Each month, the team at Eftsure monitors the headlines for the latest accounts payable (AP) and security news. We bring you all the essential stories in our cyber brief so your team can stay secure.
Origin Energy breach could fuel a wave of AI-powered scams
Origin Energy has confirmed a customer data breach in Australia that experts warn could feed a wave of AI-powered scams, after the company disclosed unauthorised access to customer records to the market on 23 July.
The exposed data reportedly includes names, email addresses, phone numbers, dates of birth, account numbers, property addresses, and aspects of payment history, and Origin has engaged independent cyber experts and government agencies.
The bigger risk is what fraudsters can build with it: someone who knows a customer's provider, address, and recent payment pattern can craft a convincing story about an overdue bill or account problem, and AI lets them do it at scale and in fluent, personalised language. Breaches like this are what make later invoice and vendor-impersonation attempts so believable and personalised.
Albanese government unveils Australian Standards for AI
The Albanese government has announced a national framework of Australian Standards for AI, establishing an Office of AI within the Department of the Prime Minister and Cabinet and signalling legislation early next year.
The first tranche targets large data centres, with obligations to underwrite their own power supply, pay their full connection costs, and reduce load to support the grid, alongside protections that stop Australian creative work being used to train AI without the creator's permission.
National Cabinet will consider the approach in August, with standards expected to be legislated early next year. Sold as regulatory certainty for investment, it also marks the start of AI governance moving from voluntary principles toward legislated obligations, the same direction the boardroom and CFO surveys elsewhere in this brief are pointing.
AML rules now reach accountants, lawyers, and real estate
Australia's AML/CTF Tranche 2 reforms took effect on 1 July, extending anti-money-laundering and counter-terrorism-financing obligations to accountants, lawyers, real estate professionals, and dealers in precious metals and stones.
Newly captured businesses can enrol with AUSTRAC from 31 March and must complete enrolment by 29 July, then stand up customer due diligence, reporting, and record-keeping programs. It is the biggest expansion of Australia's financial-crime regime in years, pulling tens of thousands of professional-services firms into obligations that banks have carried for more than a decade.
Firms in scope face real work to build compliant onboarding and monitoring, and those out of scope will still feel it through the fresh checks their advisers, agents, and vendors now run.
Deepfake of Westpac NZ boss used in scam ads
Scammers used an AI-generated deepfake of Westpac NZ chief executive Catherine McGrath in fake investment ads on social media, RNZ reported, part of a wider rise in cloned executives being used to lend credibility to fraud.
The fabricated image circulated on Facebook and other Meta platforms, steering viewers toward investment scams. The tactic matters beyond the consumer angle: the same cloned-executive technique is increasingly turned on finance teams, where a convincing video or voice of a known leader is used to authorise an urgent payment or a change of bank details.
UN: South-East Asia's scam economy is going corporate to survive
A new UN report, covered by the Straits Times, finds that South-East Asia's industrial scam operations are restructuring like legitimate businesses to survive law-enforcement crackdowns, spreading their laundering and trafficking networks into new markets.
The UN Office on Drugs and Crime estimates that victims across East Asia, South-East Asia, and Australia and New Zealand lost up to US$114.1 billion to online scams in 2025, up from an estimated US$18 to US$37 billion in 2023, and describes syndicates adopting corporate-style structures, diversifying their suppliers, and relocating rather than shutting down when compounds are raided.
Stripped of the geopolitics, it describes well-resourced operations running payment-redirection, investment, and impersonation fraud at industrial scale, and getting better at surviving disruption. We've unpacked what the shift means for finance teams in our own analysis: read our full write-up on the scam economy's new survival strategy.
New research: 4 in 10 finance teams hit fraud or overpayment last year
New research from the Controllers Council and Ottimate finds that 41% of organisations experienced invoice fraud or overpayment in the past year, based on a survey of more than 200 finance leaders.
The State of AP Maturity 2026 report ties that exposure to partial automation: disconnected systems and manual reviews that leave errors and fraud invisible until after a payment goes out. Just 48% of teams have a step to verify a vendor's banking details before paying, and only about half require two or more approvers.
As AI makes fraud harder to spot, the report argues that piecemeal automation widens the gap rather than closing it.
Most corporate boards still have no rules for AI use
A Deloitte survey of governance professionals finds that 51% of boards have no rules or guidance for how artificial intelligence is used, even as the technology spreads through the businesses they oversee.
Only 8% of boards use company-approved AI tools for committee work, and nearly half do not facilitate AI use at all. Where policies do exist, they tend to focus on security, confidentiality, and record-keeping. The finding matters as AI moves into finance and payment workflows, where an unmanaged tool can expose confidential data or approve something it should not.
92% of finance leaders feel pressure to prove AI's return
An Avalara survey of 1,505 finance leaders finds that 92% feel pressure to show a return on their AI investments, while only 7% say their organisation prioritises AI governance over speed of adoption.
The gap shows up in the controls. Thirty percent have not updated internal controls in the past year, 44% are only somewhat confident they could explain an AI agent's actions to an auditor, and nearly half say their AI incident response plans are untested or still in development. Half reported only limited measurable ROI so far.
Put simply, agents are being deployed into finance processes faster than the oversight around them is being built.
Kyriba: security and privacy rank among CFOs' top concerns
Kyriba's CFO Risk Radar, based on a survey of 1,000 CFOs and senior finance leaders, ranks security and privacy as the second-highest concern at 76%, behind only inflation.
The reading places security ahead of geopolitical instability, interest rates, and regulatory risk, a sign that fraud and data protection now sit firmly in the CFO's core risk view rather than the IT department's alone. The shift reflects how payment fraud and social engineering have become financial performance issues, not just technical ones.
Australia and allies warn of Russian "half-click" email theft via Zimbra
Australia's ACSC has joined a joint advisory with the US and a dozen allied nations warning that a Russia-linked group known as Laundry Bear stole entire mailboxes from organisations running Zimbra Collaboration Suite, using an exploit that needs no link click or attachment.
The group abused a zero-day flaw (CVE-2025-66376) that runs code the moment a rigged email is opened or previewed in the Zimbra web client, a method Proofpoint calls a "half-click" exploit with no social engineering required. Once in, it took up to 90 days of email and the full address book, harvested credentials and two-factor codes, set an app-specific password for persistent access, and used the hijacked accounts to phish new targets.
Australia and New Zealand were among the signatories, and the campaign heavily targeted Ukraine before hitting NATO members.