



The Channel Has Shifted to Where Back-Office Teams Work


NASC data from 2025 shows that losses via online contact methods reached $158.5 million — a 21.8 per cent increase from the prior year — while losses from phone-based contact fell by 32 per cent. The fraud has migrated to the tools that back-office teams use every day: email, messaging platforms, supplier portals, and increasingly video conferencing.

This matters because the controls that organisations have historically relied on — caller ID verification, recognising unfamiliar phone numbers — are less relevant when the attack arrives through the same channels as legitimate internal communications.



Urgency and Confidentiality as Enablers


Back-office teams are accustomed to processing time-sensitive requests. Finance staff work to payment deadlines. HR teams handle sensitive matters that are not shared widely. These working conditions make both groups susceptible to requests framed as urgent and confidential — two characteristics that are deliberately engineered into BEC and impersonation attacks to prevent the target from pausing to verify.


The ACSC notes that the most significant factor in successful BEC attacks is not the sophistication of the technology but the absence of a mandatory verification step before the requested action is taken. Executive impersonation is therefore as much a process failure as a technical one.




How to Verify — Practical Checks for Back-Office Teams


The ACSC's guidance on business email compromise is consistent on one point: the most effective defence is not a technical control but a procedural one. An organisation that requires mandatory out-of-band verification before any payment or sensitive change is processed will stop the majority of BEC and impersonation attacks, regardless of how convincing the communication appears.


The following practices reflect the ACSC's published guidance and Scamwatch's recommendations for businesses.



1. Always Verify Through a Separate Channel — Not by Replying


When a request arrives by email, text, or messaging platform to transfer funds, change a bank account, or disclose sensitive information, the response should never be to reply to that message or call back on a number provided within it. The number may be controlled by the criminal.


Verification should use a contact detail that exists independently of the request — a number already stored in the organisation's records, on a supplier's official website, or on a previous verified invoice. This is what the ACSC refers to as out-of-band verification: confirming the request through a channel entirely separate from the one through which it arrived.


This applies equally to video call confirmations. A deepfake video call should not itself be treated as verification. Confirmation should come through an independent, pre-established channel.



2. Establish a Mandatory Second-Approval Process for Payments and Account Changes


No payment above a defined threshold, and no change to a payroll bank account or supplier payment detail, should be processed on the authority of a single person. A mandatory second approval — from a different staff member, through a separate communication — removes the single point of failure that BEC attacks depend on.


The threshold for requiring second approval should be set at a level that reflects the organisation's risk exposure, not its transaction volume. Where an attacker is impersonating an executive and instructing a finance team member directly, a second approver from outside that chain of command provides meaningful protection.



3. Treat Urgency and Confidentiality as Warning Signals


Scamwatch and the ACSC both identify urgency and requests for secrecy as characteristic features of executive impersonation and BEC attacks. A request framed as time-critical and not to be discussed with others is asking the recipient to bypass the normal controls that would otherwise apply.


Staff should be briefed to treat these features as reasons to pause and verify — not reasons to act faster. A process that stops when something feels wrong, rather than one that defers to the apparent authority of the requestor, is significantly more resistant to this category of attack.



4. Consider a Verbal Code Word for Sensitive Instructions


A pre-agreed code word used to authenticate urgent verbal or video requests — between senior executives and finance or HR staff — provides a simple and effective check that does not rely on voice or video recognition. Commonwealth Bank research from January 2026 found that 74 per cent of Australians agreed a safe word should be set up for this purpose, but only 20 per cent had done so.


The code word should be communicated in person or through a secure channel and changed periodically. It should not be stored in email or messaging platforms where it could be compromised.



5. Keep Payment and Contact Details Current and Verified


Scamwatch recommends that organisations independently verify supplier and payee contact details before processing any payment change request — including by contacting the supplier directly using a number sourced independently of the request. Commonwealth Bank research found that only 55 per cent of small businesses had cross-checked supplier payment details in the preceding six months.


Where a supplier or employee requests a change to banking details, the change should be confirmed through a call to a known number before it is applied — not through a reply to the email or message requesting the change.




What to Do If Your Organisation is Targeted


Speed is the most important factor in limiting the damage from a successful BEC or impersonation attack. Once funds have been transferred, recovery becomes significantly more difficult — but it is not always impossible if the organisation acts quickly.

