Security

AI-era scams: deepfakes, voice clones & what Perth businesses should watch for

In 2017 we wrote a post warning people that Microsoft will not phone you and ask to fix your computer. In 2026, the scam isn't a guy with a heavy accent reading from a script. It's an AI that sounds exactly like your boss.

Welcome to the AI scam era. Here's what's actually happening, and what to do.

The four scams hitting Perth businesses right now

1. CEO voice-clone fraud

A 30-second voice sample from your LinkedIn video, fed into an AI model, produces a perfect clone. The "CEO" rings the finance team after-hours and asks for an urgent wire transfer to a "new supplier."

Defence: A second-channel verification rule for any payment instruction. No exceptions, no urgency-overrides.

2. Hyper-personalised AI phishing

Gone are the typo-laden Nigerian princes. Modern phishing emails are scraped from LinkedIn, your website, and recent press, then written by GPT-class models. They reference real colleagues, real projects, real invoice numbers.

Defence: DMARC enforcement on your domain, and a culture of "verify by phone before you click."

3. Fake Google Business Profile takeovers

Scammers claim ownership of your Google listing, change the phone number to theirs, and intercept your leads.

Defence: Quarterly check that you still have the verified owner role on Google Business. Set up alerts.

4. Browser pop-up "tech support" scams (the 2017 classic, with AI lipstick)

Fake "Microsoft Defender" pop-ups now use voice synthesis to sound like a real support agent. The lock-screen tactics are more convincing.

Defence: Hard rule for staff: No legitimate tech company will ever phone you, lock your screen, or ask for remote access unsolicited. When in doubt, close the browser, restart, ring us.

A simple "is it real?" checklist for staff

Print it, stick it next to monitors:

  1. Did I expect this email/call/SMS?
  2. Is it pressuring me to act right now?
  3. Is it asking me to move money, share credentials, or click a link?
  4. Have I verified through a known channel (phone number from your records, not the email)?

If the answer to 2 or 3 is yes and you can't tick 4, stop.

What we lock down for our hosting clients

  • DMARC enforcement (rejects spoofed mail before it lands).
  • Login attempt monitoring with geo-anomaly alerts.
  • Forced 2FA for all CMS users.
  • Daily backup verification.
  • Quarterly security review with the client.

It's not paranoia. It's just the cost of doing business in 2026.

TL;DR

The scammers got an AI upgrade. So should your defences. Train your team to be sceptical, lock your domain down properly, and have an answer for "if someone rings claiming to be the CEO, what do we do?"

security AI deepfakes scams