Australian Taxation Office, Australian Bureau of Statistics, Commonwealth Bank and Australian Banking Association: 4 in 5 SMEs report being exposed to scams

Australian Taxation Office, Australian Bureau of Statistics, Commonwealth Bank and Australian Banking Association: 4 in 5 SMEs report being exposed to scams

Australian SMEs Face Growing Threat from Scammers as Cybercriminals Exploit Vulnerabilities

Small and medium-sized enterprises (SMEs) in Australia are increasingly targeted by scammers, with cybercriminals leveraging impersonation tactics, fake invoices, and remote access schemes to steal funds and sensitive data. According to the Australian Bureau of Statistics (ABS) and Pyxis polling, 62% of businesses with 1–4 employees and 84% of those with 5–19 staff maintain an online presence, making them prime targets for fraud.

The Australian Banking Association (ABA) has warned that scammers exploit the busy schedules of business owners, often tricking them with convincing fake invoices or impersonating trusted suppliers. A single fraudulent transaction can devastate smaller operators, with ABA CEO Simon Birmingham noting that criminals actively seek weaknesses in everyday business processes.

Three common scam types highlighted by the ABA include:

  • Fake invoice scams: Fraudulent invoices mimicking legitimate suppliers but with scammer-controlled bank details.
  • Remote access scams: Criminals posing as tech support or banks to gain control of company systems and credentials.
  • Business impersonation scams: Fraudsters impersonating businesses to defraud customers, risking reputational damage.

ABA research reveals that 30% of businesses had a suspicious transaction flagged by their bank in the past year, while 20% reported a blocked transaction. Banks are enhancing protections, including the rollout of Confirmation of Payee a system designed to verify payee details before transactions are processed.

However, behavioral research from CommBank’s Behavioural Science Centre of Excellence indicates that many Australians attempt to handle scams alone rather than seeking input from colleagues or trusted contacts. A striking 72% of scammed employees did not discuss the incident with others before realizing it was fraud. Additionally, 63% of business owners cited barriers to discussing scams, including concerns about alarming customers, time constraints, and perceived lack of responsibility.

CommBank’s fraud and scams executive, James Roberts, emphasized that scammers exploit isolation, pressuring victims into quick decisions without verification. Behavioral scientist Caitlin Court added that sharing near-miss experiences such as spotting a suspicious email can help others recognize similar threats.

Separately, the Australian Taxation Office (ATO) confirmed it is assisting tax professionals targeted by cybercriminals, primarily through malicious email links and attachments. The ATO’s response follows reports of malware infections affecting practitioners, underscoring the broader risk of phishing attacks across industries.

Source: https://www.cyberdaily.au/security/14122-4-in-5-smes-report-being-exposed-to-scams

Australian Taxation Office TPRM report: https://www.rankiteo.com/company/australian-information-security-association

Australian Bureau of Statistics TPRM report: https://www.rankiteo.com/company/australian-strategic-policy-institute

Commonwealth Bank TPRM report: https://www.rankiteo.com/company/commonwealthbank

Australian Banking Association TPRM report: https://www.rankiteo.com/company/australian-banking-association

"id": "auscomausaus1788224259",
"linkid": "australian-banking-association, commonwealthbank, australian-information-security-association, australian-strategic-policy-institute",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['General business', 'Tax professionals'],
                        'location': 'Australia',
                        'size': ['1-4 employees', '5-19 employees'],
                        'type': 'SMEs (Small and Medium-sized Enterprises)'}],
 'attack_vector': ['Impersonation',
                   'Fake invoices',
                   'Remote access schemes',
                   'Malicious email links/attachments'],
 'data_breach': {'personally_identifiable_information': 'Potentially (via '
                                                        'phishing/malware)',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, financial data)',
                 'type_of_data_compromised': ['Credentials',
                                              'Payment information',
                                              'Sensitive business data']},
 'description': 'Small and medium-sized enterprises (SMEs) in Australia are '
                'increasingly targeted by scammers, with cybercriminals '
                'leveraging impersonation tactics, fake invoices, and remote '
                'access schemes to steal funds and sensitive data.',
 'impact': {'brand_reputation_impact': 'Risk of reputational damage (business '
                                       'impersonation scams)',
            'data_compromised': 'Sensitive data, credentials, payment '
                                'information',
            'financial_loss': 'Devastating for smaller operators (single '
                              'fraudulent transaction)',
            'operational_impact': 'Disruption of business processes, '
                                  'reputational damage',
            'payment_information_risk': 'Fraudulent transactions, '
                                        'scammer-controlled bank details',
            'systems_affected': 'Company systems (via remote access scams)'},
 'initial_access_broker': {'entry_point': ['Malicious email links/attachments',
                                           'Remote access scams']},
 'lessons_learned': 'Scammers exploit isolation and pressure victims into '
                    'quick decisions without verification. Sharing near-miss '
                    'experiences can help others recognize threats.',
 'motivation': ['Financial gain', 'Data theft'],
 'post_incident_analysis': {'corrective_actions': ['Enhanced monitoring',
                                                   'Verification systems '
                                                   '(*Confirmation of Payee*)',
                                                   'Awareness campaigns'],
                            'root_causes': ['Lack of verification processes',
                                            'Isolation of employees',
                                            'Phishing vulnerabilities',
                                            'Busy schedules of business '
                                            'owners']},
 'recommendations': ['Implement *Confirmation of Payee* or similar '
                     'verification systems',
                     'Encourage employees to discuss suspicious incidents with '
                     'colleagues',
                     'Raise awareness of common scam tactics (fake invoices, '
                     'remote access, impersonation)',
                     'Enhance monitoring for suspicious transactions',
                     'Improve verification processes for suppliers and '
                     'payments'],
 'references': [{'source': 'Australian Bureau of Statistics (ABS) and Pyxis '
                           'polling'},
                {'source': 'Australian Banking Association (ABA)'},
                {'source': 'CommBank’s Behavioural Science Centre of '
                           'Excellence'},
                {'source': 'Australian Taxation Office (ATO)'}],
 'regulatory_compliance': {'regulatory_notifications': 'ATO assisting tax '
                                                       'professionals'},
 'response': {'communication_strategy': 'Sharing near-miss experiences to '
                                        'raise awareness',
              'enhanced_monitoring': 'Banks flagging/blocking suspicious '
                                     'transactions, *Confirmation of Payee* '
                                     'system'},
 'stakeholder_advisories': 'Banks and regulatory bodies (e.g., ATO) issuing '
                           'warnings and assistance to affected entities.',
 'threat_actor': 'Cybercriminals, Scammers',
 'title': 'Australian SMEs Face Growing Threat from Scammers',
 'type': 'Scam, Phishing, Fraud',
 'vulnerability_exploited': ['Lack of verification processes',
                             'Busy schedules of business owners',
                             'Isolation of employees',
                             'Phishing vulnerabilities']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.