How an Australian Startup Is Turning AI Against Scammers: The New Frontier in Fraud Defense
Apate.AI, an Australian cybersecurity startup, just raised A$11.4 million (approximately US$8.15 million) to expand a radically different approach to fraud prevention: instead of detecting attacks after they happen, the company deploys AI agents that actively engage scammers, impersonate victims, and gather intelligence about fraud networks. The funding round, led by Silicon Valley investor Lobby Capital, signals a broader shift in how organizations are thinking about AI security, moving away from passive defenses toward active threat intelligence collection.
The company's core innovation is deceptively simple but operationally powerful. Apate's conversational AI agents communicate with scammers through voice and text channels, posing as real victims. While keeping fraudsters occupied, these agents extract intelligence about how attacks are organized, who is behind them, and what tactics are most effective. Commonwealth Bank, one of Apate's early institutional customers, has already conducted more than 2.5 million autonomous conversations with threat actors using the platform, generating over 250,000 intelligence artifacts that feed back into fraud-defense systems.
Why Does Fraud Prevention Need AI Agents Talking to Criminals?
Traditional cybersecurity has always been reactive. A company detects a breach, investigates it, patches the vulnerability, and moves on. But the speed of AI-powered attacks has made that timeline obsolete. According to Mandiant's M-Trends 2026 report, the time between an attacker gaining initial access to a network and actually moving through it has collapsed from more than 8 hours in 2022 to just 22 seconds in 2025, largely because AI now automates reconnaissance and decision-making that used to require human operators.
Fraud, in particular, has become a numbers game where speed and scale matter more than sophistication. AI-generated phishing emails now achieve a 54% click-through rate compared to just 12% for traditionally written ones, making them more than four times as effective. Deepfake fraud, where AI-generated video or audio convinces someone to wire money, has moved from theoretical threat to documented reality. The 2024 Arup case, where a finance employee transferred $25 million after a video call with what appeared to be his CFO and colleagues, all of whom were AI deepfakes, demonstrated that the trust layer has fundamentally broken.
Apate's approach flips the script. Instead of waiting for a victim to report fraud, the company's agents proactively engage threat actors, gather information about their methods and networks, and feed that intelligence back into institutional defenses. This transforms fraud prevention from a reactive, victim-centered model into an active, intelligence-centered one.
What Does the Broader AI Cybersecurity Funding Landscape Tell Us?
Apate's funding is part of a larger pattern in venture capital. On August 31, 2026, the startup funding cycle was light on volume but notably coherent in theme. The strongest verified new rounds spanned cybersecurity AI, quantum-computing infrastructure, and clean-air technology, with investors backing technologies tied to concrete operational problems rather than another crop of general-purpose software startups.
The macro message is clear: specialization is becoming a competitive moat. Investors are backing companies that combine software or advanced hardware with proprietary deployment knowledge, difficult technical problems, or access to institutional customers. Apate fits this pattern perfectly. The company is not selling another generic AI assistant or chatbot. It is selling a specialized system that solves a specific, high-value problem for financial institutions and other fraud-prone sectors.
Apate has also reincorporated as a Delaware company and plans to expand in the United States and Europe, including opening a London office. The funding therefore represents more than product development capital; it is financing the company's transition from an Australian cybersecurity startup into a global fraud-intelligence vendor.
How to Strengthen Your Organization's Defense Against AI-Powered Fraud
- Implement Shadow AI Controls: According to IBM's 2026 Cost of a Data Breach Report, shadow AI incidents now affect 43% of breached organizations, up sharply from 20% the year before. Establish clear policies requiring IT approval before deploying any AI tool, and monitor for unapproved AI usage involving sensitive data.
- Deploy Multi-Factor Verification for High-Value Transactions: Deepfake fraud and AI-generated phishing are most effective when they bypass human verification. Require out-of-band confirmation (a phone call to a known number, an in-person meeting, or a separate communication channel) for any transaction above a certain threshold, especially involving wire transfers or sensitive data access.
- Establish AI Governance Frameworks: 68% of organizations still lack proper AI governance to manage or detect shadow AI, and only 38% require IT approval before deploying an AI tool. Create a formal AI governance policy that covers tool selection, data handling, vendor vetting, and incident response.
- Monitor Underground Forums and Dark Web Activity: Threat actors discuss targeting patterns, list access to networks, and pivot toward new attack techniques in underground forums days or weeks before campaigns materialize. Organizations that incorporate dark web intelligence into broader security operations gain early warning of evolving threats.
- Train Employees on AI-Generated Threats: Humans are shockingly bad at catching deepfakes. In controlled testing, only 0.1% of people could consistently identify a deepfake, even when told in advance to look for one. Regular training should focus on verification procedures rather than visual detection.
What Are the Biggest AI Cybersecurity Risks Right Now?
The threat landscape has shifted fundamentally. The skill barrier to launching convincing attacks has collapsed. A criminal no longer needs real technical skill to write a phishing email or deploy malware; generative AI can now write a flawless, personalized phishing email in seconds with no grammar mistakes or giveaway red flags.
According to IBM's 2026 Cost of a Data Breach Report, AI-related breaches now cost an average of $6 million, about $1 million more than non-AI breaches. The biggest risks include shadow AI (employees using unapproved AI tools with sensitive data), AI-generated phishing and business email compromise, deepfake fraud, prompt injection attacks on AI systems themselves, and AI-adaptive malware that changes its behavior in real time to evade detection.
Nearly half of businesses, 49%, reported encountering an audio or video deepfake fraud attempt in 2024, up from roughly 30% the year before. And the problem is not limited to large enterprises. Individuals are actually easier targets because most people do not have any security team behind them. A call from a "family member" in distress, needing money urgently, is now indistinguishable from a real call thanks to voice cloning technology that requires as little as three seconds of audio to replicate someone's voice convincingly.
Apate's approach represents one answer to this acceleration: if you cannot stop the attacks from happening, at least gather intelligence about them in real time and use that intelligence to protect others. The company's success, measured in millions of conversations with threat actors and hundreds of thousands of intelligence artifacts, suggests that this model is not just theoretically sound but operationally viable at scale.