An email arrives from a supplier you have paid for years. Same signature, same tone, same invoice format. It says their bank has changed and asks you to update the account for the invoice already sitting in your payables. Accounts pays it. A fortnight later the real supplier chases the same invoice.
This is payment redirection fraud, usually sitting on top of business email compromise — someone has access to a mailbox, either yours or the supplier's, and is watching invoice traffic. It is not ransomware and the response is completely different. Nothing is encrypted. Nothing is locked. The only thing that matters is where the money is right now.
The first hour matters more than anything else you will do
Funds paid to a fraudulent account do not sit there. They are typically moved on or withdrawn quickly, often through further accounts. Your chance of recovery is highest before that happens — sometimes in the first hours, and it drops from there.
If you have just realised you paid the wrong account, do these things in this order.
1. Call your bank's fraud line. Do not email. Every major bank has a 24/7 fraud or scam number, usually printed on the back of your card and on the bank's contact page. Phone it. Ask specifically for a recall or trace of the payment and tell them it is a business email compromise / payment redirection scam. Have ready: the date and time of the payment, the amount, the BSB and account number it went to, the account name used, and your own account details. Ask for a reference number before you hang up.
2. Stop anything else queued. Check whether that supplier has other invoices scheduled, whether the same new account details were saved into your accounting system, and whether any other supplier records were changed in the same period. Freeze the payment run.
3. Call the real supplier on a number you already had. Not a number in the email. Use the number on an old invoice, your CRM, or their website. Confirm the account is not theirs, and warn them their mailbox may be compromised. If the compromise was on their side, other customers are being hit right now.
4. Preserve the evidence. Do not delete the emails. Export or save them with full headers if you can. Screenshot the changed supplier record in your accounting system and note who changed it and when. Your bank, police and insurer will all ask.
5. Report to ReportCyber. ReportCyber at cyber.gov.au is the Australian Government's official channel for reporting cybercrime including business email compromise, and reports made through it are referred to police. Keep the report reference number.
6. Report to Scamwatch. Scamwatch, run by the ACCC, is the reporting channel for scams and publishes annual scam loss data including payment redirection and false billing losses reported by businesses. Reporting does not recover your money, but it feeds the national picture.
7. Work out whether personal information was exposed. If a mailbox — yours or one you control — was compromised and it held personal information about customers or staff, you may have obligations under the Notifiable Data Breaches scheme in the Privacy Act, including assessing the breach and, in some cases, notifying the OAIC and the affected individuals. Whether the scheme applies to your business, and what it requires, depends on your circumstances. Start the assessment early rather than at the end of the week, and check the current OAIC guidance or take advice from your lawyer on the thresholds and timeframes.
8. Tell your insurer and your accountant. If you hold cyber cover, most policies have notification timeframes. Whether a loss like this is covered depends entirely on your policy wording and your own controls at the time — read it, or ask your broker. Do not assume.
Whether the money comes back depends on the receiving bank, how fast the funds moved, and the facts of your case. No one can promise recovery. Speed is the only variable you control.
While you are still in the first day: assume the mailbox is compromised
If the fraudulent email came from the supplier's real address, their mailbox is likely compromised. If it came from a lookalike domain, yours might still be fine. But if you have had any unexplained mail rules, missing invoices, or staff reporting emails they did not send, treat your own environment as suspect.
- Force a password reset on the affected mailbox and any account sharing that password.
- Check mailbox rules for auto-forwards or rules that move messages containing "invoice", "payment" or "BSB" into an obscure folder. That is the classic sign.
- Review sign-in logs for unfamiliar locations or devices.
- Turn on multi-factor authentication for every email account, today.
The Australian Signals Directorate's Essential Eight lists multi-factor authentication among its baseline mitigations. MFA on email is the single control most directly aimed at the mailbox compromise that sits underneath this kind of invoice fraud. If you have staff without it, that is the first job this week. Check the current maturity model on the ASD site for the detail of what is expected at each level.
The control that actually stops it: callback on a previously known number
Awareness training does not stop this. The emails are well written, they reference real invoices, and they arrive from real addresses. Telling staff to "look for spelling errors" is advice from a decade ago.
The control that works is procedural, not perceptual. Write it down, and apply it without exception:
> Any change to a supplier's banking details must be verified by phone call to a number held on file before the change was requested — never a number supplied in the change request itself. The call must be documented: who called, who they spoke to, the number used, the date.
The "previously known number" part is what makes it work. Fraudsters supply their own phone number in the email and answer it. If your only verification is calling the number in the message, you have verified nothing.
Practical ways to make it stick:
- Lock supplier bank details in your accounting system. Restrict who can edit them. Most systems can log changes — turn that on and review the log monthly.
- Dual authorisation on payment runs. One person prepares, a different person releases. Set a threshold if you must, but be aware fraudsters test with amounts just under known limits.
- Give staff explicit permission to delay. The email will say it is urgent and the supplier will be annoyed. Make it clear in writing that no one is ever in trouble for holding a payment to make a verification call.
- Apply it to everyone. The long-standing supplier, the director's own request, the one you spoke to yesterday. Exceptions are where the losses happen.
- Verify at onboarding too. Confirm the account for a new supplier's first payment the same way.
What to do next
If you have already paid, work the list above starting with the bank fraud line. If you have not, spend an hour this week doing three things: confirm MFA is on every mailbox, write the callback rule into your payables procedure, and check who can edit supplier bank details in your accounting system.
For current figures on the cost and frequency of this attack in Australia, go to the source rather than a secondary summary — the ASD Annual Cyber Threat Report and the ACCC's Targeting Scams reporting both publish updated numbers, and the reporting period matters when you are quoting them to a board or an insurer.
Sources
- Australian Signals Directorate / ACSC — Annual Cyber Threat Report
- ReportCyber — Report and recover (cyber.gov.au)
- ACCC Scamwatch
- Australian Signals Directorate — Essential Eight