At Managed Services Australia, we are seeing a significant shift in the way cybercriminals target businesses. While attackers still look for technical weaknesses, they are increasingly focusing on something far more difficult to patch: human trust.
Cybercriminals no longer need to breach an entire network to cause serious financial or operational damage. A convincing email, phone call, text message or Microsoft Teams chat may be enough to persuade an employee to transfer funds, disclose confidential information, reset a password or approve access to a critical system.
Artificial intelligence is making these scams faster to create, easier to personalise and more difficult to recognise. Attackers can generate polished emails, imitate the language used by an executive and create synthetic audio that sounds like a real person. When those techniques are combined with publicly available information about a business, a fraudulent request can appear disturbingly genuine.
This creates an important question for every organisation: how does an employee verify that a request is genuinely coming from the person it claims to be?
The New Face of Social Engineering
Traditional phishing emails were often easier to identify. They might contain poor spelling, awkward wording, suspicious links, unexpected attachments or an email address that was clearly unrelated to the sender.
Those warning signs have not disappeared, but businesses can no longer depend on them.
Generative AI can help an attacker produce clear, professional and contextually relevant messages in seconds. A scam can be written in natural English, adapted to a particular industry and adjusted to reflect the apparent communication style of a chief executive, finance manager, supplier or trusted adviser.
The attacker may not need access to the real person’s mailbox. They might use a lookalike domain, a compromised supplier account, a spoofed caller ID, a fraudulent social media profile or a newly created messaging account.
In other cases, the attacker may first compromise a genuine email account and quietly observe conversations before inserting a false payment request into an existing email thread.
Voice cloning adds another layer of credibility. If an employee receives an email followed by a phone call that appears to confirm the request, they may feel that they have completed a second check. However, if both communications are controlled by the attacker, the additional contact has not provided independent verification.
A Scenario That Could Happen to Any Organisation
Imagine that a finance manager receives an email that appears to be from the CEO. The message explains that a supplier payment must be completed urgently to avoid delaying an important project.
The email is well written. It refers to a genuine supplier, uses the CEO’s usual tone and mentions that the CEO is travelling and difficult to reach.
A few minutes later, the finance manager receives a phone call. The voice sounds like the CEO and reinforces the urgency of the payment.
The caller may create additional pressure by saying that the transaction is confidential, that the board is waiting or that the payment must be completed before the bank’s cut-off time.
Everything appears genuine, but the request is fraudulent.
The attack succeeds if urgency becomes more important than procedure. The employee is encouraged to act quickly, avoid discussing the request with colleagues and bypass the controls that would normally expose the fraud.
This is why impersonation scams are not simply an email-security problem. They are a business-process and human-behaviour risk.
Why AI Makes Impersonation More Effective
Cybercriminals can gather a surprising amount of useful information without accessing an organisation’s internal systems.
Company websites, LinkedIn profiles, social media posts, media releases, job advertisements and public documents may reveal:
- The names and roles of senior decision-makers
- Finance, payroll and accounts personnel
- Supplier and customer relationships
- Reporting structures and team responsibilities
- Current projects, events and business initiatives
- Executive travel, conferences and periods of leave
- The language, tone and phrases individuals commonly use
AI can help attackers organise this information and turn it into highly targeted communications. Instead of sending the same generic message to thousands of people, a criminal can create a believable request for a particular employee at a particular organisation.
The technology does not need to produce a perfect imitation. It only needs to be convincing enough when combined with the right timing, context and pressure.
Warning Signs Still Matter
AI-powered impersonation can be convincing, but unusual behaviour and requests can still reveal a scam.
Employees should be cautious when a communication includes:
- An unexpected payment or urgent transfer request
- New or amended supplier bank details
- A request to purchase gift cards or cryptocurrency
- Pressure to keep the matter confidential
- Instructions to bypass normal approval procedures
- A sudden request for passwords, MFA codes or access changes
- A request sent from a new phone number or messaging account
- An executive who is unusually difficult to contact through normal channels
- An unexpected MFA prompt or password-reset notification
- Resistance when the employee attempts to verify the request
No single sign proves that a request is fraudulent. Equally, the absence of spelling mistakes or suspicious links does not prove that it is legitimate.
Employees should assess the request, its context and the requested action together.
The Best Defence: Verify Before You Act
At Managed Services Australia, we believe the strongest defence against AI-powered impersonation combines people, processes and technology. No single control can address the entire risk.
1. Independently verify sensitive requests
Any request involving money, banking details, passwords, confidential information or access privileges should be verified using a trusted communication channel.
Employees should call a known telephone number already held by the organisation or speak to the requester in person. They should not use a phone number or contact link included in the suspicious message, as that information may lead directly back to the attacker.
The verification should also confirm the specific request, not simply whether the person recently sent an email.
2. Require dual approval for financial transactions
Significant payments, changes to supplier bank details and unusual transfers should require approval from two authorised people.
Dual approval reduces the likelihood that one employee can be pressured into completing a fraudulent transaction. It also creates a valuable opportunity for a second person to notice inconsistencies or verify the request independently.
