No ransomware, no malware, often no technical hack at all - just a convincing email and a moment of trust. Business Email Compromise (BEC) is consistently one of the costliest categories of cybercrime reported by Australian businesses, precisely because it exploits normal business processes rather than breaking through technical defences.
What Business Email Compromise Actually Is
BEC is a scam where an attacker impersonates a trusted party - a supplier, an executive, or a known contact - usually by email, to trick someone into making a payment, changing bank details, or sending sensitive information. The attacker may have compromised a real email account, or simply set up a look-alike domain that's easy to miss at a glance.
How the Invoice Fraud Version Typically Plays Out
- Reconnaissance - the attacker researches the business, often through its own website or LinkedIn, to identify who handles payments and who the business deals with regularly.
- Account compromise or impersonation - either a real supplier or staff email account is compromised (often via earlier phishing), or a near-identical domain is registered to impersonate one.
- The request - an email arrives that looks exactly like a normal invoice or payment request, sometimes inserted into a genuine, ongoing email thread to add credibility.
- The change - the email asks for payment to "updated" bank details, or for an existing invoice to be paid to a new account, often citing a plausible reason like a bank account change.
- The loss - by the time the real supplier follows up asking why they haven't been paid, the money is gone, usually moved through several accounts within hours.
Why It Works So Well
- It doesn't trip security software - there's no malicious attachment or link to flag, just a normal-looking email with different bank details.
- It exploits real relationships - the request looks like it's coming from someone the business actually deals with, which lowers natural suspicion.
- It relies on routine - paying supplier invoices is a normal, repeated task, which makes a fraudulent one easy to process without a second look.
- Urgency discourages verification - many of these emails include a reason for urgency, designed to discourage the recipient from picking up the phone to check.
How to Actually Stop It
- Verify any change to payment details by phone - using a number you already have on file, not one provided in the email itself. This single habit stops the vast majority of invoice fraud attempts.
- Set a policy, not just a habit - make "verify bank detail changes by phone" a documented requirement for anyone who processes payments, not an informal best practice some staff know and others don't.
- Use multi-factor authentication on every email account - this closes off the account-compromise version of the attack, which is how many BEC scams start in the first place.
- Watch for look-alike domains - a supplier's real domain and a near-identical one (a swapped letter, a different extension) can look the same in a quick glance at a mobile inbox.
- Train staff on this specific scenario - general phishing awareness doesn't always cover BEC, because there's often no obvious "phishing" red flag like a suspicious link.
If It's Already Happened
Speed matters more than anything else. Contact your bank immediately to attempt a recall, report it to ReportCyber (the ACSC's reporting platform), and review whether any email accounts were actually compromised as part of the scam - not just impersonated - so the access can be shut down.
Where to Start
If your business doesn't have a documented payment-verification process, that's the single highest-value fix available - it costs nothing to implement and closes off the most common version of this attack entirely.
Frequently Asked Questions
How is Business Email Compromise different from a normal phishing attack?
BEC often doesn't involve any malware or dodgy link at all, just a convincing email asking for a legitimate-looking payment to be sent to updated bank details. That's exactly why it slips past security software that's designed to catch malicious attachments and links.
What's the single best way to stop invoice fraud?
Verify any change to payment or bank details by phone, using a number you already have on file rather than one given in the email. This one habit, made into a documented policy rather than an informal habit some staff know about, stops the vast majority of these scams.
What should we do if we've already paid a fraudulent invoice?
Contact your bank immediately to attempt a recall, since speed matters more than anything else in these situations. It's also worth reporting the incident to ReportCyber and checking whether an email account was actually compromised, not just impersonated, so any access can be shut down.
Does MFA actually help against Business Email Compromise?
Yes, MFA on every email account closes off the account-compromise version of this scam, which is how a lot of BEC attacks start in the first place. It won't stop a look-alike domain being used to impersonate a supplier, which is why a phone verification habit still matters alongside it.
We help Perth businesses lock down email accounts and build practical processes that stop invoice fraud before it costs you anything.
Cybersecurity Services →No verification process for payment changes yet?
Call 0433 087 091 for a free, no-obligation conversation about protecting your business.
Book a Free ConsultationFor related reading, see our guides to Common Phishing Email Tactics Targeting Perth Businesses and Email Security for Perth Businesses.