How to recognise and safely handle a deepfake voice or AI-generated scam call targeting Australian businesses
Summary
This guide helps you troubleshoot and resolve: How to recognise and safely handle a deepfake voice or AI-generated scam call targeting Australian businesses. Follow the steps below to fix the issue.
Common Causes
Deepfake voice scams, sometimes called AI vishing, are a growing threat to Australian small businesses and home offices. Criminals use artificial intelligence to clone a trusted person's voice from a short audio sample, then call pretending to be a colleague, supplier, or even your managing director to request urgent payments, password resets, or remote access. This guide explains how to recognise the warning signs and respond safely if your business is targeted.
What a deepfake voice scam looks like
Most AI-generated scam calls share a few common patterns. Knowing them helps your team react quickly instead of reacting emotionally.
- Urgency or secrecy: The caller pressures you to act immediately, bypass normal approval processes, or keep the request confidential.
- Familiar voice, unusual request: The voice sounds like a boss, supplier, or staff member, but the request is unusual, such as a wire transfer, gift cards, or remote access.
- Audio tells: Slight robotic cadence, odd pauses, flat emotional tone, or background noise that sounds synthetic.
- Channel switch: The caller asks you to move to email, SMS, WhatsApp, or a messaging app to continue the conversation.
- Verification refusal: The caller discourages you from checking with anyone else or hangs up when challenged.
Detailed Instructions
Step 1: Hang up and pause
The single most effective defence is to stop the call. Scammers rely on urgency and fear. Once you hang up, you regain control and can verify the request calmly.
- Do not press any keys or follow prompts if it is a recorded message.
- Do not call back the number that appeared on your caller ID, as it may be spoofed.
- If you were mid-task, close any remote session or payment screen you opened.
Step 2: Verify through a trusted channel
Contact the person or organisation directly using a number you already trust.
- Open your phone contacts or company directory.
- Dial the number stored there, or send a message on a platform you have used before.
- Ask the person to confirm the request using a pre-agreed phrase or question only they would know.
- If you cannot reach them, speak to another manager or colleague before acting.
Step 3: Check your accounts and devices
If the call led to any action, treat it as a potential compromise.
- Review recent transactions in your banking portal and flag any you did not authorise.
- Check email rules for new forwarding filters or auto-replies you did not create.
- Look at sign-in activity in
Microsoft 365orGoogle Workspaceadmin consoles for unfamiliar locations. - Confirm multi-factor authentication is still enabled on all admin and finance accounts.
Step 4: Notify your team and document the incident
Scammers often target multiple people in the same organisation. A quick internal alert prevents repeat attempts.
- Send a brief warning email or message to staff describing the approach.
- Record the date, time, caller number, and a summary of what was said.
- Save any voicemails as evidence before they are deleted.
- Update your internal finance and IT procedures to require in-person or video verification for any unusual payment or access request.
Step 5: Report the scam
Reporting helps protect your business and the wider Australian community.
- Open a ticket with 220 through the support portal so our security team can review your account and advise on next steps.
- Report the call to Scamwatch via the Australian Competition and Consumer Commission website.
- If money or sensitive data was shared, report it to ReportCyber (Australian Cyber Security Centre) and your bank.
Preventative measures for your business
Building a few habits into your daily operations makes deepfake scams far less effective.
Use a callback verification policy
Any request involving payments, credentials, or access must be verified by calling the requester back on a known number. Make this a written policy and include it in your staff onboarding.
Limit publicly available voice samples
- Remove personal phone numbers from public websites and social media bios.
- Avoid uploading high-quality voice recordings to public platforms.
- Set voicemail greetings to be brief and consider using text-only alternatives where possible.
Strengthen authentication
- Require multi-factor authentication on every business account, especially email, banking, and remote access tools.
- Use a password manager so staff never need to read credentials aloud during a call.
- Restrict remote desktop or admin access to managed devices only.
Train your team regularly
Run short, realistic phishing and vishing simulations each quarter. Keep reporting simple: if something feels off, staff should hang up and forward the details to a single internal email address or ticketing queue.
Troubleshooting
The caller knew internal details about my business
This is common. Information may come from a previous data breach, LinkedIn profiles, supplier websites, or earlier social engineering attempts. Treat any unusual request as suspicious regardless of how accurate the background details sound.
The voice sounded exactly like my colleague
Modern voice cloning is highly convincing. Verification must come from a separate channel and a pre-agreed factor, such as a callback on a known number, a video call, or a security question that is not based on publicly available information.
I already transferred money or shared a password
Act quickly.
- Contact your bank immediately to attempt a recall or freeze on the transaction.
- Change the compromised password from a clean device and review active sessions.
- Open a ticket with 220 through the support portal so we can help secure your accounts and audit access logs.
- Report to ReportCyber and keep all evidence for the investigation.
I am unsure whether the call was genuine
When in doubt, treat it as a scam. There is no harm in hanging up and verifying through a trusted channel. A legitimate caller will understand the delay.
Still Having Issues?
💻 Open a Ticket