STEP 1 — Contact your bank immediately

Call the bank's dedicated fraud line as soon as a fraudulent transfer is identified. Do not wait until the next business day. The sooner the transfer is reported, the greater the likelihood that funds can be recalled or blocked before they are moved further.


STEP 2 — Report to authorities

Report to Scamwatch and ACSC ReportCyber. Where the loss is significant or there is evidence of an organised criminal operation, report to the Australian Federal Police.

STEP 3 — Internal escalation and containment

Notify senior management, IT, and legal counsel. Review your cyber insurance policy for notification timeframes — some policies require notification within 24 hours, which is shorter than the legal obligations under the Privacy Act or the Cyber Security Act. Document the incident immediately.


If a Suspicious Request Has Been Received but No Action Taken


Where a staff member has received what appears to be a fraudulent request — but has not acted on it — the incident should still be reported internally and, where appropriate, to Scamwatch and ReportCyber. For guidance on reporting suspicious emails to email service providers, refer to the ACSC's published advice.


Reporting attempted fraud, even where no loss occurred, helps build the intelligence that supports broader disruption efforts.


Internal Steps Following Any Incident


Whether or not funds were transferred, any BEC or impersonation attempt should be treated as an organisational incident requiring a documented response. This includes:

  • Recording the details of the communication — the channel used, the content, the time, and any identifiers such as email addresses or phone numbers

  • Notifying senior management, IT, and legal counsel as appropriate

  • Reviewing whether existing verification processes were followed, and identifying any gaps

  • Briefing the wider team, without disclosing sensitive details, so that staff are aware the organisation has been targeted

A pattern of attempted attacks against the same organisation — even where none succeed — is itself intelligence worth capturing and acting on.


A Note on Cyber Insurance


Organisations that hold cyber insurance should review their policy terms before an incident occurs. Some policies impose notification timeframes that are shorter than the legal obligations under the Privacy Act or the Cyber Security Act — in some cases requiring notification within 24 hours. Knowing the policy requirements in advance avoids the risk of inadvertently voiding coverage through delayed notification.




The most effective defence against deepfake and BEC fraud is procedural rather than technical. Mandatory out-of-band verification before any payment or sensitive change is processed, a second-approval requirement for high-risk transactions, and a culture that treats urgency and requests for secrecy as warning signals rather than reasons to act faster — these are the controls that stop the majority of attacks regardless of how convincing the impersonation appears.


If an attack succeeds, the speed of the response determines the outcome. Contact the bank immediately, report to Scamwatch and ACSC ReportCyber, and treat the incident as an organisational event requiring documentation and review.


Official sources:




Last updated: September 2026




SHARE

Latest

HR

Employee Choice Pathway 2026: Casual Conversion Checklist & Lessons from Baker v Macquarie University

The Fair Work Commission's landmark Gregory Baker v Macquarie University [2026] FWC 3054 decision has fundamentally chan...

Employee Choice Pathway 2026: Casual Conversion Checklist & Lessons from Baker v Macquarie University
Finance & Accounting

Finance Digital Transformation: A Guide to Continuous Auditing Software in Australia (2026)

With the Australian Taxation Office (ATO) Corporate Plan 2026–27 placing a strategic focus on "enabling a move to real-t...

Finance Digital Transformation: A Guide to Continuous Auditing Software in Australia (2026)
Technology

AML/CTF Tranche 2 Privacy Compliance: Maintaining IT and Data Infrastructure Post-1 July 2026

Under expanded Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) laws, specific small business service pro...

AML/CTF Tranche 2 Privacy Compliance: Maintaining IT and Data Infrastructure Post-1 July 2026
HR

Right to Disconnect FWC Determinations: Section 333M Compliance and Policy Checklist for HR Teams

Following a series of landmark Fair Work Commission (FWC) determinations throughout late 2025 and 2026, Australia's Righ...

Right to Disconnect FWC Determinations: Section 333M Compliance and Policy Checklist for HR Teams
Finance & Accounting

AASB 18 Statement of Profit or Loss Redefinition: What the 1 January 2027 Accounting Standard Means for Finance Teams

Australian accounting standards are undergoing a major shift as AASB 18 replaces AASB 101, fundamentally altering how yo...

AASB 18 Statement of Profit or Loss Redefinition: What the 1 January 2027 Accounting Standard Means for Finance Teams
advertisement