Home / Insights / Fraud Prevention
Fraud Prevention

Business Email Compromise & Invoice Fraud: The Defence Guide for Australian Business

By Financial Crime Advisory · 7 August 2026 · 12 min read

Business email compromise is the fraud that hits every size of Australian business, from sole traders to listed companies, and it needs no malware, no hacking of your bank, and no technical brilliance. It needs one email that looks right, arriving at the moment an invoice is genuinely due, with one thing changed: the account the money goes to. The invoice is real. The amount is real. Only the BSB and account number are the fraudster's. This guide covers how the attack actually works, the three layers of defence that stop it, and exactly what to do in the first hours if a payment has already gone.

In this guide

What BEC and payment-redirection fraud are

Business email compromise (BEC) is a family of frauds with a single common move: a criminal uses email to impersonate someone your business trusts — a supplier, your own chief executive, an employee, a conveyancer — and uses that trust to redirect a payment to an account the criminal controls. The Australian authorities most businesses will deal with, including the ACCC's Scamwatch and the reporting channels operated with the Australian Federal Police, treat payment-redirection fraud as one of the most damaging categories of scam affecting Australian business, and it is easy to see why: a single successful redirection can equal months of profit, and it strikes precisely the businesses that believe they are too small, too careful or too boring to be targeted.

The defining feature of BEC is that almost everything about the fraudulent transaction is genuine. There really is a supplier. There really is an invoice due. The email thread really does contain months of authentic correspondence. The person paying is doing exactly what they do every week. The fraud lives in one field on one document — the destination account — and that is what makes it so quietly effective against businesses that would never fall for a lottery scam or a fake parcel text.

The main variants

BEC is best understood as a set of variations on one theme. Knowing the shapes helps your team recognise the attack whatever costume it arrives in.

Supplier invoice redirection

The classic. A criminal — writing from a compromised supplier mailbox or a lookalike address — sends your accounts team an invoice, or a follow-up to a genuine invoice, advising that the supplier's bank details have changed. The next payment run sends real money owed to a real supplier into the fraudster's account. Often nobody notices until the genuine supplier chases the unpaid invoice weeks later.

Executive impersonation ("CEO fraud")

An email apparently from a director or chief executive instructs a finance staff member to make an urgent, confidential transfer — commonly framed around an acquisition, a deposit, or a matter "the lawyers are handling". The pressure is social: it exploits the reluctance of staff to question a senior name, and the urgency is engineered so verification feels like insubordination.

Payroll diversion

A message purporting to come from an employee asks payroll or human resources to update their bank details before the next pay cycle. It is small per incident, cheap for the attacker to run at scale, and often noticed only when the real employee asks where their pay went.

Conveyancing and settlement redirection

Property transactions are a prized target because the amounts are large, the timing is public or guessable, and the parties — buyers, agents, conveyancers, lenders — are exchanging bank details by email under deadline pressure. A redirected deposit or settlement payment can be the single largest transfer a family or small firm ever makes.

New-supplier fraud

Rather than hijacking an existing relationship, the fraudster invents one: a convincing new supplier, contractor or landlord is introduced into the payment process, sometimes on the back of a genuine procurement conversation the attacker has been reading. The first "invoice" is the fraud.

Anatomy of a real attack

Payment-redirection fraud is not a spray-and-pray email blast. The damaging incidents follow a patient, well-rehearsed sequence.

  1. Entry: mailbox compromise or lookalike domain. The attacker either gains access to a genuine mailbox — typically through a phished password, a reused credential from an unrelated breach, or a mailbox without multi-factor authentication — or registers a domain one character different from a real one, close enough that no one reading quickly will notice. Sometimes the compromised mailbox is not yours at all: it is your supplier's, which means your own security controls never see anything wrong.
  2. Silent monitoring. Inside a compromised mailbox, the attacker does nothing conspicuous. They read. They learn who invoices whom, for how much, on what cycle, in what tone, with what sign-off. Many set up mailbox rules that quietly forward copies of correspondence out, or shunt replies containing words like "invoice", "payment" or "account" into a hidden folder so the genuine owner never sees the conversation being hijacked.
  3. The perfectly timed strike. When a real invoice is due — and only then — the altered version arrives. It matches the expected amount, the expected format, the expected thread. It may sit inside a genuine reply chain. The only change is the bank detail, usually accompanied by a plausible reason: new bank, audit requirement, account under maintenance. Follow-up emails politely nudge the payment along, and if the victim raises questions, the attacker — reading in real time — answers them in the supplier's own voice.
  4. Funds out through mules. Once the payment lands, it moves. The first account is rarely the destination; it is a hop, and the money is split, layered through mule accounts — often held by recruited or duped individuals — and moved on or converted. This staging is why speed matters so much on discovery: the window in which funds are still sitting in the first account is short and closes fast.
The tell that hides in plain sight: in most successful redirections, someone later remembers a small oddity — a change of tone, an invoice arriving from a slightly different address, an unusual insistence on urgency. The attack does not succeed because there were no signs. It succeeds because there was no process that forced anyone to act on them.

