It’s Scams Awareness Week (24–28 August), and this year’s theme — “No one’s just a number” — lands squarely on the wealth sector. Investment scams were the single biggest money-loser in Australia over the first half of 2026, with about $80.4 million reported stolen to Scamwatch. That’s more than any other scam category, and it’s the exact space your clients invest in.
Here’s why this matters more for advice firms than almost anyone else: the scammers doing the damage aren’t inventing new products. They’re impersonating real ones — cloning adviser names, faking “super review” and “portfolio rebalance” emails, and standing up look-alike login pages for client portals. We regularly see clients across the Northern Beaches and Central West NSW forward us a “message from their adviser” that’s actually a near-perfect copy of a firm’s branding. If your practice looks trustworthy, that trust is exactly what gets weaponised against your clients.
So do three things this week. First, publish and repeat a plain statement of how you’ll never contact clients — for example, “we will never email you a link to log in, or ask you to move funds over the phone.” Second, lock the front door: phishing-resistant MFA on your client portal and email, and brief reception and admin on the impersonation playbook so a confident-sounding caller can’t talk someone into a change. Third, watch for look-alike domains of your own business name. Stop. Check. Protect isn’t just consumer advice — it’s an operational checklist for the firm.
If you run a financial advice or wealth practice and want a hard look at your portal security, email authentication and staff training, that’s the kind of work we do every day. Have a look at our financial services IT and team cyber safety training pages, or get in touch.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
