A Supplier Lost Thousands to One Changed Bank Detail. Here’s the Verification Step That Would Have Stopped It.

Byteway provides IT and cyber security for businesses across Australia, and the incident we get called about most often is...

business email compromise prevention australia

Byteway provides IT and cyber security for businesses across Australia, and the incident we get called about most often is not ransomware or a dramatic breach. It is a paid invoice that turned out to be fraudulent, discovered when the real supplier rings weeks later asking where their money is. By then the money is gone, and it usually cannot be recovered. This guide explains exactly how that fraud works, the one verification step that stops it, and what to do in the first hour if a payment has already left.

The frustrating part of every one of these cases is how ordinary it looks. No vault gets hacked. A real invoice arrives, from a real supplier, for real work, and one line of bank account detail has been quietly changed. The payment system does its job perfectly. The verification step is the thing that was missing.

Executive summary

Payment redirection fraud, also called business email compromise (BEC), is when a criminal alters the bank details on a legitimate payment so your money goes to their account instead of your supplier’s. It cost Australians $166.8 million in 2025, and false billing was the most reported scam type for small businesses. The attacker usually compromises your supplier’s email, watches real invoices, then sends a genuine-looking one with changed account details. The single most effective control is free: verify any change to bank details by phone, on a number you already have, never a number from the email.

What is payment redirection fraud?

Payment redirection fraud is a form of business email compromise. The criminal’s goal is simple: get a legitimate business payment sent to a bank account they control instead of the intended recipient. They do not need to break into your bank. They only need you to change one set of account details, or to pay an invoice that already has the wrong ones.

It is sometimes called invoice fraud, false billing, or payment diversion fraud. The label varies. The mechanics are consistent, and they are deliberately unglamorous. An email that looks right carries a bank account number that is wrong, and a payment leaves on time to the wrong destination.

How the scam actually works, step by step?

Understanding the sequence is what makes it easy to stop, because there is a natural interception point in the middle.

Step one: the attacker gets into an email account. Often it is not yours. It is your supplier’s. They get in through a phishing email that harvested a password, or reused credentials from an earlier breach. Phishing was the most common entry point in the 2025 Australian data, with more than 65,000 reports.

Step two: they watch, quietly. This is the patient part. The attacker sits inside the mailbox, sometimes for weeks, reading the normal flow of business. They learn the supplier’s invoice format, the projects in progress, the tone of the emails, and crucially, when a payment is due. Some set a mailbox rule that forwards relevant emails to them and deletes the evidence, so the account owner never notices.

Step three: they strike at the natural moment. When a real invoice is due, they send it. From the compromised address, or a lookalike, continuing the genuine email thread, referencing the real work. The invoice matches the supplier’s usual invoices, because the attacker has been studying them. Everything is correct except the BSB and account number.

Step four: the payment leaves. Nothing triggers suspicion. The invoice was expected, the sender is known, the amount is right. Accounts pays it. The money lands in the criminal’s account and is moved on within minutes.

Step five: discovery, too late. Weeks later the real supplier asks about an overdue payment. Now there are two victims, the supplier whose email was compromised and the business that paid, and an argument about who bears the loss.

Why it is so hard to spot

Most security advice tells you to look for red flags: bad spelling, odd addresses, urgency, a sender you do not recognise. Payment redirection fraud defeats all of it.

  • The sender is genuine or nearly identical, because their real account was compromised.
  • The email thread is real, because the attacker continued an existing conversation.
  • The invoice is expected, because they timed it to a real payment.
  • The amount is correct, because they copied a real invoice.
  • There is often no urgency, because rushing you would look suspicious. Some attackers are patient and polite.

The one thing that is wrong is the bank account, and a bank account number is exactly the kind of detail nobody scrutinises because it is boring and it changes occasionally for legitimate reasons.

This is also why it is not really a technology problem you can filter your way out of. Good email security reduces the chance of the initial compromise, and it matters, but once a convincing invoice with changed details reaches a person, the defence has to be a process, not a spam filter.