Why it works: it attacks process, not technology

Most cyber threats attack systems. BEC attacks the way your business does business. The email filter is not tricked, because the email is often genuinely from the supplier's real mailbox. The bank's fraud systems are not tricked, because the payment is a legitimate business making a deliberate, authorised transfer. The person paying is not careless — they are doing their job exactly as the process defines it. The process is the vulnerability: if "an email from the supplier" is sufficient authority to change where money goes, then whoever controls the supplier's email controls your money.

This is also why purely technical spending disappoints against BEC. You can harden every system you own and still lose six figures because a supplier's mailbox — a system you will never control — was compromised. The defence has to assume the email channel is compromised, and build controls that hold anyway. That is the logic behind the three layers below, and it is why the first layer, not the technical one, is the headline.

Layer 1: finance-process controls — the headline

These controls work no matter how the fraudulent email arrived, which is what makes them the foundation rather than an accessory.

Mandatory call-back verification of bank-detail changes

This is the single most effective control against payment-redirection fraud, and it costs nothing but minutes. Before any change to a payee's bank details is actioned — and before any first payment to a new payee — a staff member phones a known contact at the organisation and verbally confirms the details. The number must be independently sourced: from your existing supplier records, a prior contract, or the supplier's official website. Never from the email requesting the change, and never from a "new" phone number helpfully supplied in the same message — fraudsters routinely include their own number precisely to absorb this check. Make it mandatory, make it no-exceptions, and record that it happened. A rule with a workaround for "urgent" cases is not a rule; urgency is exactly the condition the attacker will manufacture.

Dual authorisation over thresholds

Payments above a defined threshold, and all bank-detail changes, should require two people to approve — genuinely independently, not one person entering and a colleague waving it through. Dual authorisation defeats executive-impersonation fraud in particular, because the attacker must now convince two people, in a process where "keep this confidential" is itself a red flag.

Supplier master-data discipline

Treat your vendor master file as the asset it is. Changes to it should be restricted to a small number of staff, logged, and reviewed periodically. New suppliers should go through a verification step before their first payment. If bank details can be edited casually at the point of payment, every payment run is an opportunity for redirection.

Use the account-verification tools banks offer

Australian banks increasingly offer payee-verification capabilities that check whether the account name you entered matches the name on the destination account, and warn you on a mismatch. These checks are not a substitute for call-back verification — but a name-mismatch warning on a "supplier's new account" should stop a payment cold until it is resolved by phone.

If you implement only one thing from this guide: make call-back verification of bank-detail changes mandatory, with independently sourced numbers, no exceptions for urgency, and a record that the call happened. It is the control that still works when everything technical has already failed.

Layer 2: email and technical controls

Technical controls raise the cost of the attack and shrink the ways in. They matter — as long as you are honest about what each one does and does not cover.

Harden the mailboxes themselves

Most mailbox compromises are prevented by basics done properly: multi-factor authentication enforced on every mailbox with no exceptions for executives or shared accounts; conditional access policies that challenge or block sign-ins from unfamiliar locations and devices; and disabling legacy authentication protocols, which allow password-only access that bypasses MFA entirely and remain a favourite entry point wherever they are left switched on.

Audit mailbox rules and forwarding

Because attackers rely on hidden rules to monitor and conceal correspondence, mailbox rules are both a detection opportunity and a post-incident goldmine. Alert on new auto-forwarding to external addresses, block it by default where the business allows, and periodically review rules on finance-adjacent mailboxes. A rule that deletes or refiles messages containing payment keywords is close to a smoking gun.

