The Number That Matters Most Isn't the Big One
Last year, 481,000 scams were reported in Australia. Australians lost more than $139 million through romance scams, $97 million through phishing scams, and $166 million through payment-redirection scams.
But here’s the number we want you to sit with: one.
One business owner who transferred $20,000 to a fraudulent payment link. One team member who read a verification code to a caller under pressure. One person who trusted a message because it arrived at exactly the right moment.
Scams Awareness Week 2026 — running 24–28 August under the theme*”No one’s just a number”* — makes a deliberate point: every report represents a real person whose money, time or trust has been taken. And being scammed is not a reflection of intelligence or character.
At iQtec, we work with SMBs every day. We see the same patterns Scamwatch describes playing out in business inboxes, payment processes and supplier conversations. This week, we want to connect the dots — between the human stories in the campaign, and what they actually look like when they target your business.

The Scam Patterns Hitting Businesses Right Now
The Scams Awareness Week 2026 campaign features four real victim stories. Each one has a direct equivalent in the business environment.
1. Urgency + A Fake Purchase = Phishing at Work
Lindy received a phone notification claiming a laptop purchase had succeeded. The message included a number to call. When she called, the scammer said they needed to close her account to stop the transactions and sent a verification code. Although the code warned it should not be shared, Lindy read it out under pressure. The scammer’s method was to rush her, create panic and keep her moving without pausing. She lost a large amount of money and was left in debt.
In a business context: This is a classic phishing play — and it’s increasingly AI-powered. Scammers now craft messages that imitate normal business tone, referencing real suppliers, projects or internal language, knowing that phishing targets decision-making rather than infrastructure. A staff member receiving an urgent notification about an unauthorised transaction on a company account faces the same trap Lindy did. The rush is the weapon.
What businesses can do: Build a rule that no verification code is ever shared over the phone — no matter who appears to be calling. Make this a process, not just a policy.
2. A Legitimate-Looking Payment Link = Business Payment Fraud
Mannu was arranging construction of a granny flat and expected to pay a $20,000 deposit to his builder. A payment link arrived at the expected point in the process and looked legitimate — but it was not from the builder. The money was stolen after he used it. His advice: be cautious with payment links, verify the website independently, and contact the organisation using a number you already hold on file.
In a business context: This is Business Email Compromise (BEC) and payment-redirection fraud — one of the most costly scam types for Australian businesses. Modern fraudulent payment messages are cleanly written and context-aware, potentially referencing real projects, invoice numbers and payment timing. Payment redirection works by quietly changing the destination account on a legitimate invoice and claiming the supplier has updated their banking details.Voice cloning is now also being used to weaken verbal verification — a short audio sample can create a convincing executive voicemail or call. iQtec’s position is clear: awareness training is useful but not sufficient when a fraudulent message is indistinguishable from a legitimate one. The burden must shift from individual suspicion to a repeatable payment process.
What businesses can do: Never approve a bank-detail change or out-of-cycle payment based on an email or payment link alone. Always call a known number — not the one in the email.
3. Trust Built Over Time = Social Engineering at Scale
Nikita received a friend request from someone posing as a British pilot, with convincing cockpit photographs. After weeks of conversation, he claimed his son was in hospital and asked for help. Nikita sent $5,000. After receiving the funds, the person disappeared. She stresses: it can happen to anyone.
In a business context: Scammers invest time building trust with staff — through fake LinkedIn connections, impersonated supplier relationships or long-running email conversations — before making a financial request. MFA fatigue attacks and hyper-targeted spear phishing are built on the same principle: understand the person’s context, relationships and habits, then exploit them.
What businesses can do: Treat any unsolicited communication that eventually leads to a money or credential request with the same scepticism, regardless of how long the relationship appeared to last.
4. A Plausible Message at the Right Moment = Impersonation
Susanne received messages from someone she believed was her daughter, claiming her phone was broken and bank account frozen, with several urgent payments required. Because her daughter was hosting a wellness retreat at the time, the story was plausible. Susanne transferred just under $26,000 before speaking with her actual daughter.
In a business context: Voice cloning and executive impersonation — including fake CFO payment requests, apparent CEO messages and impersonated IT-support calls — exploit exactly this dynamic: when the context is right, people trust. An employee receiving an urgent message from what appears to be the MD, asking for a quick payment before a meeting, faces the same test Susanne did.
What businesses can do: Build a culture where it’s safe — and expected — for staff to pause and verify any urgent payment request, even if it appears to come from leadership.