The one step that stops it: call-back verification

Here is the control that would prevent the large majority of these cases, and it costs nothing.

Any change to a supplier’s bank details is verified by phone before payment, using a number you already have on file, not a number from the email or invoice.

That final clause is the whole thing. Fraudulent invoices often include a helpful note about updated banking details and a number to call to confirm. That number goes to the attacker, who will happily confirm their own fraudulent account. Verification only works if you reach the real supplier through a channel you already trust: a phone number from a previous genuine invoice, your existing contact, the number on their official website, not anything supplied in the suspicious message.

The conversation takes thirty seconds. “We’ve received an invoice with updated bank details, can you confirm the account?” If they changed it, they confirm. If they did not, you have just stopped a fraud.

The reason this has to be a hard rule rather than a “when it feels suspicious” habit is that the entire danger of these attacks is that nothing feels suspicious. If verification depends on someone sensing something is off, it will fail exactly when it matters, because a good BEC invoice does not feel off at all.

The controls that stop it at each stage

Call-back verification is the single most important step, but a layered approach closes the gaps around it. These map to the stages above.

Stop the email compromise (stage one and two):

  • Multi-factor authentication on all email accounts. This is the single biggest technical control, because it stops stolen passwords from being enough to get into a mailbox. It is also part of meeting your security obligations under the Australian Privacy Principles.
  • Staff awareness of phishing, since phishing is the most common entry point. People who can spot a credential-harvesting email prevent the compromise that starts the whole chain.
  • Email security and monitoring to reduce spoofing and detect suspicious mailbox rules, the kind attackers use to hide their tracks. This overlaps with the general hygiene we cover in recent ACSC alerts.

Catch the fraudulent invoice (stage three and four):

  • Mandatory call-back verification for any bank-detail change, as above.
  • A dual-approval rule for new or changed payment details, so two people sign off rather than one.
  • A verification step for first-time payments to a new supplier, not just changes to existing ones.
  • Flagging external emails, so staff can see when a message claiming to be internal actually came from outside.

Limit the damage (stage five):

  • A known first-hour response, so if a payment does go, everyone knows to act immediately rather than hoping.
  • Cyber insurance that covers social engineering or funds transfer fraud. Check your policy, because coverage varies and some treat it as a separate extension.

What the law says about who bears the loss

This is the part that turns invoice fraud from an IT concern into a business risk you cannot ignore.

If your business pays altered bank details without independently verifying them, you can bear the loss yourself. Australian courts have addressed this. In one Western Australian case, attackers intercepted email communication between two companies and changed the account details on a legitimate invoice, and the resulting dispute over who carried the loss went before the court. The broad lesson from these cases is consistent: the obligation to verify sits with the party making the payment. “The email instructed me to” is not a defence.

Your bank is also usually unable to recover the funds once they have left, because from the bank’s perspective you authorised the payment. That is what makes prevention so much more valuable than response here. Unlike a fraudulent card transaction, a business-initiated bank transfer to a fraudster is very hard to claw back.

For businesses covered by the Privacy Act, an email compromise that exposes personal information can also trigger data breach assessment and notification obligations, so a single compromised mailbox can create both a financial loss and a compliance event at once.

What to do in the first hour if a payment has already gone

Speed matters more than anything else here. If you discover a payment has gone to a fraudulent account:

  1. Call your bank immediately. Ask them to attempt a recall or freeze. The sooner you act, the slightly better the odds, though recovery is never guaranteed.
  2. Contact the receiving bank if you can identify it, to report the fraudulent account.
  3. Report it to ReportCyber (cyber.gov.au), run by the Australian Signals Directorate’s ACSC, which routes reports to law enforcement.
  4. Report to Scamwatch as well.
  5. Secure the compromised email account. Reset passwords, enable MFA if it was not on, and check for malicious mailbox forwarding rules. If it was your supplier’s account, tell them urgently.
  6. Preserve the evidence. Keep the emails, the invoice and the payment records, both for the investigation and for any insurance claim.
  7. Tell your insurer if you have cyber or crime cover.