SPF, DKIM and DMARC — deployed, and understood honestly

Email authentication (SPF, DKIM and a DMARC policy set to enforce) stops criminals from sending mail that exactly impersonates your domain, and helps receiving systems reject exact spoofs of others. Deploy it properly — many businesses have DMARC in monitoring mode for years without ever enforcing it. But be clear-eyed: DMARC does nothing against a lookalike domain, which is a different domain the attacker legitimately owns, and nothing against a genuinely compromised mailbox, whose messages pass every authentication check because they are, technically, authentic. Email authentication removes one technique from the attacker's kit. It does not remove the attack.

Lookalike-domain monitoring and defensive registration

Monitor for newly registered domains that resemble yours and your key suppliers' — transposed letters, added hyphens, swapped top-level domains. Defensively registering the most obvious variants of your own domain is cheap. When a lookalike appears, that is advance warning that someone may be preparing to impersonate you to your own customers, and worth acting on quickly.

Layer 3: people

The staff who process payments are not the weakness in this story — armed with the right training and the right culture, they are the sensor network that catches what the technology cannot.

Train the targets, specifically. Generic annual security awareness barely moves the needle on BEC. Targeted training for accounts-payable staff, payroll officers and executive assistants — the people fraudsters actually write to — does. Walk them through real attack anatomy: the changed-details email inside a genuine thread, the executive's urgent confidential request, the employee's new account before payday. Staff who have seen the play recognise the play.

Make urgency itself the red flag. Every BEC variant leans on time pressure, because time is what verification takes. Teach a simple reflex: the more urgent and the more confidential a payment request is, the more it must be verified through a second channel. A genuine supplier or executive is never harmed by a confirmation call; a fraudster is defeated by it.

Build a no-blame speak-up culture. The staff member who pauses a payment to double-check must be praised even when the request turns out to be genuine — especially then. And the staff member who realises they may have just paid a fraudulent invoice must know that reporting it immediately, without fear, is the difference between a recoverable incident and an unrecoverable one. Organisations that punish the messenger teach their people to sit on the one piece of information that decays by the hour.

The first hours after discovery

If a payment has gone to a fraudster's account, the clock is running. In rough order of priority:

  1. Call your bank immediately. Before meetings, before root-cause analysis, before drafting careful emails. Ask them to attempt recall of the payment and to contact the receiving bank to freeze the funds. Recovery is sometimes possible while money is still in the first account; the odds fall steeply with every hour, because moving the money on quickly is the whole point of the mule network.
  2. Report to ReportCyber. Lodge a report through ReportCyber, the Australian Government's online cybercrime reporting portal, which routes matters to the appropriate law-enforcement agency. Banks and police coordinate freezing and tracing more effectively when a formal report exists, and the report number matters later for insurers and disputes.
  3. Preserve the evidence. Do not delete, forward-and-tidy, or "clean up" anything. Preserve the fraudulent emails themselves with full headers, the mailbox audit logs, any mailbox rules found, sign-in records, and the payment records. If a mailbox is suspected compromised, secure it (reset credentials, revoke sessions) but capture its state first. This evidence determines what actually happened — and, later, who bears the loss.
  4. Notify the counterparty. If you paid a redirected supplier invoice, the supplier needs to know their mailbox may be compromised and that other customers may be receiving the same fraudulent details right now. If the compromise was on your side, your other counterparties may be at risk. Early, candid notification limits the blast radius for everyone.
  5. Understand that "whose system was compromised" will matter. When money is lost between two innocent businesses, the question of who bears the loss is frequently disputed, and the facts about where the compromise occurred and what verification was or was not done tend to be central to how those disputes resolve. We describe this generally — we are investigators, not lawyers, and you should take legal advice on your position. What we can say from the investigation side is that the party with preserved evidence and a documented verification process argues from a much stronger position than the party with neither.

Investigating how the compromise happened

Once the emergency response is moving, the question becomes how — because until you know how the attacker got in and what they touched, you cannot say the incident is over, and you cannot answer the loss question with evidence rather than assumption.

A proper BEC investigation typically covers mailbox forensics — reconstructing from audit logs which accounts were accessed, from where, when, and what was read or sent; a full rule and forwarding audit across the tenant, since attackers often plant rules in more mailboxes than the one that was noticed; and tracing the credential source — whether the password was phished, reused from an external breach, or captured some other way, and whether other accounts share the same exposure. The output is a timeline: entry, monitoring period, the fraudulent sends, and the exfiltration paths. That timeline tells you whether the attacker is truly out, which counterparties were exposed, what to fix so it cannot recur — and it is the factual backbone for any insurance claim or dispute about the loss.