What All Four Stories Have in Common
Every story shows the same three elements: pressure (the target is pushed to act immediately), trust (the scammer appears to be a bank, builder, family member or partner), and a convincing story (the request aligns with something the person fears, expects or cares about).
This is not a technology problem. It’s a human and process problem. And it’s one iQtec helps businesses address at both layers.
The iQtec Perspective: Awareness Is a Start, Not a Solution
FAQs
iQtec approaches cybersecurity as a managed, continuously improving business capability — assessing risk and obligations, managing and monitoring controls, responding to incidents, and progressively maturing governance and compliance. The focus is on reducing risk, creating leadership confidence and supporting growth.
For scam and fraud protection specifically, that means two things working together:
The technical layer — managed spam and phishing filtering, email security policy, SPF, DKIM and DMARC monitoring, endpoint detection and response, SaaS collaboration security, dark-web credential monitoring, cloud MDR and managed SOC. These controls intercept threats before they reach your people.
The human and process layer — phishing targets decision-making rather than infrastructure. The right response is ongoing micro-training rather than annual-only modules, realistic phishing simulations, clear reporting routes and visible leadership participation.
iQtec helps strengthen both technical and human defences through awareness programmes, simulations and layered protection.
Both matter. Neither alone is enough.
The Stop. Check. Protect. Framework — Applied to Business
Scamwatch’s 2026 campaign uses a simple three-step framework. Here’s how it applies in a business context:
STOP — Before approving any urgent payment, sharing credentials or acting on an unexpected request, pause. Community research found that people responded positively to messages that reminded them they retained some control and could take protective action. In business, that control is a process step, not a gut feeling.
CHECK — Scammers commonly impersonate trusted organisations. Verify by contacting the person or organisation using contact details you already hold — not those supplied in the suspicious communication. In business: call your supplier on the number saved in your system.
Check the sender’s domain carefully. Never reply in the same email thread to confirm a payment change.
PROTECT — Act quickly if something feels wrong. Contact your bank immediately. Report to Scamwatch.
Change passwords and security details if you think they’ve been compromised. In business: also notify your IT provider immediately, so the technical response can begin alongside the financial one.
A Practical Checklist for SMBs This Week
☑ Share this article with your team today — start the conversation
☑ Review your payment-change verification process — is it a clear, enforceable procedure?
☑ Confirm that staff know they should never share verification codes over the phone
☑ Check that your email domain has SPF, DKIM and DMARC configured correctly
☑ Brief staff on Scamwatch’s Scam Stories archive — real stories are more memorable than generic advice
☑ If you think you’ve been targeted, contact your bank and iQtec immediately — early action matters
Every Scam Starts the Same Way. Your Response Doesn't Have To.
Scams don’t distinguish between a family member at home and a finance officer at a desk.
The tactics are the same: urgency, trust and a story that fits. Talking openly about scams is a protective action — it reduces stigma, helps people disclose incidents earlier and makes it harder for scammers to succeed.
This week, use that conversation as a starting point inside your business. And if you want to understand where your real exposure is — in your email environment, payment processes or team habits — that’s exactly the kind of structured review iQtec can help with.
Want to know where your business is exposed? iQtec helps Australian SMBs move from reactive security to a structured, practical approach — covering email protection, payment-process risk, staff awareness and ongoing monitoring. Talk to iQtec about a cybersecurity review
What is Scams Awareness Week 2026?
Scams Awareness Week is an annual national campaign intended to help Australians recognise, avoid and report scams. It brings together government, businesses, community organisations and individuals to strengthen the collective response to scammers.
How do these consumer scams relate to business risks?
The tactics are identical: urgency, impersonation and a convincing story. In business, they appear as payment-redirection fraud, executive impersonation, AI-generated phishing and fake supplier requests — often targeting staff who handle payments or credentials under time pressure.
What's the single most important thing a business can do right now?
Review your payment-change verification process. The burden should shift from individual suspicion to a repeatable process. Controls should include confirming any supplier-bank change through a known independent channel, never relying on replying in the same email thread, and using written verification procedures consistently.
Is security awareness training enough to protect my business?
Awareness training remains useful but is not sufficient when a fraudulent message is indistinguishable from a legitimate one. iQtec’s position is that the burden should shift from individual suspicion to a repeatable payment process, backed by technical controls.
What should I do if my business has been targeted?
Contact your bank immediately, report to Scamwatch and notify your IT provider so technical steps can begin in parallel. If credentials may have been compromised, change passwords and enable or enforce MFA without delay.
