Home › Knowledgebase › KB-556

How to recognise and safely handle a deepfake voice or AI-generated scam call targeting Australian businesses

Summary

This guide helps you troubleshoot and resolve: How to recognise and safely handle a deepfake voice or AI-generated scam call targeting Australian businesses. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Deepfake voice scams, sometimes called AI vishing, are a growing threat to Australian small businesses and home offices. Criminals use artificial intelligence to clone a trusted person's voice from a short audio sample, then call pretending to be a colleague, supplier, or even your managing director to request urgent payments, password resets, or remote access. This guide explains how to recognise the warning signs and respond safely if your business is targeted.

What a deepfake voice scam looks like

Most AI-generated scam calls share a few common patterns. Knowing them helps your team react quickly instead of reacting emotionally.

Even a 30-second sample from a social media video or voicemail greeting can be enough to train a convincing voice clone. Assume any voice can be spoofed.

Detailed Instructions

Step 1: Hang up and pause

The single most effective defence is to stop the call. Scammers rely on urgency and fear. Once you hang up, you regain control and can verify the request calmly.

Step 2: Verify through a trusted channel

Contact the person or organisation directly using a number you already trust.

  1. Open your phone contacts or company directory.
  2. Dial the number stored there, or send a message on a platform you have used before.
  3. Ask the person to confirm the request using a pre-agreed phrase or question only they would know.
  4. If you cannot reach them, speak to another manager or colleague before acting.
Never use contact details provided by the caller during the suspicious call. Scammers routinely give a fake "direct line" that routes straight back to them.

Step 3: Check your accounts and devices

If the call led to any action, treat it as a potential compromise.

Step 4: Notify your team and document the incident

Scammers often target multiple people in the same organisation. A quick internal alert prevents repeat attempts.

  1. Send a brief warning email or message to staff describing the approach.
  2. Record the date, time, caller number, and a summary of what was said.
  3. Save any voicemails as evidence before they are deleted.
  4. Update your internal finance and IT procedures to require in-person or video verification for any unusual payment or access request.

Step 5: Report the scam

Reporting helps protect your business and the wider Australian community.

  1. Open a ticket with 220 through the support portal so our security team can review your account and advise on next steps.
  2. Report the call to Scamwatch via the Australian Competition and Consumer Commission website.
  3. If money or sensitive data was shared, report it to ReportCyber (Australian Cyber Security Centre) and your bank.

Preventative measures for your business

Building a few habits into your daily operations makes deepfake scams far less effective.

Use a callback verification policy

Any request involving payments, credentials, or access must be verified by calling the requester back on a known number. Make this a written policy and include it in your staff onboarding.

Limit publicly available voice samples

Strengthen authentication

Train your team regularly

Run short, realistic phishing and vishing simulations each quarter. Keep reporting simple: if something feels off, staff should hang up and forward the details to a single internal email address or ticketing queue.

Troubleshooting

The caller knew internal details about my business

This is common. Information may come from a previous data breach, LinkedIn profiles, supplier websites, or earlier social engineering attempts. Treat any unusual request as suspicious regardless of how accurate the background details sound.

The voice sounded exactly like my colleague

Modern voice cloning is highly convincing. Verification must come from a separate channel and a pre-agreed factor, such as a callback on a known number, a video call, or a security question that is not based on publicly available information.

I already transferred money or shared a password

Act quickly.

  1. Contact your bank immediately to attempt a recall or freeze on the transaction.
  2. Change the compromised password from a clean device and review active sessions.
  3. Open a ticket with 220 through the support portal so we can help secure your accounts and audit access logs.
  4. Report to ReportCyber and keep all evidence for the investigation.

I am unsure whether the call was genuine

When in doubt, treat it as a scam. There is no harm in hanging up and verifying through a trusted channel. A legitimate caller will understand the delay.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket