Most people believe they know what a cyber scam looks like.
The email will be badly written.
The logo will look wrong.
The request will be so unusual that no sensible person would trust it.
That description may have been reasonably accurate once.
It is becoming much less useful today.
At our recent Geelong Cyber Sip event, guest speaker Paul Barge from Kaseya explained how artificial intelligence is changing the way cybercriminals operate.
Paul’s presentation covered the broader scale of cybercrime in Australia, but one of the most important lessons was what AI now allows criminals to create.
Phishing emails can be written in polished, natural language.
Fake websites can closely imitate legitimate brands.
Voices can be copied from a few seconds of audio.
Video meetings can be created using convincing deepfakes.
The traditional warning signs are becoming harder to rely on.
That is exactly why events such as Cyber Sip matter to us at eManaged.
Technology changes quickly, and the information businesses need to protect themselves changes with it.
Much like our Lunch & Learn sessions, Cyber Sip is about bringing current, practical information directly to local business communities.
We want people to understand what is happening, why it matters and what they can do next.
Paul’s Geelong session was an excellent example of that.
AI is helping criminals move faster
Artificial intelligence has created enormous opportunities for legitimate businesses.
It can help people draft documents, analyse information, improve customer service and automate repetitive work.
Those same capabilities are also available to criminals.
A scammer no longer needs strong writing skills to create a convincing email.
They can use AI to produce professional messages in seconds.
They can adjust the tone to suit a particular industry, imitate the language used by a supplier or create several variations of the same campaign.
This dramatically increases the volume of attacks.
In the past, a criminal may have needed to spend considerable time building each message.
Now, campaigns can be generated and launched at scale.
That means businesses are not only dealing with better scams.
They are dealing with many more of them.
Phishing no longer looks amateur
For years, cybersecurity training told people to look for poor grammar and spelling mistakes.
Those signs are still worth noticing, but they are no longer enough.
A modern phishing email may look almost identical to a genuine message from Microsoft, Australia Post, a bank, a supplier or a delivery company.
The branding may be accurate.
The writing may be clear.
The request may appear completely reasonable.
Paul explained that these messages often lead to a second page designed to look just as convincing as the email.
Someone clicks the link and arrives at what appears to be a familiar login page.
They enter their username and password.
The page may then show an error or redirect them to the genuine website.
The person may never realise their credentials have been stolen.
What makes this especially dangerous is that the message often arrives in a believable context.
A shipping notification lands while the business is expecting a delivery.
A payment request arrives near the end of the month.
A Microsoft alert appears while someone is already having trouble signing in.
The criminal does not need the message to be perfect.
They only need it to feel plausible for a few seconds.
Busy people are easier to manipulate
Paul shared his own experience of falling for a fraudulent message related to road tolls.
He had recently had his wallet stolen and was updating financial details across several services.
When a message arrived asking him to update payment information, it made sense in the circumstances.
He entered the details.
Soon afterwards, multiple laptops were reportedly purchased using his information.
Paul has worked in technology for decades.
He understands cybersecurity.
The scam did not succeed because he lacked intelligence or experience.
It succeeded because it arrived at a moment when the story felt believable.
That is an important lesson for every organisation.
Cybercriminals do not necessarily need employees to be careless.
They need them to be busy, distracted or under pressure.
Most people do not analyse every email with complete attention.
They are moving between tasks, answering calls, helping customers and trying to meet deadlines.
Scams are designed around that reality.
Business email compromise is particularly dangerous
One of the most serious threats Paul discussed was business email compromise.
This occurs when criminals gain access to a legitimate email account and quietly monitor the conversations taking place.
They may remain there for days or weeks.
Their goal is often not to cause an immediate disruption.
They are waiting for the right opportunity.
A discussion begins about a property settlement, supplier payment or major purchase.
The criminal watches the conversation and learns how the people involved communicate.
At the right moment, they insert themselves into the thread.
A message appears explaining that the bank details have changed.
Because it arrives inside an existing conversation and comes from a familiar address, the request appears genuine.
The payment is made.
By the time anyone realises what happened, the money may already be gone.
This kind of attack works because it uses trust that already exists.
The email address is real.
The conversation is real.
Only the final instruction is fraudulent.
That is why unusual payment requests should always be verified through another channel.
The person requesting the change should be contacted using a known phone number, not a number included in the email itself.
A second person should be involved when significant amounts of money are being transferred.
The extra step may feel inconvenient.
It is far less disruptive than recovering from a fraudulent payment.
Voice cloning changes the meaning of verification
Businesses have traditionally been told to pick up the phone when an email request looks suspicious.