The businesses that recover anything are the ones that move in the first hour, not the first day.

Byteway Expert Insight

The thing that surprises business owners most about these cases is that the victims are rarely careless. The finance people who pay these invoices are usually competent and experienced. They get caught because the fraud is designed specifically to pass every check a competent person makes. The invoice is expected, the sender is known, the amount is right. Everything that normally signals “this is fine” is present.

That is why we push so hard on making verification a rule rather than a judgment. If you leave it to someone noticing something is wrong, it will fail on the one invoice that was engineered not to look wrong. A fixed rule, verify every bank-detail change by phone on a known number, removes the need for anyone to sense anything. It just happens, every time, and it catches the one that matters.

The other thing worth saying to every business owner: tell your finance team, out loud, that they will never be in trouble for making that verification call, even if it turns out to be genuine and slightly awkward. The fraud relies on people not wanting to seem difficult or slow. Give them explicit permission to be difficult and slow about bank details, and you have closed the gap the whole scam depends on.

Get the controls in place before the invoice arrives

The most expensive part of payment redirection fraud is how reasonable it looks on the day. The defence is not complicated, but it does need to be in place before the fraudulent invoice lands, not improvised after.

Byteway sets up the full stack of controls for Australian businesses: email security and multi-factor authentication to make the initial compromise far harder, monitoring to catch the mailbox rules attackers hide behind, and a payment verification process your finance team can actually follow. If you want to strengthen the wider picture, it connects directly to our managed IT and cyber security services.

Book a cyber security and payment controls review. We will check where your gaps are and give you a plain plan to close them.

👉 Book your review

Frequently asked questions

What is payment redirection fraud?

It is a scam where a criminal changes the bank details on a legitimate business payment so the money goes to their account instead of the real supplier’s. Also called business email compromise or invoice fraud, it usually begins with a compromised email account and a genuine-looking invoice with substituted account details.

How common is invoice fraud in Australia?

Very. Australians lost $166.8 million to payment redirection scams in 2025, up nearly 10 per cent on the previous year, and false billing was the most frequently reported scam type for small businesses. Email compromise ranks among the top self-reported cybercrimes for Australian businesses.

How do I verify a supplier’s bank details safely?

Call the supplier on a number you already have, from a previous invoice or their official website, and confirm directly. Never use a phone number or link from the email requesting the change, as it may reach the fraudster. Make this mandatory for every bank-detail change.

Why can’t my email filter just stop this?

Because the fraudulent invoice often comes from a genuinely compromised account and continues a real conversation, so it can pass technical filters. Good email security and MFA reduce the chance of the initial compromise, but once a convincing invoice reaches a person, the reliable defence is a verification process, not a filter.

Who is liable if my business pays a fraudulent invoice?

Generally the business that made the payment can bear the loss, because it authorised the transfer. Australian courts have found that the obligation to verify altered bank details sits with the paying party. “The email told me to” is not a defence, which is why verification is essential.

Can I get the money back? ]

Sometimes, but only with immediate action, and often not at all. Contact your bank the moment you discover it to attempt a recall, and report via ReportCyber. Because you authorised the payment, banks frequently cannot recover the funds, so prevention matters far more than response.

What is the first thing to do if we have paid a fake invoice?

Call your bank immediately to attempt a recall or freeze, then report to ReportCyber and Scamwatch, secure the compromised email account, preserve the evidence, and notify your insurer. Speed in the first hour gives you the best, though still limited, chance of recovery.

Does multi-factor authentication help against invoice fraud?

Yes, significantly. MFA on email accounts is the single biggest technical control, because it stops stolen passwords from being enough to break into a mailbox, which is how most of these attacks begin. It should be on every account, especially email and finance systems.

Scroll to Top