E-SCAN 39: EVOLVING CRIME
E-Scan 39: The amplifying scamming landscape
One of the most demanding pressures on contemporary policing is the intersection between technology, the broader online space, and crime occurrence. It is no secret that advances in technology have created new forms of crime, while simultaneously amplifying, and in some case transforming, traditional criminal behaviour.
Within this broader ecosystem, online scams stand out as an acute pressure that impacts both individual Australians and Australian business, large and small. According to Scam Watch, despite the total number of reported scams decreasing, there was a 7.8 per cent increase in financial loss across 2025, resulting in an annual total of $2.18 billion lost to scams across Australia. While online scamming has been a consistent pressure for several years now, the most recent twist in the story has been artificial intelligence (AI), which has intensified, and professionalised the online scamming industry.
INTERPOL has warned that advances in AI are contributing to an ‘industrialisation’ of global financial fraud, with low-cost digital tools allowing criminal activity to be carried out at a previously unseen scale. Decreasing barriers to entry and a rise in global scam centres has enabled criminal networks to expand their pool of voluntary and involuntary workers: reports suggest that 300,000 people have been trafficked into scam compounds in Southeast Asia alone.
Recent threat assessments indicate that Large Language Models, such as ChatGPT, are being employed in tandem with social media posts, encrypted messaging and online ads to amplify phishing and social engineering attacks. OpenAI has described the relatively structured workflow underlying such attacks as the ‘ping, zing, sting’ model. At each stage of the process, automation facilitates and scales activity enabling scammers to generate and translate content for mass distribution, develop hyper-personalised messages and create deceptive materials. The result is an increase in romance baiting (‘pig butchering’), covert influence operations and impersonation fraud.
Synthetic media use is also seeing an uptick. Voice-cloning technology is advancing rapidly, and the Federal Bureau of Intelligence has identified cases involving the impersonation of CEOs and executives enabling malicious actors to authorise fraudulent transactions over the phone. The agency itself has been targeted with criminals spoofing the Internet Crime Complaint Centre (IC3) website and impersonating employees in an attempt to revictimise victims of scam.
AI-enhanced activity is not limited to fraud. In one of the first documented cases of its kind, Anthropic reported an AI-orchestrated cyber espionage campaign, in which 80 – 90 per cent of tactical operations were executed independently of human intervention. The threat actor, identified as a Chinese state-sponsored group, successfully induced Claude Code to undertake tasks such as reconnaissance, vulnerability identification and exploitation and credential harvesting. While human authorisation was still required at certain stages of the attack, it demonstrates how AI can now be employed to support multi-stage operations, allowing cyber activity to be organised as semi-automated workflows.
For law enforcement, the implications are significant. AI is not simply introducing new tools into the criminal landscape; it is reshaping how crime is scaled and how trust is exploited. Two pressures clearly stand out.
The first is scale. AI-enabled scams dramatically reduce the cost and effort required to generate convincing, personalised content at volume. This shifts online fraud from a series of discrete incidents to a continuous, high-volume threat environment. Even low success rates can produce substantial returns when thousands of interactions are automated and deployed simultaneously. For policing, this challenges the viability of reactive, case-by-case responses. Investigations will increasingly struggle to keep pace with the volume, cross-jurisdictional nature, and low attribution thresholds of these offences. This places a premium on prevention, disruption, and upstream interventions – working with financial institutions, telecommunications providers, and platforms to reduce exposure before harm occurs.
The second is trust. AI-enhanced impersonation, through voice cloning, synthetic media, and increasingly sophisticated social engineering, undermines the basic signals individuals and organisations rely on to verify identity. Authority can be convincingly replicated, whether in the form of a CEO, a government agency, or a police officer. This has two consequences. First, it increases victim vulnerability by eroding the reliability of familiar cues. Second, it places pressure on policing itself, as criminals are able to mimic institutional identity and exploit public trust in law enforcement to facilitate scams. Maintaining legitimacy in this environment will require police to think more deliberately about authentication, public communication, and how to support communities in verifying interactions.
Taken together, these pressures point to a shift in the policing environment from responding to individual offences, to operating within a system where crime is persistent, scalable, and increasingly built on the manipulation of trust.
More from E-Scan 39.
Members only access
All Australia and New Zealand police members/employees are entitled to access this publication through ANZPAA's secure member site. You must provide your official police jurisdictional email address to subscribe.
LoginSubscribe
BACK TO BLOG