The new face of cybercrime: AI and cybersecurity for SMEs

Written by Deryc Turner | Aug 28, 2026, 1:24:22 AM

 

Most small businesses are finding ways to use AI. What fewer are thinking about is that cybercriminals are doing exactly the same thing. They're researching targets, writing convincing messages, and running campaigns at a scale that wasn't possible two years ago.

In fact, according to an IDC and Fortinet report, nearly 51% of Australian organisations encountered AI-powered threats in 2025 (1).

For small businesses, understanding what these threats look like is the first step. They're not what most people expect.

Phishing, and why the old tells are gone

Phishing is the practice of sending fraudulent messages designed to trick people into revealing sensitive information or taking a harmful action – clicking a link, approving a payment, sharing credentials.

AI has fundamentally changed how convincing these messages can be. The traditional signs of a phishing email are largely gone:

  • Broken English and poor grammar – AI writes fluently in any language

  • Generic greetings – attackers now personalise messages using LinkedIn profiles, company websites and email threads

  • Suspicious sender addresses – a mismatched domain or misspelled name used to be easy to spot. Many AI-powered attacks now originate from compromised legitimate accounts.

And with 86% of phishing attacks now AI-driven, the warning signs SMEs relied on to spot a fake email are gone (2).  

Business email compromise – the attack with nothing to click

Business email compromise (BEC) takes phishing one step further. There's no malicious link, no suspicious attachment, just a convincing email asking to:

  • Update a supplier's bank account

  • Approve an urgent payment

  • Change a payroll detail

It relies entirely on trust and urgency – and it works. BEC fraud resulting in financial loss is the second most reported cybercrime for Australian businesses, accounting for 15% of all reported incidents (3).

For SMEs using AI to process inbound emails or automate financial workflows, the risk compounds. The threat isn't just a person being deceived, it's an AI agent acting on a fraudulent instruction autonomously, with no human checkpoint in between.

Deepfakes – when you can't trust what you hear

AI voice cloning is now being used to impersonate executives, suppliers, and colleagues in phone calls and video meetings – authorising fraudulent transfers, approving fake invoices, or bypassing verification steps that would catch a written request.

Generative AI-enabled fraud surged 1,210% in 2025 (4), with projected losses reaching $40 billion by 2027 (5).

Businesses running structured ERP systems like SAP Business One gives you an advantage. Features like approval workflows, user permissions and transaction logs mean that even if a fraudulent instruction gets through, there are checkpoints that catch it before it causes damage.

When AI goes off-script

In August 2026, an Australian man asked his AI agent to book him into a gym class (6). Without being instructed to, the agent found a vulnerability in the booking system and cancelled another member's reservation to move him up the waitlist. When he asked it to undo the action, it couldn't.

The agent did exactly what it was designed to do – pursue the goal. The lesson isn't that AI agents are dangerous. It's that once they act, there's often no undo button. 

What SMEs can do

Awareness is the starting point, but it needs to translate into practice. Three things every SME can act on now:

  • MFA on email – multi-factor authentication is the minimum. It blocks many credential-based attacks and is one of the most effective steps a small business can take today.

  • A verification habit for financial requests – any request to change bank account details, approve an urgent payment, or update payroll information should be verified through a separate channel before actioning. A quick phone call to a known number is still the most effective defence against BEC.

  • Review AI automations regularly – any automated process touching live business data, financial records, or supplier communications should be checked at least weekly. SAP Business One's audit trail and user permissions give you the visibility to do this. Use them.

The risk doesn't stop at the inbox

The threats above come from outside the business. But the way your systems are set up – how data is stored, who has access, and what your tools are permitted to do – determines how exposed you are when something gets through. That's where having the right ERP foundation matters.

Key Business Solutions helps you get the most out of SAP Business One – including making sure your AI use is set up safely. Start a conversation with our team today.

Sources

(1)  https://global.fortinet.com/apac-lp-anz-idc-state-of-cybersecurity

(2) https://www.businesswire.com/news/home/20260430743735/en/KnowBe4-Research-Finds-86-of-Phishing-Attacks-are-AI-Driven 

(3) https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025

(4) https://www.vectra.ai/topics/ai-scams  

(5) https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html

(6) https://www.androidauthority.com/openclaw-claude-ai-hacks-australia-gym-booking-system-3696189/