A Supplier Lost Thousands to One Changed Bank Detail. Here’s the Verification Step That Would Have Stopped It.
Byteway provides IT and cyber security for businesses across Australia, and the incident we get called about most often is not ransomware or a dramatic breach. It is a paid invoice that turned out to be fraudulent, discovered when the real supplier rings weeks later asking where their money is. By then the money is gone, and it usually cannot be recovered. This guide explains exactly how that fraud works, the one verification step that stops it, and what to do in the first hour if a payment has already left. The frustrating part of every one of these cases is how ordinary it looks. No vault gets hacked. A real invoice arrives, from a real supplier, for real work, and one line of bank account detail has been quietly changed. The payment system does its job perfectly. The verification step is the thing that was missing. Executive summary Payment redirection fraud, also called business email compromise (BEC), is when a criminal alters the bank details on a legitimate payment so your money goes to their account instead of your supplier’s. It cost Australians $166.8 million in 2025, and false billing was the most reported scam type for small businesses. The attacker usually compromises your supplier’s email, watches real invoices, then sends a genuine-looking one with changed account details. The single most effective control is free: verify any change to bank details by phone, on a number you already have, never a number from the email. What is payment redirection fraud? Payment redirection fraud is a form of business email compromise. The criminal’s goal is simple: get a legitimate business payment sent to a bank account they control instead of the intended recipient. They do not need to break into your bank. They only need you to change one set of account details, or to pay an invoice that already has the wrong ones. It is sometimes called invoice fraud, false billing, or payment diversion fraud. The label varies. The mechanics are consistent, and they are deliberately unglamorous. An email that looks right carries a bank account number that is wrong, and a payment leaves on time to the wrong destination. How the scam actually works, step by step? Understanding the sequence is what makes it easy to stop, because there is a natural interception point in the middle. Step one: the attacker gets into an email account. Often it is not yours. It is your supplier’s. They get in through a phishing email that harvested a password, or reused credentials from an earlier breach. Phishing was the most common entry point in the 2025 Australian data, with more than 65,000 reports. Step two: they watch, quietly. This is the patient part. The attacker sits inside the mailbox, sometimes for weeks, reading the normal flow of business. They learn the supplier’s invoice format, the projects in progress, the tone of the emails, and crucially, when a payment is due. Some set a mailbox rule that forwards relevant emails to them and deletes the evidence, so the account owner never notices. Step three: they strike at the natural moment. When a real invoice is due, they send it. From the compromised address, or a lookalike, continuing the genuine email thread, referencing the real work. The invoice matches the supplier’s usual invoices, because the attacker has been studying them. Everything is correct except the BSB and account number. Step four: the payment leaves. Nothing triggers suspicion. The invoice was expected, the sender is known, the amount is right. Accounts pays it. The money lands in the criminal’s account and is moved on within minutes. Step five: discovery, too late. Weeks later the real supplier asks about an overdue payment. Now there are two victims, the supplier whose email was compromised and the business that paid, and an argument about who bears the loss. Why it is so hard to spot Most security advice tells you to look for red flags: bad spelling, odd addresses, urgency, a sender you do not recognise. Payment redirection fraud defeats all of it. The one thing that is wrong is the bank account, and a bank account number is exactly the kind of detail nobody scrutinises because it is boring and it changes occasionally for legitimate reasons. This is also why it is not really a technology problem you can filter your way out of. Good email security reduces the chance of the initial compromise, and it matters, but once a convincing invoice with changed details reaches a person, the defence has to be a process, not a spam filter. The one step that stops it: call-back verification Here is the control that would prevent the large majority of these cases, and it costs nothing. Any change to a supplier’s bank details is verified by phone before payment, using a number you already have on file, not a number from the email or invoice. That final clause is the whole thing. Fraudulent invoices often include a helpful note about updated banking details and a number to call to confirm. That number goes to the attacker, who will happily confirm their own fraudulent account. Verification only works if you reach the real supplier through a channel you already trust: a phone number from a previous genuine invoice, your existing contact, the number on their official website, not anything supplied in the suspicious message. The conversation takes thirty seconds. “We’ve received an invoice with updated bank details, can you confirm the account?” If they changed it, they confirm. If they did not, you have just stopped a fraud. The reason this has to be a hard rule rather than a “when it feels suspicious” habit is that the entire danger of these attacks is that nothing feels suspicious. If verification depends on someone sensing something is off, it will fail exactly when it matters, because a good BEC invoice does not feel off at all. The controls that stop it at each stage Call-back verification is the single







