AI phishing and deepfake fraud protection for Australian businesses.
Verification workflows for payment and identity requests, staff testing against AI-written lures, and Entra ID hardening against account takeover, delivered Australia-wide.
Black Shard provides AI phishing protection and deepfake fraud protection for Australian businesses. Artificial intelligence has changed the two ends of a fraud attempt: the lure that opens it and the impersonation that closes it. Writing is fluent and specific to the target business. A voice or a short video clip, built from a public sample, can carry an instruction in the voice of somebody the recipient trusts. Business email compromise and voice-cloning payment fraud are the two concrete forms this takes, and both sit inside what is now described as AI-enabled attacks.
Black Shard is an Australian software engineering and cybersecurity firm, headquartered in Brisbane, delivering nationally. The controls that hold against AI-enabled attacks are verification controls: a callback before a payment detail changes, an out-of-band approval for that change, and an identity layer that limits what a single compromised sign-in can reach. Staff testing, Entra ID hardening and incident response are built around that position.
How AI changed phishing and fraud
A phishing email used to carry tells: odd grammar, a generic greeting, a request out of step with how the business actually operates. Generative writing tools remove the grammar tell and can be pointed at whatever the target has published about itself: a name and a role from the company website, a supplier relationship from a tender notice, the register a finance team actually writes in. The result reads as though somebody who knows the business wrote it.
A short public sample of somebody's voice, a webinar recording, a conference talk, a voicemail greeting, is enough to generate a call in that voice, and the same applies to video. A callback to confirm an urgent instruction has been a standard verification step for years, on the assumption that a voice is hard to fake convincingly at short notice. That assumption no longer holds. Voice-cloning payment fraud runs on exactly this gap: an instruction that sounds like it came from a director or an executive, timed to bypass the verification step that would normally have caught it.
None of this is expensive to run at volume. Writing one convincing, business-specific lure used to take real effort. An attacker can now produce many, each tailored to a different target inside the same organisation, at close to no additional cost. The number and average quality of attempts against the same underlying weaknesses both increase: an unverified request to change bank details, a mail rule quietly forwarding invoices, a login page that looks right down to the logo.
The defence that works
A control that depends on a person spotting a tell breaks once the tell is gone. Grammar, an unfamiliar sender, a voice that does not quite sound right: these have been useful signals, and none of them can be relied on against a well-produced AI-enabled attack. The controls that hold instead do not depend on recognising the lure at all: a callback to a number sourced independently of the request before a payment or bank detail changes, an out-of-band approval for that change made through a channel separate from the one the request arrived on, and an identity layer built so that one compromised sign-in does not reach the mailbox rules, the payment system and the file store all at once.
Black Shard designs this as a verification workflow: who can request a payment or identity change, what independent step confirms it, and what happens when that step is skipped. The work sits inside the same security advisory practice that produces a response plan or a policy set, applied here to the specific requests an AI-enabled attack is built to force through.
- Callback verification, to a number sourced independently of the request, before a payment or bank detail changes
- Out-of-band approval for payment and identity changes, confirmed through a channel separate from the one the request arrived on
- Identity hardening so a single compromised sign-in cannot reach mail rules, payment systems and file storage at once
- A written policy naming who can request a change and what independent step has to confirm it
Testing your organisation against AI-grade lures
Phishing simulation and social engineering testing are a standing Black Shard practice, and the lures written for it now match what a genuine AI-enabled attack produces: fluent, specific to the business, and free of the grammar tell staff have been trained to look for. A vishing scenario tests whether the callback verification step is actually followed under pressure.
Results are reported per team, with the verification step that failed identified. Individuals are not named. Where the step was a callback that was not made or an approval that was rubber-stamped, the follow-up is written against that specific failure, and a second wave after training can measure whether it held.
- Phishing simulation with lures written to the fluency and specificity of a genuine AI-enabled attack
- Vishing scenarios testing whether the callback step actually gets followed
- Per-team results with the failed verification step identified; individuals are not named
- An awareness follow-up written against that step, with a second wave available to measure whether it held
Hardening identity and mail
Business email compromise starts from one successful sign-in: a password reused from another breach, a session token lifted through a convincing login page, an application granted more access than the integration needed. From there, a mailbox rule can be planted to watch for invoices, or the mailbox itself can be used to send the fraudulent request. An Entra ID security review checks the controls that stop a single sign-in from reaching that far: conditional access and multi-factor authentication coverage across every account that matters, an audit of who holds privileged roles and whether each assignment still stands up, and a review of what third-party and internal applications have been granted access to the tenant.
