Skip to content

Cyber Security6 min read

How to stop invoice and payment fraud

The most common way Australian businesses lose money to cybercrime, and the five habits that stop it.

By Ventiq ·

A glass invoice with a small blue padlock resting on it

It usually starts with an email that looks completely normal.

A supplier you have paid for years writes to say they have changed banks, and could you please update their details before the next invoice. Or a settlement agent sends the account for a deposit. Or your own managing director, travelling, asks the bookkeeper to make an urgent payment. The email address looks right. The tone is right. The timing is plausible. The money is paid, and it is gone.

This is business email compromise, and it is consistently among the most costly forms of cybercrime reported by Australian businesses. It does not need clever technology. It needs one compromised mailbox, or one convincing look-alike address, and one busy person.

How the fraud actually works

There are two common versions.

The hijacked mailbox. An attacker gets the password to a real email account, often through a fake login page sent in a phishing email, or a password reused from another breached website. They read quietly for weeks, learn who pays whom and when, and then step in at exactly the right moment with a changed bank account. Sometimes they set up rules in the mailbox that hide the real replies, so nobody notices the conversation has been hijacked.

The look-alike address. The attacker registers a domain one letter away from a real one, or uses a free email account with the right display name, and relies on nobody checking carefully. On a phone screen, the display name is all you see.

In both cases the request is for something routine. That is the point. It does not look like an attack.

Five habits that stop it

1. Confirm bank details by phone, every time

Any new bank account, and any change to an existing one, is confirmed by a phone call to a number you already have on file, never one in the email. This single rule, applied without exception, defeats most of these attacks outright. Write it down, train it, and make it impossible to skip for payments above a threshold.

2. Turn on multi-factor authentication for every mailbox

If a stolen password is not enough to log in, the hijacked-mailbox version of the fraud mostly fails. Multi-factor authentication should be enforced for every user, including directors and part-timers, with an authenticator app rather than SMS where possible.

3. Protect your email domain from impersonation

Three technical settings, called SPF, DKIM and DMARC, tell the world’s mail servers which systems are allowed to send email as your domain, and what to do with email that fails the check. Set up correctly, they stop criminals sending email that appears to come from you, and they help your own mail land in inboxes instead of junk. Most businesses have these partly configured at best.

4. Use email security that looks for impersonation, not just malware

Older email filters look for viruses. Modern email security also looks for the signs of impersonation: a display name that matches your director on an address that does not, a domain registered last week, language about urgency and payments. These tools catch what people miss.

5. Watch for the quiet signs of a compromised mailbox

Mailbox rules that forward or delete messages, logins from unexpected countries, and sudden changes in sending patterns are all visible to whoever manages your Microsoft 365 tenant. Someone should be watching, and alerts should go to a person who will act.

What to do if it has already happened

Call your bank immediately; funds can sometimes be recalled if you act within hours. Report it to ReportCyber, the Australian government’s reporting service, and to the police. Reset passwords, turn on multi-factor authentication, check every mailbox for hidden rules, and tell the counterparty whose identity was used. Then look at why it worked, and fix that.

The honest summary

Invoice and payment fraud is not sophisticated. It is persistent, and it preys on normal, busy people doing their jobs. The defences are not sophisticated either: one unbreakable verification habit, multi-factor authentication, domain protection, modern email security and someone watching. If you would like help putting those in place and proving it to your insurer, see our Cyber Security & Compliance service, or start a conversation.

Next step

Let us make your technology secure, simple and accountable.

Tell us what is working, what is not and where the business is heading. We will give you a clear, practical path forward.