Your accounts team gets an email from a supplier you have paid for years. Same name, same signature, same tone. It says their bank has changed and asks you to use the new account for this month's invoice. Someone updates the payee, the payment run goes out on Friday, and three weeks later the real supplier rings asking where their money is.
That is business email compromise, usually shortened to BEC. It needs no malware and no clever exploit. It works because it looks exactly like normal business, and because paying a supplier is a routine job done by busy people.
It is also one of the most common ways Australian businesses lose money online. In its Annual Cyber Threat Report 2024-25, published in October 2025, the Australian Signals Directorate said email compromise was the top cybercrime reported by businesses: 19% of business reports were email compromise with no money lost, and another 15% were BEC fraud where money was lost. The same report put the average self-reported cost of cybercrime to a small business at $56,600 per report. The National Anti-Scam Centre's Targeting Scams report for 2025 counted $166.8 million lost to payment redirection scams that year, the second largest category after investment scams.
How it works
There are two common versions, and the difference matters for the fix.
In the first, the criminal never gets into anyone's mailbox. They register a domain that looks like your supplier's (an extra letter, .com instead of .com.au) or simply spoof the display name, then send a convincing request to change bank details.
In the second, they get into a real mailbox, often yours or your supplier's, usually with a stolen password or a phishing page that captures the sign-in. Then they wait. They read the threads, learn who pays whom and when, and create inbox rules so replies from the real supplier or your bank are moved to a folder nobody checks, or forwarded to an outside address. When a large invoice is due, they reply inside the genuine thread with new bank details. Nothing about it looks odd, because it is sent from the real account.
The second version is why "check the sender's address" is not enough advice on its own.
Are you affected?
If your business pays suppliers by bank transfer, or receives payments from customers who could be told to pay somewhere else, this applies to you. Some tell-tale signs:
- A supplier or customer says they emailed you something you never received.
- Inbox rules you did not create, especially ones that forward mail outside the business or move messages with words like "invoice", "payment" or "bank".
- Sign-ins to Microsoft 365 from countries or networks your staff do not use.
- A request to change bank details that comes with urgency ("before today's cut-off") or a reason you cannot easily check.
How to fix it
The strongest control here is a process, not a product. Technology reduces how often the fake email arrives. The call-back is what stops the payment.
- Call back on a number you already hold. Any change to bank details, from any supplier, is confirmed by phone using the number in your supplier file or on a past invoice. Never the number in the email asking for the change. Write this down as a rule and tell your suppliers you follow it, so they expect the call.
- Two people for payee changes and large payments. One person enters a new or changed payee, a second person approves it. Most banking platforms and accounting systems support dual authorisation. Turn it on and set a threshold that fits your business.
- Make MFA mandatory for every mailbox. Multi-factor authentication stops most password-only takeovers. For finance and admin staff, move towards phishing-resistant methods such as passkeys or FIDO2 security keys, because some phishing kits can relay a code or push approval in real time. See our article on adversary-in-the-middle phishing that gets past MFA.
- Watch mailbox rules and forwarding. In Microsoft 365, block automatic forwarding to external addresses with an outbound spam policy. The default, "Automatic - System-controlled", blocks it in most tenants but not all, so Microsoft recommends setting it explicitly to Off. Make sure someone actually reads the alerts Microsoft 365 raises about suspicious forwarding, and check finance mailboxes for rules you cannot explain.
- Set up DMARC on your own domain. DMARC stops criminals sending email that claims to come from your exact domain, which protects your customers from fake invoices "from you". It does not stop lookalike domains, which is why step 1 matters. Our plain English guide to SPF, DKIM and DMARC covers how to get to enforcement safely.
- Train the people who pay the bills. A short, specific session for the accounts team on what a payment redirection email looks like is worth more than a generic annual course.
If you think it already happened
Speed matters more than anything else. Money can sometimes be recovered if the bank acts within hours.
- Call your bank straight away and ask them to recall the payment and contact the receiving bank.
- Report it to ReportCyber at cyber.gov.au or call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371).
- Reset the password of any mailbox you think was accessed, sign it out of all sessions, remove unknown inbox rules and check what MFA methods are registered to it.
- Tell the supplier or customer involved, by phone.
- If the attacker could read mailboxes that hold personal information, check whether the Notifiable Data Breaches scheme applies. Our guide to notifiable data breaches explains the test.
Where Geidi fits
Geidi's cyber security services include a 24/7 security operations centre and security practices aligned to Essential Eight. If you'd like to talk about protecting your payment process, talk to us.
Sources
- Australian Signals Directorate: Annual Cyber Threat Report 2024-2025
- National Anti-Scam Centre: Targeting scams report 2025 (PDF)
- Microsoft Learn: Control external email forwarding in Microsoft 365
- Microsoft Learn: Detect and remediate Outlook rules and custom forms injection attacks
- Microsoft Learn: Authentication strengths in Microsoft Entra ID
- Microsoft Learn: Set up DMARC to validate the From address domain