Offboarding and recovery are part of the same review: whether a departing user's access is removed the day they leave, and whether the tenant can be recovered if an administrator account is lost. For an organisation running on Microsoft 365, these are the controls that decide how far a single compromised credential reaches.
- Conditional access and MFA coverage across every account that matters, including break-glass accounts
- Privileged-role audit: who holds high-impact roles, and whether each assignment still stands up
- App-consent audit, including over-broad third-party grants a single click can hand over
- Offboarding and recovery, so a lost or compromised account cannot lock the business out
When money has already moved
If a payment has already gone out on a fraudulent instruction, the first steps do not depend on us: contact the receiving bank's fraud line immediately, since a transfer can sometimes be recalled or frozen within the first hours; preserve the email, call recording or message that carried the instruction; and engage your insurer if one is in place. Black Shard is not a bank and cannot recall a payment directly; the engagement that follows is technical.
Containment, root-cause analysis and remediation follow the same shape as any other incident: the entry point is traced, whichever sign-in, mailbox rule or verification step was skipped, containment actions are agreed with you before they are taken, and the gap is closed and re-tested. Where personal information is involved, Black Shard supports the Notifiable Data Breaches assessment under the Privacy Act 1988 with a factual incident record. The legal decision on notification sits with your legal advisers.
- Contact and triage: the sign-in, mailbox rule or verification step behind the fraud, established from what you can tell us
- Containment: actions agreed with you before they are taken
- Root-cause analysis and remediation, then a re-test of the closed gap
- Notifiable Data Breaches support where personal information is involved
How much does this cost?
No figure is published. Staff testing is quoted as a fixed scope driven by headcount, the channels in scope and whether a second wave after training is included. An Entra ID review is scoped to the size of the identity estate: users, guest accounts, privileged roles and app consents. Incident response is scoped to what happened.
Send a brief to [email protected] and scoping starts from the detail you have.
Questions, answered
- Does the defence depend on detecting AI-generated content?
- The controls built here do not depend on detecting synthetic content: callback verification sourced independently of the request, an out-of-band approval channel separate from where the request arrived, and identity hardening that limits what a single compromised sign-in can reach.
- What is business email compromise?
- An attacker gaining control of, or convincingly impersonating, a mailbox a business trusts, then using it to redirect a payment, request a bank detail change, or harvest further access. It typically follows one successful sign-in, through a reused password, a phished session token, or an over-permissioned application.
- How does voice-cloning payment fraud work?
- A short public sample of somebody's voice, from a recorded talk, a webinar or a voicemail greeting, is used to generate a call or a voice message carrying an urgent instruction: change these bank details, approve this transfer. It targets the callback step that used to be a reliable check, which is why the verification workflow needs to hold against a convincing voice rather than rely on spotting one that sounds wrong.
- Do you test us with AI-written lures or vishing?
- Yes, as part of the standing phishing simulation and social engineering testing practice. Lures are written to the fluency of a genuine AI-enabled attack, and vishing scenarios test the callback verification step under pressure with a researched pretext. Results are reported per team; individuals are not named.
- We have already had a payment go out on a fraudulent instruction. What do you do?
- Contact the receiving bank's fraud line first; a transfer can sometimes be recalled or frozen in the first hours, and that does not depend on us. The engagement that follows is technical: tracing the sign-in, mailbox rule or verification step behind it, containment actions agreed with you before they are taken, remediation, a re-test, and support with the Notifiable Data Breaches assessment where personal information is involved.
- Do you work with organisations outside Brisbane?
- Yes. Black Shard is headquartered in Brisbane and delivers Australia-wide. Scoping and the debrief run by video call as standard, and Brisbane organisations that would rather scope across a table have that option on the social engineering testing, Brisbane page.
Scope AI phishing and deepfake fraud defence with Black Shard.
Brisbane head office. Work delivered across Australia.