That remains good advice, but AI is also changing what can happen over the phone.
Paul explained that modern technology can imitate a person’s voice using only a few seconds of audio.
For public figures, executives and business owners who appear online, there may already be more than enough audio available.
A criminal could potentially copy the voice of a manager, customer or supplier and use it to support a fraudulent request.
The call may sound real.
The tone may be familiar.
The sense of urgency may push the recipient to act quickly.
This does not mean every phone call should be treated with suspicion.
It does mean businesses need stronger verification processes for high-risk requests.
That could involve an agreed code word, confirmation through a known internal system or approval from more than one person.
The key is to decide on the process before an urgent request arrives.
Deepfake video is no longer science fiction
Paul also shared an example involving a fraudulent online meeting.
An employee joined what appeared to be a normal video call with colleagues and the company’s chief financial officer.
The people on screen looked and sounded legitimate.
The meeting continued for several minutes.
At the end, the employee was instructed to transfer a substantial amount of money.
The transfer was made.
The meeting had been created using deepfake technology.
For many small businesses, an incident of that scale may feel remote.
The technology behind it is not.
Deepfakes are becoming easier to create, and the quality continues to improve.
Businesses increasingly rely on video calls for approvals, meetings and financial decisions.
That creates another opportunity for criminals to exploit trust.
Seeing a person on screen can no longer be treated as absolute proof of identity.
The human element remains critical
Paul noted that human error is involved in a large proportion of successful cyber incidents.
That statistic is sometimes used to describe employees as the weakest link.
That language can be unhelpful.
People are not weak because they are human.
They are operating in environments where sophisticated scams are deliberately designed to manipulate trust, urgency and routine.
The goal should not be to blame employees.
It should be to support them.
Staff need practical training that reflects the threats they are likely to encounter now.
They need to understand that a well-written email can still be malicious.
They need to know that a familiar voice may not always be genuine.
Most importantly, they need a clear and safe way to report something when they are unsure.
If employees fear embarrassment or punishment, they may keep quiet after clicking a suspicious link.
That delay can allow a small incident to become much more serious.
A strong security culture encourages people to speak up quickly.
Training needs to stay current
One-off cybersecurity training is no longer enough.
The threat environment is changing too quickly.
Employees need regular exposure to realistic examples.
Phishing simulations can help businesses understand how staff respond to current techniques.
The purpose is not to catch people out.
It is to identify where more support is needed.
Someone may easily recognise a badly written scam but struggle with an email that perfectly imitates Microsoft.
Another employee may spot the message but not know how to report it.
Training should help close those gaps.
It should also reinforce the idea that cybersecurity is part of everyday work, not a technical subject that belongs only to the IT team.
Technology still has an important role
People are an essential part of cybersecurity, but they should not be expected to carry the full burden.
Good technology creates additional layers of protection.
Email security tools can analyse incoming messages and identify suspicious patterns.
Multifactor authentication can make stolen passwords less useful.
Dark web monitoring can alert the business when credentials have been compromised.
Regular patching closes known weaknesses.
Backups help the business recover when data is encrypted or lost.
These controls are most effective when they work together.
Paul used the story of the three little pigs to explain layered security.
One house had almost no protection.
Another had made some improvements but still relied on limited defences.
The final house had several layers, active monitoring and people continuously watching for new threats.
The point was not that any system is impossible to breach.
It was that stronger layers make the business far more difficult and expensive to attack.
Cybercriminals often look for easier opportunities.
Making your business harder to compromise can be enough to send them elsewhere.
Why Cyber Sip matters to us
At eManaged, we do not believe cybersecurity information should only be available to large companies with specialist teams.
Local businesses deserve access to the same quality of insight.
That is why we run Cyber Sip events.
They give people the opportunity to hear directly from experts such as Paul Barge, understand how the threat landscape is evolving and ask questions in a practical setting.
We were delighted to have Paul join us in Geelong.
His presentation was informative, engaging and honest about the challenges businesses now face.
The biggest takeaway was not that artificial intelligence should be feared.
It was that businesses need to update the way they think about trust.
A professional email may still be fake.
A familiar voice may have been copied.
A video meeting may not be what it appears to be.
That does not mean organisations should become paralysed by suspicion.
It means they need better training, stronger verification processes and security systems designed for the world as it is now.
At eManaged, we help businesses build those layers.
We work with organisations to strengthen their technology, train their people and put clear processes in place so one convincing message is less likely to become a major incident.
Because as the scams become smarter, businesses need to become better prepared.
Talk to eManaged about helping your team recognise modern cyber threats and respond with confidence.
