Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

The Industry Speaks: Scam Awareness Week 2026

The theme for this year’s Scam Awareness Week – which runs from 24 to 28 August – is “No one’s just a number”, and that’s certainly true of the industry leaders sharing their wisdom with Cyber Daily’s readers!

Fri, 21 Aug 2026
The Industry Speaks: Scam Awareness Week 2026

Christopher Rule
General Manager - Defence, Security and Resilience at GME Defence

While public awareness during Scams Awareness Week often centres on consumer fraud, businesses are facing an equally serious threat. Attackers are increasingly using phishing, social engineering and ransomware to infiltrate business systems, access sensitive data and control operational technology - not just steal money.

We're seeing scams move beyond the individual and into the heart of business infrastructure, with the aim of exfiltrating data, intellectual property and personal information. The recent Origin Energy breach is a timely reminder of how exposed operational systems can be. Experts now foreshadow the targeting of critical infrastructure as the next threat. Where our information networks touch the physical world, scams may put at risk our energy, water, manufacturing, and power capacity.

 
 

Through our partnership with Owl Cyber Defense, GME works with organisations to reduce this risk by limiting system exposure, strengthening access controls, and adopting a more resilient, Zero Trust-aligned approach to security.


Anthony Daniel
Managing Director - Australia, New Zealand and the Pacific Islands, at WatchGuard Technologies

Every year, Scam Awareness Week is framed as a reminder to “stay vigilant”. But vigilance alone is not enough when scam tactics are becoming increasingly difficult to tell apart from legitimate digital interactions. Attackers are hyper-personalising their approaches, using spoofed platforms, online advertisements, and fake websites to exploit trust, harvest credentials and quietly establish access.

The scale of the problem in Australia reflects that shift. According to the ACCC, Australians reported more than $2 billion in scam losses in 2025. Online scams involving financial loss increased by 31.8 per cent, and phishing remained the most commonly reported scam type. WatchGuard’s Threat Report points to the same broader trend towards more evasive activity, with new malware increasing every quarter and surging 1,548 per cent between Q3 and Q4 alone as attackers became increasingly effective at concealing malicious behaviour within seemingly legitimate traffic.

For Australian businesses, particularly those with limited security resources, the answer is not simply more reminders for employees to be careful before they click. Organisations need to accept that some highly convincing scams will succeed and build their security strategy around what happens next.

Multi-factor authentication remains essential, but it should be reinforced by continuous monitoring, behavioural analysis and Zero Trust principles that can identify when legitimate credentials are being misused. These controls give organisations greater visibility into what happens after a user logs in, helping security teams detect unusual behaviour and contain suspicious activity before it escalates.

Employee awareness remains important, but it cannot be the sole line of defence against increasingly sophisticated attacks. In 2026, the real test is how quickly an organisation can detect abnormal activity after the click, contain it and prevent one compromised account from becoming a broader business-wide incident.


Professor Mathews Nkhoma
Associate Deputy Vice Chancellor Strategy International & Engagement, College of Business and Law, at RMIT University

The national anti-scam system is currently at its strongest either before contact is made or after loss has occurred. Between these points lies a stage that is less formally recognised - the pre-transaction stage - when a victim of fraud and under pressure or deception, seeks access to funds.

This is the point at which behavioural intervention can prevent a scam from progressing and funds have not yet been irreversibly transferred.

Despite its significance, the pre-transaction stage is not formally recognised as a distinct intervention layer within the national anti-scam architecture.

A proposed pre-transaction stage strategy would operate through existing service infrastructure rather than requiring a new institution, with the purpose of interrupting scam-related harm at the moment when deception intersects with financial decision-making.

Community finance services operate precisely at this point of decision. A staged pilot would test and refine this intervention layer, assessing its effectiveness, safeguards and integration within the broader anti-scam framework.


Mariana Paun
Chief Business Resilience Officer at Zepto

From 1 September 2026, the core rules of the Scam Prevention Framework take effect, imposing strict duties on banks, telecommunications providers, and digital platforms to detect, disrupt and respond to scams. With payment redirection being the second-largest scam loss category in 2025, costing Australians over $166 million, the message is clear: the controls you have in place at the moment money moves will determine whether you protect your customers or face regulatory consequences.

