← Field Notes
·16 August 2026·4 min read

AI Invoice Scams Cost Australian Businesses $167m in 2025

Payment redirection scams hit Australian businesses for $166.8m in 2025, and AI now writes the fake invoices and clones the voices. One free rule stops them.

Australian businesses lost $166.8 million to payment redirection scams in 2025 — the fraud where a criminal impersonates a supplier, or your own director, and quietly reroutes a legitimate payment into their account. That's up 9.3 per cent on the year before. And AI is the reason it keeps working: the fake invoice now reads perfectly, and the 'urgent' call confirming a new bank account can be a cloned copy of a voice you know.

The National Anti-Scam Centre's Targeting Scams report for 2025, published by the ACCC on 30 March 2026, put total reported scam losses at $2.18 billion. Payment redirection — the category that lands squarely on businesses — accounted for $166.8 million of that, second only to investment scams. ACCC Deputy Chair Catriona Lowe named the driver directly: scam activity is growing more sophisticated 'through Artificial Intelligence and the industrialisation of criminal syndicates'.

The mechanics are old; the polish is new. A payment redirection scam intercepts or imitates a real business email thread — a supplier's invoice, a request to 'update our account details' — and swaps the account number. What used to give it away, the broken English and the odd formatting, is gone. Generative AI writes fluent, on-brand messages in seconds. The newer escalation is audio: attackers need only a few seconds of a recording to clone a voice, so the follow-up phone call can sound exactly like the person it claims to be.

$166.8m

Lost to payment redirection scams

Australia, 2025 — up 9.3% on 2024

$2.18bn

Total reported scam losses

All Australian scams, 2025 (NASC)

15%

Business cybercrime that is email compromise

Most common attack with a loss (ASD)

Want to know what this means for your business? We'll map it in one call.

Book a call →

This is a cash problem before it is an IT problem. A trades business paying a $40,000 supplier invoice, or an accounting firm moving client funds, is one swapped account number away from a loss no one notices until the real supplier chases payment weeks later. By then the money has cleared, and in most cases it is unrecoverable. Business email compromise — intercepting or fabricating invoices to redirect payments — is already the most common cyber attack causing a financial loss for Australian businesses, at 15 per cent of reported incidents, per the ASD's Annual Cyber Threat Report. We've written before about how SMEs adopted AI faster than they secured it; payment redirection is where that gap turns expensive.

The uncomfortable part is that the controls most owners reach for don't catch this one. Antivirus doesn't stop it. A spam filter doesn't, because the email is often genuine — a real supplier account that's been compromised, or a lookalike domain a busy eye won't clock. Multi-factor authentication protects your logins, not your accounts-payable process. The attack targets a decision, not a device: someone approving a bank-detail change under time pressure. If you're not sure where a decision like that sits in your own business, a short call will map it.

The defence costs nothing. Never change a supplier's or an employee's bank details on the strength of an email or a phone call alone. Verify every change by calling the person back on a number you already had — not the one in the message. Put a second pair of eyes on any payment over a threshold you set. And treat urgency as a warning, not a reason to hurry: 'pay this today or we lose the discount' is the scammer's oldest lever, now delivered in a familiar voice.

The ASD's free small-business guidance at cyber.gov.au and the ACCC's Scamwatch both spell out the same callback rule. It works because it breaks the one thing AI can't fake for the criminal: a channel they don't control. This is the mirror image of the caution we urged before you hand an AI agent access to your business data — same principle, applied to the humans and machines asking you to move money.

Key takeaways

Payment redirection scams cost Australian businesses $166.8 million in 2025, up 9.3 per cent on 2024, out of $2.18 billion in total reported scam losses (National Anti-Scam Centre, Targeting Scams 2025, published March 2026).
AI removes the old tells: fluent, on-brand fake invoices and cloned voices make supplier and boss impersonation far harder to spot.
Antivirus, spam filters and MFA don't stop it — the attack targets an approval decision, not a device.
The fix is free: verify any bank-detail change by calling back on a number you already had, and require a second approver above a set threshold.

Common questions

What is a payment redirection scam?

A criminal intercepts or impersonates a legitimate business email or call and swaps the bank account on an invoice or payment request, so a genuine payment lands in their account instead. It cost Australian businesses $166.8 million in 2025.

How is AI making invoice scams worse?

AI writes fluent, on-brand fake emails with none of the old spelling or formatting giveaways, and can clone a familiar voice from a few seconds of audio to confirm the fake request by phone.

How do I stop payment redirection fraud?

Never change bank details on an email or call alone. Verify every change by calling back on a number you already had — not the one in the message — and require a second approver on payments over a threshold you set.

Sources

National Anti-Scam Centre — Targeting Scams 2025 report (ACCC, March 2026)

ACCC — Annual scam losses exceed $2 billion (media release, 30 March 2026)

ASD — Annual Cyber Threat Report 2024-2025 (October 2025)

Assumptions & methodology
  1. The $166.8 million payment redirection figure and the $2.18 billion total are from the National Anti-Scam Centre's Targeting Scams report on 2025 scam data, published by the ACCC on 30 March 2026. The 9.3 per cent rise is measured against the 2024 payment redirection figure of $152.6 million reported in the same series.
  2. The 15 per cent business-email-compromise figure is from the ASD's Annual Cyber Threat Report 2024-25 (published October 2025) — the share of reported business cybercrime incidents with a financial loss attributed to business email compromise.
  3. The voice-cloning description reflects publicly reported capabilities of current AI audio tools and guidance published on the ACCC's Scamwatch; it is not a claim about any specific Australian case.

Related notes

ShareLinkedInEmail

Field Notes are general commentary on AI trends for Australian businesses. They don’t constitute professional advice. Talk to your accountant, lawyer, or IT adviser before acting on anything specific to your situation — or talk to us if you want help working out where AI fits.

Don't miss the next one

Get each new Field Note in your inbox as it publishes — short, practical AI intelligence for business owners.

Not sure where a fake invoice could slip through your business?

A short call maps where money leaves your business and where a verification step belongs. Book a call to talk it through.

Book a call →