Add Think Technology as a trusted source Malware and Phishing Scams Still Threaten Australian Business | TTA

Malware and scams still threaten business – and the losses are growing

malware and scam threatens business

A fake competition post appears on Facebook. It promises a cruise holiday. All you have to do is like and share. Within hours, tens of thousands of people have shared it, many of them during business hours, on devices connected to your company network. The post disappears, and a near-identical one goes up in its place.

Scenarios like this play out constantly across Australian social media. They are not just a nuisance. They are an entry point for malware and credential theft that can reach deep into a business. The threat has grown significantly since cases like that P&O cruise scam first circulated, and the financial damage has reached levels that should concern every business owner in Brisbane and beyond.

The scale of the problem in Australia

According to the National Anti-Scam Centre’s 2025 Targeting Scams Report, Australians lost $2.18 billion to scams across 2025, a 7.8% increase on 2024. Phishing was the single most-reported scam type, with 65,361 reports to Scamwatch. More telling: phishing losses rose 51.7% even as total report numbers fell, meaning the attacks that got through caused far more damage per incident.

The Australian Signals Directorate’s (ASD) Annual Cyber Threat Report 2024-25 confirmed that phishing featured in 60% of all cyber incidents reported to the Australian Cyber Security Centre (ACSC) that year. The average self-reported loss per business cybercrime rose 50% to $80,850 per incident. Small businesses averaged $56,600 per incident.

Online and social media scams are the fastest-growing channel. Reports of online-based scams involving financial loss rose 31.8% in 2025, with associated losses up 21%. The ACCC referred more than 7,000 suspected Facebook scam URLs to Meta for investigation in 2025 alone. The fake competition post format is still very much active.

How a social media scam becomes a business problem

The P&O cruise-style post is a classic lure. The danger is not just that an employee wastes five minutes entering a fake competition. The danger is what happens after the click.

Many fake posts and competition pages are designed to harvest credentials, install information-stealing malware, or redirect users to phishing pages that mimic real login screens. When this happens on a work device, or a personal device with access to business systems, the damage can extend well beyond the individual who clicked.

Information-stealer malware, a fast-growing threat flagged in the ASD 2024-25 report, quietly exfiltrates passwords, session tokens, and saved credentials. That data then gets used in follow-on attacks: business email compromise, invoice fraud, or ransomware. The employee who clicked a cruise competition post on their lunch break may never make the connection.

AI has made phishing harder to spot

Phishing in 2026 looks nothing like the poorly-worded emails of five years ago. Generative AI lets attackers produce fluent, grammatically correct messages in seconds. They can mimic the tone of a supplier, clone a brand’s visual style, or pose as a colleague with a believable request.

Security researchers have noted that AI-assisted phishing emails draw click rates several times higher than older attempts. The old advice, watch for bad spelling, still applies, but it is no longer sufficient on its own. Targeted attacks that “spear-phish” specific employees using information scraped from LinkedIn and social media are now common even against small and mid-sized businesses.

This shift matters for how you train staff. Generic awareness training is less effective when the threat is a polished, personalised message rather than a mass-blast scam email.

What good protection looks like

The ACSC’s recommended baseline starts with a few fundamentals that many businesses still haven’t fully put in place:

  • Multi-factor authentication (MFA) on all accounts, especially email and any cloud services staff access remotely.
  • Email filtering at the gateway, so threats are blocked before they reach the inbox. TTA’s email security solutions integrate directly with Microsoft 365 to scan inbound traffic and stop malicious attachments and links before they land.
  • DNS filtering to block access to known malicious sites, including fake competition and phishing pages, even if a user clicks a link.
  • A clear policy on staff use of social media and personal browsing on work devices or networks.
  • Regular, practical security awareness training, not a once-a-year tick-box exercise.

Beyond the technical controls, cloud app security monitoring gives your IT team visibility into unusual sign-in behaviour or credential use that might indicate a compromise is already underway. Catching a breach early is far less costly than responding after data has been exfiltrated.

A quick check for your business

Ask yourself these five questions. If the answer to any is “I’m not sure”, it’s worth a conversation with your IT support team:

  • Do all staff use MFA on their email and key business applications?
  • Is your email filtered at the gateway, not just by a client-side spam folder?
  • Do you have a policy covering staff use of social media on work devices?
  • Has your team had practical phishing awareness training in the last 12 months?
  • Do you have a process for staff to report a suspicious email or link quickly?

Frequently asked questions

What is a phishing scam in plain terms?

A phishing scam is an attempt to trick someone into handing over passwords, personal details, or money by pretending to be a person or organisation they trust. It usually arrives by email, SMS, or social media, and often links to a fake website designed to look like the real thing.

Can a social media post really infect a business network?

Yes. Clicking a link in a fake social media post can direct a user to a page that downloads malware or harvests login credentials. If that happens on a work device, or a personal device used to access work systems, the attacker may then gain access to business email, files, or financial accounts.

How much does a phishing or malware incident actually cost a business?

According to the ASD’s Annual Cyber Threat Report 2024-25, Australian businesses reported an average loss of $80,850 per cybercrime incident, a 50% increase on the previous year. Small businesses averaged $56,600. These figures cover direct financial loss and do not include recovery time, reputational damage, or regulatory consequences.

Is email filtering enough on its own?

Email filtering at the gateway is one of the most effective controls, but it works best as part of a layered approach. DNS filtering, MFA, and regular staff training each address different points in the attack chain. A determined attacker who gets past email filtering can still succeed if a staff member clicks a link on a social media platform not covered by that filter.

How do I report a scam or phishing attempt in Australia?

You can report scams to Scamwatch at scamwatch.gov.au, and cybercrime to the ACSC via ReportCyber. If a business email account or system has been compromised, contact your IT support team immediately so they can contain the incident before it spreads.

Where do we start if we want to improve our protection?

Start with MFA and email gateway filtering, these two controls stop a large proportion of phishing attempts before they cause harm. From there, a basic IT security assessment can identify the gaps in your current setup and help you prioritise the next steps without guessing.

How do we get started?

TTA works with businesses across Brisbane and South-East Queensland to put practical cyber security controls in place, email filtering, MFA, DNS filtering, staff training, and more. If you’d like to talk through your current setup or get a second opinion on your exposure, get in touch with our team.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.