Home › Knowledgebase › KB-195

How to recognise and avoid business email compromise (BEC) scams targeting invoices and payments

Summary

This guide helps you troubleshoot and resolve: How to recognise and avoid business email compromise (BEC) scams targeting invoices and payments. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Business Email Compromise (BEC) scams are among the most financially damaging cyber crimes affecting Australian small businesses. Attackers impersonate trusted contacts such as CEOs, suppliers, or finance teams to redirect invoice payments or trick staff into transferring funds. This guide explains how to recognise the warning signs and the verification steps your team should follow before any payment is made.

What is a BEC scam?

BEC scams involve an attacker gaining access to, or spoofing, a legitimate business email account. They then send convincing messages designed to alter normal payment processes. Common variants include:

Warning signs to watch for

Train your team to pause and verify when any of the following appear:

Always inspect the full email address, not just the display name. On most email clients you can hover over or click the sender's name to reveal the actual address.

Verification steps before any payment change

Implement a two-person verification policy for any change to payment details. The following process should become standard practice across your organisation.

Step-by-step verification procedure

  1. Do not reply to the email or use any phone numbers or links contained within it.
  2. Open a new email or message thread and contact the sender using a known, previously verified address or phone number from your own records.
  3. Confirm verbally that the request is genuine and document the call, including who you spoke with and when.
  4. Cross-check the new bank details against those held in your finance system. A change in BSB or account number is a major red flag.
  5. Obtain secondary sign-off from a second authorised person before processing the payment.
  6. Wait at least 24 hours for any "urgent" request involving new payment details. Genuine suppliers will understand the delay.

Even if the email appears to come from your CEO or a long-standing supplier, the same verification rules apply. Attackers deliberately target these relationships because employees are less likely to question them.

Technical red flags in the email itself

Beyond the message content, the technical details of an email can reveal a scam:

How to report a suspected BEC email to 220 Internet Services

If you receive a suspicious email targeting your business, report it as quickly as possible. Early reporting can prevent further attempts and protect other customers.

Reporting steps

  1. Do not delete or forward the email from your normal inbox.
  2. In Microsoft Outlook, open the message and select Home > Report Message > Phishing. In Google Workspace, use the Report phishing option from the message menu.
  3. If you have already clicked a link or replied, change any exposed passwords immediately and notify your account holder.
  4. Open a support ticket through the 220 customer portal and attach the original email as an .eml or .msg file. Include a brief timeline of what occurred and whether any funds were transferred.
  5. If funds have already been sent, contact your bank immediately to attempt a recall, then report the incident to the Australian Cyber Security Centre at cyber.gov.au/report.

If money has been transferred, time is critical. Contact your bank the moment the scam is identified. The sooner a recall request is lodged, the greater the chance of recovering the funds.

Preventative measures for your organisation

Reduce your exposure to BEC scams with these ongoing practices:

Strong, unique passwords combined with multi-factor authentication are the foundation of email security. Speak with the 220 team if you need help configuring MFA on your mail accounts.

What to do if your email account has been compromised

If you suspect an attacker has gained access to a mailbox:

  1. Change the account password immediately from a clean device.
  2. Review and revoke any active sessions or connected apps in your email settings.
  3. Enable or re-confirm multi-factor authentication.
  4. Check mailbox rules for auto-forwarding or filters you did not create.
  5. Notify contacts who may have received fraudulent messages from the account.
  6. Open a ticket with 220 so our team can review account logs and assist with remediation.

Reporting suspicious emails quickly helps protect your business and the wider 220 customer community. If you are ever unsure whether a payment request is genuine, pause and verify through an independent channel before acting.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket