On 3 August 2026, Visa announced it was buying BioCatch, an AI fraud detection company, for $2.4 billion in cash.
BioCatch doesn't catch fraud the old way. It watches how you type, how you hold your phone, the pressure of your finger on a screen. More than 3,000 behavioural signals per session, analysed in real time, to figure out whether the person sitting behind a banking login is the actual account holder or someone very good at pretending to be one.
Visa's reasoning was direct. Account takeovers and scams cost the global economy over $1 trillion annually, and AI is making those attacks faster and cheaper to run.
That figure is global. The Australian slice of it is uncomfortable reading for anyone running a business here.
What's actually happening in Australia right now
The National Anti-Scam Centre received 481,523 scam reports in 2025. Of those, 274,577 came with a dollar loss attached, totalling $2.18 billion. Investment scams took the biggest share at $837.7 million. Payment redirection fraud, which is the one most likely to hit a business's accounts payable process, added $166.8 million. False billing scams clocked $23.6 million.
There's a harder detail buried in those numbers. Fewer scams are being reported year on year, but total losses are climbing. As we covered in our breakdown of the Origin Energy breach, the average cost of a successful cyber crime for an Australian small business is now $56,600, up 14% in twelve months.
Fewer attacks, more damage per hit. Generative AI cut the attacker's cost to near zero. A convincing fake invoice that once took a criminal an hour to construct now takes seconds. Voice cloning can replicate your supplier's voice from a handful of YouTube clips. A payment redirection email written in your accountant's exact style no longer requires a skilled social engineer. The attacks got cheaper. The average loss per incident got 30% more expensive. That gap is exactly where Australian small businesses are sitting right now.
What Visa's move is actually telling you
The deal is being framed as a payments story. It's really a signal about where the threat lands.
Visa is explicitly moving fraud detection upstream, before a transaction reaches the payment stage. BioCatch flags suspicious behaviour during a banking session, not after money has already moved. By the time a fraudulent payment clears, it's often too late to recover it. That's the problem Visa is trying to solve.
The same logic applies to small businesses, at a very different scale.
Most payment fraud targeting Australian SMBs doesn't interact with Visa's network at all. It bypasses the payment rails entirely. A supplier impersonation email. A changed BSB on an invoice. A "CEO" asking for an urgent transfer before month end. These attacks land in your inbox, your invoice approval process, your staff's judgement. No behavioural biometrics baked into a payment network will catch an employee who's been convinced to manually approve a fraudulent bank transfer.
Visa is protecting the part of the journey it owns. Nobody else is protecting the part you own.
The controls that actually reduce exposure
Most of what works here isn't expensive. It's process, and the honest problem is that most small businesses haven't formalised it.
The single most effective step is verifying payment detail changes by phone. If a supplier emails to say their BSB has changed, call them using a number you already have, not the one in the email. That step alone would stop a large share of payment redirection fraud. It costs nothing and takes two minutes.
Beyond that: put a two-person check on payments above a threshold that makes sense for your business, whether that's $2,000 or $10,000. Require two people to approve anything above it. Simple, cheap, and widely skipped.
Train your team on what AI phishing looks like in 2026. It's not broken English anymore. It's unusual urgency, requests that skip normal approval steps, and messages that arrive outside business hours from addresses that look almost right. The JADEPUFFER incident is a good illustration of how quickly these attacks move once someone's in.
Audit your supplier banking details. Payment fraud often starts with a compromised supplier, not a compromised you. If you haven't confirmed your key suppliers' payment details by phone in the past six months, do it now.
Get your email security settings checked. SPF, DKIM, and DMARC records on your domain cost nothing to audit and block a large proportion of spoofed emails. Your IT provider can run this check in a few minutes.
The bottom line
When Visa spends $2.4 billion specifically to catch fraud before it becomes a payment, the message isn't complicated. The economics of fraud shifted. Attackers got cheap access to tools that used to require real skill. The pool of potential targets got wider.
Australian SMBs are in that pool. The $2.18 billion lost to scams in Australia last year isn't concentrated in a handful of large corporate incidents. It's spread across businesses dealing with the same fake invoices, the same redirected payments, the same impersonation calls that yours is.
The controls above are a starting point. If you're not sure whether your business has them in place, get in touch with OrionX to find out where your process gaps are before an attacker does.
Sources: Visa investor relations release (3 August 2026); CNBC, "Visa buys BioCatch for $2.4 billion" (3 August 2026); Disruption Banking, "Visa Acquires BioCatch for $2.4 Billion to Fight AI-Powered Fraud" (4 August 2026); TechBusiness News AU, citing National Anti-Scam Centre 2025 data; Inside Small Business / BizCover, "Fewer Scams, Bigger Losses" (May 2026); ASD Annual Cyber Threat Report 2024-25.