Fortunately for businesses, the industry has responded to this growing threat with the roll out of Confirmation of Payee (CoP), an industry-wide security service that matches the account details a business enters with the account details held by the recipient’s bank. Since launching in July 2025, CoP has surpassed more than 150 million checks and has become the front-line defence against payments fraud and scams. Zepto’s own platform data shows that one in three payments checked by CoP in the first half of 2026 were flagged for closer inspection, demonstrating the importance of verifying before money moves.

While scam awareness efforts rightfully focus on educating businesses and consumers about the social engineering tactics bad actors use, businesses cannot neglect the moment at which money moves and the deception succeeds. Those who embed safer security controls into their payment flows will not just meet incoming compliance expectations, they’ll be directly addressing the critical vulnerability where Australians are losing the most.


Heng Mok
CISO-in-Residence, Asia Pacific-Japan, at Zscaler

This Scam Awareness Week, organisations should recognise that scam prevention can no longer rely on individual caution or basic security controls alone. With Australia’s Scams Prevention Framework set to require regulated banks, telcos and digital platforms to prevent, detect, disrupt, report and respond to scams, scam prevention is, and should be, a business resilience and governance priority.

Zscaler research shows why this shift matters: Australia is among the top 10 most targeted countries globally for phishing activity. This comes as attackers continue to abuse legitimate AI platform features, such as shareable chats, to make malicious content appear more credible.

MFA can no longer be treated as the final line of defence. Organisations need stronger visibility, identity-based controls and Zero Trust principles to reduce the risk of scams becoming a broader compromise.


Adrian Covich
Vice President Systems Engineering APJ, at Proofpoint

The integration of artificial intelligence into cybercrime has fundamentally shifted the threat landscape, turning what were once easily identifiable scams into highly sophisticated attacks that cost the Australian economy billions.

According to the ACCC’s National Anti-Scam Centre, Australians lost $2.18 billion to scams in 2025. For Australian businesses, this evolution is most acutely felt through the rise of Business Email Compromise (BEC). By preying on finance teams hunting for savings amidst a high volume of administrative work, attackers create a false sense of urgency that tricks employees into bypassing verification protocols and authorising payments directly into criminal accounts.

However, despite this, Australian businesses must recognise that scams are fundamentally a people problem, exploiting human behaviour and trust at scale. A human-centric approach to security requires combining continuous, context-driven employee education with behaviour-based controls and robust threat intelligence to detect malicious intent and block fraudulent requests before a transaction can occur.


Jason Duerden
VP ANZ at SentinelOne

Scammers have traditionally faced a choice between volume and personalisation. LLMs remove that trade-off, while AI agents add something more dangerous: persistence. They can research targets, generate tailored approaches and keep testing different routes without becoming tired or deciding the effort is no longer worthwhile.

We’ve already seen this behaviour in cyber incidents. An AI agent took around 17,600 actions during the recent Hugging Face intrusion, most of which failed, but it rebuilt tools, restored communications and continued for two and a half days. Applied to scams, that same persistence could allow criminal groups to pursue thousands of Australians with approaches shaped around their provider, workplace or recent activity.

The Scams Prevention Framework must account for the full sequence. A social media ad, telco message, account login and bank transfer may each appear ordinary in isolation. Stopping the scam depends on connecting those signals before the money leaves, at the same speed the attacker is operating.”


Fred Slikker
Managing Director at Digidentity

For years, scam prevention has relied on people noticing that something doesn’t look or sound quite right. That advice is becoming less useful when a deepfake can recreate a familiar face, stolen customer data can supply the correct personal details and a spoofed number can appear to belong to a trusted organisation. Even together, those signals don’t prove that someone genuinely represents the organisation they claim to, or has authority to make the request.

The Scams Prevention Framework should drive a much higher standard of verification by organisations, not simply at the point a customer is onboarded, but throughout the lifecycle of a relationship. Organisations need to be confident not only that a person is who they claim to be, but that they are authorised to act on behalf of an organisation and that the documents, instructions or mandates they provide are genuine and current. The burden should not fall on consumers to make these judgements under pressure. Organisations should have robust, independent ways to verify identity, authority and the authenticity of the evidence on which transactions and decisions are based.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: