Support
Contact
Book a Free ReviewCall 1300 053 948
Scams

The invoice that changed banks: anatomy of a payment-redirection scam

One email, new bank details, money gone. How payment-redirection fraud actually unfolds inside a business email compromise — and the process that stops it.

No malware, no ransom note, no drama — just an invoice with new bank details, paid without a second thought. Payment redirection is the quietest way Australian businesses lose six figures. Here's exactly how it unfolds.

The Australian Signals Directorate's threat reporting consistently ranks business email compromise among the costliest cybercrimes for Australian business — self-reported losses in a recent year came in at almost $84 million, and payment redirection is its signature move. What makes it dangerous is how ordinary every step looks. Walk through the anatomy and you will see why process, not just technology, is the fix.

Step by step: how the scam actually works

1

One mailbox falls.

A phished password, no MFA — often not even your mailbox, but a supplier's or a conveyancer's. The attacker logs in quietly and does nothing conspicuous.

2

They read, and wait.

For weeks the attacker studies the mailbox: who invoices whom, for how much, in what format, with what sign-off. An inbox rule quietly forwards or hides relevant threads so the owner notices nothing.

3

They pick the moment.

The best moment is a genuine, expected, large payment — a settlement, a deposit, a project progress claim. The victim is already intending to pay.

4

The switch.

A real invoice is intercepted and re-sent with one change: the bank details. Or an email "from" the known contact — the real thread, the real style, sometimes the real mailbox — advises the account has changed.

5

The money moves, then vanishes.

Funds land in a mule account and are dispersed within hours. Recovery is possible only if the bank is alerted almost immediately — after a day or two, it is largely gone.

6

Discovery comes weeks later.

The supplier chases the unpaid invoice; both sides realise the payment went elsewhere; and two businesses that did "nothing wrong" begin an argument about who wears the loss.

Why smart people fall for it

Because nothing in the scam looks unusual. The email comes from a real thread with a real history at a plausible moment. There is no dodgy link and no attachment — nothing for spam filters or instincts to catch. Deepfake voice, which we covered in the $25M phone call, is now used to "confirm" changes when victims do try to check. The defence has to assume the email channel itself is compromised.

The controls that actually stop it

Out-of-band verification, without exception.

Any change of bank details is confirmed by phone on a number you already had — never one from the email. One habit, most of the risk gone.

MFA on every mailbox

yours and, contractually, your key suppliers'. The scam starts at the weakest inbox in the chain.

Mailbox-rule monitoring.

New forwarding rules and sign-in anomalies are the early fingerprints of a compromised account — exactly what our 24/7 SOC watches for.

Email authentication (DMARC)

makes your domain hard to spoof, protecting your clients from "you" asking them to pay elsewhere.

Two-person payment approval

over a set threshold — a second pair of eyes at the exact moment it matters.

FAQ

Frequently asked questions

If we pay a fraudulent invoice, can the bank recover it?

Only if you act immediately — call your bank the moment the fraud is suspected, and report via ReportCyber. Recovery odds fall from possible to poor within about 48 hours.

Who legally wears the loss — us or the supplier?

It is genuinely messy and often litigated: courts weigh whose systems were compromised and who failed to verify. Assume you cannot rely on recovering from the other party — prevention is the only clean answer.

Would our insurance cover a redirected payment?

Social-engineering fraud cover exists but is often a sub-limited optional extra with verification conditions attached — check the policy wording now, not after. Our renewal checklist covers what insurers expect.

What's the one process change to make this week?

Write the rule into your payments procedure: bank detail changes are only actioned after voice confirmation on a known number, and staff are praised — never hurried — for holding a payment to check.

Tighten the chain

We harden the whole path — mailboxes, monitoring, DMARC and payment process — for Melbourne finance and legal firms especially, because that is where the largest payments live. If your business moves big money on email instructions, talk to us before someone else's email does.

Book your free IT & Cyber Security Review

See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.