Supplier bank-detail changes should be confirmed through a known contact using details already stored in the organisation’s records.
3. Strengthen identity and email security
Multi-Factor Authentication remains an important control because it can make stolen passwords far less useful.
Organisations should also review:
- Email-security policies
- Privileged access
- Mailbox forwarding rules
- Sign-in activity
- Administrative permissions
- The way access and account changes are approved
Technical controls can help detect suspicious messages, malicious links, unusual logins and compromised accounts.
However, MFA alone cannot stop an employee from willingly making a payment after being deceived. Financial procedures and employee awareness remain essential.
4. Train employees for modern attacks
Security-awareness training must reflect the way modern scams operate.
Employees should understand that impersonation may occur through email, telephone calls, video meetings, text messages, Microsoft Teams or social media.
Training should use realistic examples and clearly explain how staff can report a concern. Short, regular exercises are often more useful than treating cybersecurity as a once-a-year compliance activity.
5. Protect employees who challenge unusual requests
Staff must feel comfortable slowing down a request, even when it appears to come from a senior executive.
Leaders should actively reinforce that following the verification process is expected and will be supported.
An employee should never fear criticism for confirming a payment, questioning an access request or refusing to disclose an MFA code.
Create a “Pause and Verify” Culture
One of the most valuable habits an organisation can develop is a culture in which employees automatically pause when a request is unusual, urgent or sensitive.
A simple response can be powerful:
“Before I proceed, I need to verify this request through our normal process.”
This does not accuse the apparent sender of wrongdoing. It protects the employee, the executive and the organisation.
A strong Pause and Verify culture means that urgency never cancels security. It means confidential requests are still subject to approval. It also means identity is established through a trusted process rather than assumed because an email, photograph, caller ID or voice seems familiar.
Some businesses introduce a pre-agreed verification phrase for highly sensitive requests. This may add value, but it should not replace formal approval processes, as phrases can be disclosed or discovered.
The safest approach uses multiple controls rather than one shared secret.

What to Do if You Suspect an Impersonation Attempt
If an employee believes a request may be fraudulent, they should stop and report it immediately.
The organisation should:
- Avoid replying, transferring funds or using contact details supplied in the message.
- Contact the apparent sender through a known, trusted channel.
- Notify the internal IT team or managed service provider.
- Preserve the email, message, call details and any related records for investigation.
- Contact the bank immediately if money has already been transferred.
- Review the affected account for suspicious sign-ins, forwarding rules or access changes.
- Reset credentials and revoke active sessions if an account compromise is suspected.
- Inform other employees who may receive a similar request.
Speed matters after a suspected incident, particularly when a fraudulent payment has been made.
Employees should know who to contact and should not delay reporting because they are embarrassed or uncertain. Fast reporting gives the organisation the best possible chance of containing the incident.
People, Process and Technology
AI-powered impersonation demonstrates why cybersecurity is no longer only an IT responsibility.
The strongest protection comes from three elements working together:
- People who understand modern threats and feel confident reporting concerns
- Processes that require verification, separation of duties and accountability
- Technology that protects identities, email, devices and business systems
Technology can filter many malicious messages and identify suspicious activity. Processes can prevent one person from approving a high-risk action alone. Well-trained employees can recognise when something does not feel right and activate those controls.
If one element is missing, attackers have more room to succeed.
Is Your Organisation Ready?
The question businesses should ask is no longer:
“Could we receive a phishing email?”
A better question is:
“What would happen if someone successfully impersonated our CEO, finance manager or key supplier today?”
Would an urgent payment be independently confirmed? Would a bank-detail change require dual approval? Would employees know how to report a voice-cloned call? Could your team identify and contain a compromised Microsoft 365 account?
If those questions reveal uncertainty, now is the time to improve your verification procedures, identity controls and employee awareness.
Key Takeaways
- I is making phishing and impersonation messages more convincing and easier to personalise.
- Voice cloning can make a fraudulent phone call appear to confirm a fraudulent email.
- A familiar email address, caller ID, writing style or voice should not be treated as proof of identity.
- Requests involving money, credentials, sensitive information or access must be independently verified.
- Dual approval, MFA, email protection, employee training and clear reporting procedures all reduce risk.
- A Pause and Verify culture helps employees resist urgency and follow the correct process.
How Managed Services Australia Can Help
Many organisations have gaps within their Microsoft 365 environment, identity controls, email security and financial verification procedures without realising it.
Managed Services Australia helps businesses strengthen their cybersecurity through proactive security assessments, Microsoft 365 security reviews, identity and access management, Multi-Factor Authentication, employee-awareness training and ongoing security monitoring.
We work with organisations to identify practical weaknesses before attackers exploit them and establish controls that employees can follow in the real world.
If you are unsure how your organisation would respond to an AI-powered impersonation attempt, contact Managed Services Australia for a practical review of your current security posture.
🌐 Explore our services at Managed Services Australia.
📧 Dial 1300 024 748, shoot us an email at [email protected], or schedule a session with one of our IT specialists.







