The email says your supplier's bank details have changed
This is the fraud that takes the largest single amounts from Australian small businesses. It goes by payment redirection, or business email compromise, and it cost Australians $166.8 million in 2025 — up 9.3 per cent on the year before, and the second-largest loss category in the country behind investment scams.
For small businesses specifically, the picture is worse than the headline suggests. In the National Anti-Scam Centre's 2025 data, false billing — the category that captures this fraud — was the most frequently reported scam type of all, both with and without financial loss.
What it actually looks like
Not much. That is the problem.
There is nothing wrong with that email. It is polite, it references your real invoice number and the right amount, it comes from the address you have always used, and it sits in the thread you have been replying to for months. The only thing wrong with it is the account number, and no amount of reading will tell you that.
In the most expensive version, the criminal is inside the supplier's mailbox. They have read your last six months of correspondence. They know your invoice numbers, your payment terms, your first names and how your supplier signs off. The ACCC describes exactly this: the scammer either hacks into the business's email system, or impersonates the address by changing as little as one character.
The step that catches careful people
Most people who feel uneasy do the obvious thing: they reply and ask.
So the check cannot happen on the same channel as the request. Verifying by email means verifying with whoever controls the mailbox — and that is precisely the thing in question.
The version nobody warns you about
Almost every warning describes a supplier saying their details have changed. That version is real. It is also the easier one to catch, because there is something to compare against.
The version that quietly takes more money never claims anything changed at all. It is the first invoice from a new supplier — a subcontractor you engaged last month, a materials wholesaler you have opened an account with, a consultant whose first bill is due. You have never seen their real bank account. There is no earlier invoice on file.
So the criminal does not need a story. They simply supply the details, and there is nothing to notice.
If your bank warns you, believe your bank
Australian banks now run Confirmation of Payee, which checks whether the account name matches the account number before a first-time payment. It is a genuinely good control, and criminals have adapted to it in the most direct way available: they tell you the warning is coming.
A real supplier never says this. A real supplier says the opposite: if the name does not match, stop and ring us. Any message that arrives in advance to explain away a bank's warning is one of the clearest fraud signals in this whole category.
The two minutes that stop it
- Don't reply to the email. Leave the thread alone entirely.
- Find the number yourself — an old invoice, your accounting system, a signed contract, their website. Never the signature block on the message in front of you.
- Read the BSB and account number back. Not "did you send this invoice" — ask them to confirm the digits. A compromised mailbox does not stop the real person answering their phone.
- Check the name matches when you enter the payee, and stop if it doesn't.
- Write down who verified it and when. One line in the accounting system. It is what an insurer or auditor will ask for, and it makes the habit visible to whoever pays next time.
Why BAS weeks are worse
Criminals read the calendar. The last week of October, February, April and July is when Australian small businesses have the most payments moving, the least attention to spare, and the most plausible reason to receive an unexpected bill. An invoice that would get a second look in the middle of a quiet month gets paid on the 27th.
If you only apply the verification habit in one week of the quarter, apply it in that one.
If the money has already gone
Move now, before you are certain. Recovery depends almost entirely on speed, because funds are usually moved on within hours.
- Ring your bank and say it was a scam payment. Ask them to attempt a recall and to contact the receiving bank.
- Report to ReportCyber at cyber.gov.au and Scamwatch at scamwatch.gov.au.
- Call IDCARE on 1800 595 160 — Australia's free national identity and cyber support service.
- Tell the real supplier. Their mailbox may still be compromised, and their next customer may be about to pay the same account.
- Keep the thread. Don't delete it, don't reply to it. It is evidence.
On refunds, be realistic. Australia's Scams Prevention Framework began applying to banks from 1 July 2026 and opens a complaints path through AFCA from January 2027, but unlike the UK model it does not guarantee reimbursement — and business payments are treated differently from consumer ones. Prevention is doing nearly all of the work here.
Common questions
The email came from our supplier's real address. Doesn't that mean it's genuine?
No. In the most damaging version of this fraud the criminal is inside the real mailbox, so the email genuinely comes from the real address and sits inside your existing thread with the right signature and the right invoice attached. There is no misspelling to spot. The sender address is not evidence. The only reliable check is a phone call to a number you found yourself.
Can we just reply to the email and ask them to confirm the account?
No, and this is the step that catches careful people. If the mailbox is compromised or the address is a lookalike, your reply goes to the criminal - who will answer politely and explain the change, often mentioning a bank merger or a new entity. Scamwatch describes this exact behaviour. Verifying by email means verifying with the scammer. You have to change channel.
Nothing said the details had changed - it's just the first invoice from a new supplier. Do we still check?
Yes, and this is the version almost nobody writes about. Warnings describe a scammer claiming details have changed, but with a new supplier you have never seen the real account, so no story is needed. The criminal simply supplies an account number and there is nothing to compare it against. Any first payment to any payee should be confirmed by voice.
Our bank showed a name mismatch but the supplier told us to expect it. What now?
Stop, and do not pay. Australian banks run Confirmation of Payee, which checks the account name before a first-time payment. A message telling you in advance to ignore a mismatch - because the account sits under a parent company, or the bank is mid-migration - is one of the clearest fraud signals there is. A real supplier tells you the opposite: if the name does not match, stop and ring us.
Are small businesses really targeted more than large ones?
Small businesses combine meaningful payment values with thin controls, which is the profile criminals prefer. In the National Anti-Scam Centre's 2025 data, false billing - the category that captures this fraud - was the most frequently reported scam type for small businesses, both with and without financial loss. Reported losses also understate the truth, because many incidents are absorbed quietly and never reported.
We have already paid. How fast do we need to move?
Immediately, and before you are certain. Ring your bank now, say it was a scam payment, and ask them to attempt a recall and contact the receiving bank. Recovery depends almost entirely on speed - funds are usually moved on within hours. Then report to ReportCyber and Scamwatch, and call IDCARE on 1800 595 160. Being wrong costs you a phone call; being slow costs the money.
Will our bank refund a business payment?
Do not assume so. Australia's Scams Prevention Framework began applying to banks from 1 July 2026 and opens a complaints path through AFCA from January 2027, but unlike the UK model it does not guarantee reimbursement, and business payments are treated differently from consumer ones. Whether you are compensated turns largely on whether the bank met its obligations, not on the fact you were deceived.
Does cyber insurance cover this?
Sometimes, under social engineering or funds transfer fraud extensions - usually with sub-limits and strict conditions. Read the conditions before an incident, not after: a policy that requires call-back verification will not pay out if the call was skipped. That makes the verification habit worth having twice over.
Check an invoice before you pay it
Forward the email, the invoice or a photo of it to Is it a scam? and get a plain-English verdict back in seconds — you and up to three others, unlimited by email and WhatsApp, with a tax invoice for a deductible expense.
See the Business plan