Australian Resource Centre
IT

Paid an invoice to changed bank details: what to do in the first hour, and how to stop the next one

A practical response plan for invoice payment redirection: who to call in the first hour, why the compromised mailbox may be yours, and the change-of-bank-details procedure that actually prevents the next loss.

2026-09-08

An email arrives from a supplier you deal with all the time. Same signature, same thread, same tone. "We've changed banks — please use the new account for this invoice." Someone in accounts pays it. Days or weeks later the real supplier chases the money and you realise it went somewhere else.

This is invoice payment redirection, one form of business email compromise (BEC). The Australian Federal Police has publicly warned that criminals were targeting the construction sector with BEC scams using fraudulent invoices and altered bank details — a sector full of subcontractors paying large progress claims by EFT. That warning was on the AFP site as at 28 October 2025, the date this article's research was checked. The pattern is not limited to construction, but the mechanics are the same everywhere: someone reads your email thread, waits for a real invoice, and changes two lines of it.

Two things matter. What you do in the first hour, and the procedure you put in place so it does not happen again.

The first hour after you realise

Speed is the only advantage you have. Once the funds are moved out of the receiving account and split across other accounts, tracing and recovery get much harder. Work through this in parallel, not in sequence — put different people on different tasks.

  1. Call your bank's fraud team, not the general line. Say the words "payment redirection fraud" and ask them to attempt a recall or trace on the transaction. Have ready: the date and time of payment, the amount, the receiving BSB and account number and account name, and your own account details. Recall processes and success rates differ between banks and depend on where the money has gone, so ask directly what they can attempt and by when.
  2. Stop anything still in the queue. Check for scheduled or batched payments to the same account, and any other invoices from that supplier awaiting payment. If the same fake details have been entered into your accounting system as the supplier's saved account, they will keep being used.
  3. Call the real supplier on a number you already hold — from a contract, a previous statement, or your own records. Not a number in the email. Tell them their invoice or your correspondence has been intercepted and ask them to check their own systems.
  4. Report it to government. Cybercrime and scam incidents affecting businesses are reported through ReportCyber and Scamwatch. Reporting will not usually recover funds on its own, but it creates the record you will need for insurance, for your bank, and for any police follow-up, and it feeds intelligence on the receiving accounts.
  5. Preserve the evidence. Do not delete the emails. Keep the full message with headers if you can, screenshots of the invoice, and a written timeline of who did what and when. If you engage an IT provider or insurer later, this is the first thing they will ask for.
  6. Check your cyber or fraud insurance. If you hold a policy, notify the insurer early. Cover for funds transfer fraud varies a great deal between policies and some have short notification windows — read yours rather than assume.

You will find average-loss figures for BEC quoted widely online. Treat second-hand numbers with caution and pull the current figure from the official annual cyber threat report if you need one for a board paper or a business case.

The compromised mailbox is often yours

Most advice assumes the supplier was hacked. Often the attacker is sitting in your own mailbox, reading the thread and waiting. Before you conclude anything, have someone check your email tenancy:

If anything looks wrong, reset passwords, revoke active sessions, remove the rules, and re-enrol multi-factor authentication. If you do not have someone who can read those logs confidently, get an IT provider in the same day. Assume the attacker still has access until you have evidence they do not — they will often try again with a second invoice while you are distracted by the first.

The part that changes how seriously owners treat this

As a general position, money paid into an account that is not your supplier's may not discharge the debt you owe them — so you can be out of pocket and still holding an unpaid invoice. But that depends entirely on the facts: your contract, your conduct, the supplier's conduct, and where the compromise occurred. This is general information, not legal advice. Get advice on your own situation before you pay anything twice or concede liability, and do not try to settle it by argument over the phone. Plan on the basis that the loss may sit with your business, because that is what makes the prevention worth the friction.

The controls that actually work

Vendor content tends to stop at "verify by phone". That is right, but it is not a procedure. Write the procedure down this week and make it a condition of paying.

What to do next

If you have just paid, work the first-hour list now — bank fraud team first, then the supplier on a known number, then your mailbox. If you are reading this because someone you know got hit, spend an hour this week doing three things: write the change-of-bank-details call-back rule, set the dual-authorisation threshold, and have your IT provider confirm multi-factor authentication and forwarding-rule alerts are on across every mailbox that touches invoices. Those three cost nothing and remove most of the opportunity.

Sources

Written by ARC Editorial, drafted and reviewed with claude-opus-5. ARC publishes these to help business owners find answers; if something here matters to your situation, a Facilitator can point you at someone who has solved it.

Stuck on this in your own business?

ARC is a facilitated community — a real person works out who in the room has already solved your problem, and introduces you.

See what ARC is
← All articles