This is the work we do. Financial Crime Advisory investigates BEC and invoice-fraud incidents end to end — mailbox forensics and compromise timelines, working with banks on tracing redirected funds, and hardening the finance processes and email controls so the same attack cannot land twice. See our services, or talk to a specialist — before the next invoice, or in the first hours after the wrong one.

BEC variants at a glance

The table below summarises the main variants, what each one looks like from the inside, and the primary control that defeats it.

VariantHow it looksPrimary control
Supplier invoice redirectionA genuine invoice or thread, with "updated" bank details and a plausible reasonCall-back verification of every bank-detail change, on an independently sourced number
Executive impersonation ("CEO fraud")Urgent, confidential transfer request apparently from a director or executiveDual authorisation over thresholds; no payment on email authority alone
Payroll diversionAn "employee" asks payroll to update their account before the next pay runVerify detail changes with the employee via a known channel, never by reply
Conveyancing / settlement redirectionDeposit or settlement account details supplied or "corrected" by email near a deadlinePhone confirmation of account details with the conveyancer on a known number
New-supplier fraudA convincing new vendor or contractor whose first invoice is the fraudNew-payee verification and supplier onboarding checks before first payment

Notice the pattern in the right-hand column: every primary control is a process control, and most of them are a phone call. That is the nature of this fraud — it enters through email, but it is defeated at the payment process.

Common questions

BEC & invoice fraud, answered

What is business email compromise?

Business email compromise (BEC) is a fraud in which a criminal uses email — either a genuinely compromised mailbox or a convincing lookalike — to impersonate someone the victim trusts, usually a supplier, an executive or a colleague, and to redirect a legitimate payment to an account the criminal controls. The most common form in Australia is payment-redirection fraud: a real invoice arrives, but the BSB and account number on it have been changed. Because the request rides on a genuine business relationship and a genuine transaction, it routinely defeats staff who would never fall for an obvious scam.

Who bears the loss when an invoice is paid to a fraudster's account?

It is genuinely contested and heavily fact-dependent. When a customer pays a fraudster instead of the real supplier, both parties usually blame each other: the supplier says the invoice was paid to the wrong account, the customer says the fraudulent instruction came from the supplier's own email system. Outcomes tend to turn on whose system was actually compromised, what each party knew or should have suspected, and whether the paying party took reasonable steps to verify the account details before paying. There is no simple rule, and you should get legal advice on your specific facts. The practical lesson is that prevention — a verified call-back before any bank-detail change — is dramatically cheaper than the dispute.

Can the bank get the money back?

Sometimes — but only if you move fast. If the receiving account still holds the funds, your bank can attempt a recall and ask the receiving bank to freeze the balance. Fraudsters know this, so money is typically moved on through mule accounts or converted within hours of landing. The realistic recovery odds fall steeply with every hour that passes, which is why calling your bank should be the very first action after discovery — before internal meetings, before working out how it happened, before anything else.

Does DMARC stop invoice fraud?

Partially. SPF, DKIM and DMARC stop criminals from sending mail that exactly spoofs your domain, and they are worth deploying properly for that reason. But they do nothing against the two techniques behind most invoice fraud: a lookalike domain that is one character different from the real one, and a genuinely compromised mailbox — where the fraudulent email passes every authentication check because it really did come from the supplier's account. Email authentication is one layer. Finance-process controls, above all call-back verification of bank-detail changes, are the backstop that works regardless of how the email arrived.

What is the single most effective control?

Call-back verification of every bank-account-detail change. Before updating a supplier's account details or paying to a new account, phone a known contact at the supplier on a number sourced independently — from your existing records or the supplier's official website, never from the email requesting the change — and confirm the new details verbally. It costs a few minutes, it requires no technology, and it defeats invoice redirection whether the attacker used a spoofed domain, a lookalike domain or the supplier's own compromised mailbox. No technical control offers the same coverage.

FCA
Financial Crime Advisory
Australia's fraud, AML & loss-prevention specialists

One changed invoice away from a six-figure loss?

Whether you want your payment process hardened before it happens, or the money has already gone and the clock is running — talk to a specialist. We investigate the compromise, work the trace, and close the gap it came through.