This week (24–28 August 2026) is the National Anti-Scam Centre's Scams Awareness Week, and the number behind it should stop any Perth business owner mid-scroll: four in five small and medium businesses were targeted by an attempted scam in the past year. Nationally, Australians made close to 92,000 scam reports to Scamwatch in just the first six months of this year, totalling $156.6 million in losses — and while the number of reports actually fell, the average loss per report climbed more than 30%. Fewer attempts are getting through, but the ones that do are costing more. This year's campaign theme, "No one's just a number," is the Anti-Scam Centre's way of saying every one of those figures is a real business, often one that thought it wasn't the kind of target scammers bother with.
The three most common ways scammers reach Perth businesses
The campaign's own breakdown of what's hitting small businesses lines up with what we see in practice: fake invoices with altered bank details, remote access scams where someone poses as "IT support," and straight-up business impersonation — a scammer pretending to be a supplier, a bank, or even a staff member's boss. We've covered the mechanics of two of these in detail before: how payment redirection and invoice scams trick accounts staff into paying a fraudster instead of the real supplier, and how fake IT support scams talk their way into remote access to your systems. If you haven't read either, Scams Awareness Week is a good excuse to send them around the office.
What's easy to miss is that these aren't separate, unrelated risks — they're variations on the same trick. A scammer finds a plausible reason to be trusted (a familiar business name, a convincing login page, a voice that sounds like your boss) and asks for something that feels routine: approve this payment, click this link, let me remote in to "fix" something. The specific channel changes; the pattern doesn't.
The "Stop. Check. Protect." test
The National Anti-Scam Centre's advice for this year's campaign is deliberately simple, and it works just as well applied to a business as to an individual:
- Stop. Don't act immediately just because a request feels urgent — urgency is the tell, not a reason to skip the next step. A genuine supplier, bank, or colleague will still be genuine in ten minutes.
- Check. Verify who you're actually dealing with using contact details you already have or find independently — never the phone number or link in the message itself. If an invoice suddenly shows new bank details, ring the supplier on the number from your existing records to confirm, not the number in the email.
- Protect. If something does get through, report it — to your bank immediately if money has moved, and to cyber.gov.au or Scamwatch either way. Reporting quickly is what sometimes makes a bank transfer recoverable, and it's what feeds the intelligence that gets scam infrastructure taken down faster.
None of that requires new software or a security budget. It requires a habit, and habits are exactly what a five-minute team huddle this week can start building.
Why "it won't happen to us" is the actual vulnerability
Every business we talk to that's been caught out says some version of the same thing afterwards: they didn't think they were a target. That assumption is precisely why small businesses are attractive targets in the first place — scammers know a business without a dedicated security team is less likely to have a verification habit in place, and more likely to have one person under time pressure who can approve a payment or grant access without a second sign-off.
The businesses that avoid becoming part of next year's statistics generally aren't the ones with the biggest security budgets. They're the ones where "stop and check" is just how things are done — a second person confirms unusual payment requests, IT access requests go through one known channel, and staff know reporting a near-miss won't get them in trouble.
Building that into how the business actually runs
A few concrete things make the "Stop. Check. Protect." habit stick rather than fade after this week:
- A standing rule that bank detail changes always get a phone call, to a number you already had on file, before any payment goes out.
- One documented way IT support ever contacts you — so an unsolicited call or pop-up asking for remote access is an automatic red flag, not a judgement call under pressure.
- A "no blame" culture around reporting — the staff member who clicks a bad link and says so immediately is the reason damage gets contained, not extended.
- Multi-factor authentication everywhere it's offered, so a scammer with a stolen password still can't get in.
What we do
Layered protection matters because no single check catches everything — our IT security solutions combine email filtering, access controls and staff awareness so a moment of pressure doesn't become a costly mistake. If you'd like a second opinion on whether your current setup and habits would catch these scams, or want a short team session run through the "Stop. Check. Protect." test, get in touch or call (08) 9325 1196 — Computer Mechanics has been helping Perth businesses stay ahead of scammers since 1997.



