An email arrives from a supplier you deal with all the time. Same signature, same thread, same tone. "We've changed banks — please use the new account for this invoice." Someone in accounts pays it. Days or weeks later the real supplier chases the money and you realise it went somewhere else.
This is invoice payment redirection, one form of business email compromise (BEC). The Australian Federal Police has publicly warned that criminals were targeting the construction sector with BEC scams using fraudulent invoices and altered bank details — a sector full of subcontractors paying large progress claims by EFT. That warning was on the AFP site as at 28 October 2025, the date this article's research was checked. The pattern is not limited to construction, but the mechanics are the same everywhere: someone reads your email thread, waits for a real invoice, and changes two lines of it.
Two things matter. What you do in the first hour, and the procedure you put in place so it does not happen again.
The first hour after you realise
Speed is the only advantage you have. Once the funds are moved out of the receiving account and split across other accounts, tracing and recovery get much harder. Work through this in parallel, not in sequence — put different people on different tasks.
- Call your bank's fraud team, not the general line. Say the words "payment redirection fraud" and ask them to attempt a recall or trace on the transaction. Have ready: the date and time of payment, the amount, the receiving BSB and account number and account name, and your own account details. Recall processes and success rates differ between banks and depend on where the money has gone, so ask directly what they can attempt and by when.
- Stop anything still in the queue. Check for scheduled or batched payments to the same account, and any other invoices from that supplier awaiting payment. If the same fake details have been entered into your accounting system as the supplier's saved account, they will keep being used.
- Call the real supplier on a number you already hold — from a contract, a previous statement, or your own records. Not a number in the email. Tell them their invoice or your correspondence has been intercepted and ask them to check their own systems.
- Report it to government. Cybercrime and scam incidents affecting businesses are reported through ReportCyber and Scamwatch. Reporting will not usually recover funds on its own, but it creates the record you will need for insurance, for your bank, and for any police follow-up, and it feeds intelligence on the receiving accounts.
- Preserve the evidence. Do not delete the emails. Keep the full message with headers if you can, screenshots of the invoice, and a written timeline of who did what and when. If you engage an IT provider or insurer later, this is the first thing they will ask for.
- Check your cyber or fraud insurance. If you hold a policy, notify the insurer early. Cover for funds transfer fraud varies a great deal between policies and some have short notification windows — read yours rather than assume.
You will find average-loss figures for BEC quoted widely online. Treat second-hand numbers with caution and pull the current figure from the official annual cyber threat report if you need one for a board paper or a business case.
The compromised mailbox is often yours
Most advice assumes the supplier was hacked. Often the attacker is sitting in your own mailbox, reading the thread and waiting. Before you conclude anything, have someone check your email tenancy:
- Mailbox rules and forwarding. Look for inbox rules that move messages containing words like "invoice", "payment", "bank" or the supplier's name into an obscure folder or delete them. Look for forwarding to an external address. These are the classic fingerprints.
- Sign-in logs. Check recent sign-ins to the affected accounts for unfamiliar locations, unfamiliar devices, or successful logins that bypassed multi-factor authentication.
- App and device consents. Look for third-party apps or mail clients connected to the account that nobody recognises.
- Sent items. Attackers sometimes send from your account and delete the evidence, so a gap in the sent folder is worth investigating.
If anything looks wrong, reset passwords, revoke active sessions, remove the rules, and re-enrol multi-factor authentication. If you do not have someone who can read those logs confidently, get an IT provider in the same day. Assume the attacker still has access until you have evidence they do not — they will often try again with a second invoice while you are distracted by the first.
The part that changes how seriously owners treat this
As a general position, money paid into an account that is not your supplier's may not discharge the debt you owe them — so you can be out of pocket and still holding an unpaid invoice. But that depends entirely on the facts: your contract, your conduct, the supplier's conduct, and where the compromise occurred. This is general information, not legal advice. Get advice on your own situation before you pay anything twice or concede liability, and do not try to settle it by argument over the phone. Plan on the basis that the loss may sit with your business, because that is what makes the prevention worth the friction.
The controls that actually work
Vendor content tends to stop at "verify by phone". That is right, but it is not a procedure. Write the procedure down this week and make it a condition of paying.
- A single change-of-bank-details process. Any request to change a supplier's account details — by email, letter, portal message, or phone — triggers a call-back to a phone number already on file, to a named contact you have dealt with before. Never a number in the request. Never a reply to the email. Document the call: who you spoke to, on what number, at what time.
- Two people, not one. Require dual authorisation for any new or changed payee, and for any payment above a threshold you set for your business. Pick the threshold based on what you could absorb losing, not on convenience.
- Lock the master file. The person who can change supplier bank details in the accounting system should not be the person who can release payments. If your team is too small for that, the second check should be the owner.
- Slow down urgency. Pressure to pay today, a changed email address by one character, a request to switch to a new contact, or a bank account name that does not match the trading name — any of these means stop and call.
- Technical basics. Multi-factor authentication on all mailboxes, alerting on new mailbox forwarding rules, and restricting who can create them. Set this up once and it keeps working.
- Tell your own customers your details do not change. Put a line on your invoices stating that you will never notify a change of bank details by email, and that any such request should be verified by phone. It protects your customers and your reputation.
What to do next
If you have just paid, work the first-hour list now — bank fraud team first, then the supplier on a known number, then your mailbox. If you are reading this because someone you know got hit, spend an hour this week doing three things: write the change-of-bank-details call-back rule, set the dual-authorisation threshold, and have your IT provider confirm multi-factor authentication and forwarding-rule alerts are on across every mailbox that touches invoices. Those three cost nothing and remove most of the opportunity.
Sources
- Criminals target construction sector in business email compromise scams — Australian Federal Police (checked 28 October 2025)
- Official reporting channels for cybercrime and scams: ReportCyber (cyber.gov.au) and Scamwatch — channel names and forms have changed over time, so confirm the current channel on the site before reporting.