How to recognise and avoid business email compromise (BEC) scams targeting invoices and payments
Summary
This guide helps you troubleshoot and resolve: How to recognise and avoid business email compromise (BEC) scams targeting invoices and payments. Follow the steps below to fix the issue.
Common Causes
Business Email Compromise (BEC) scams are among the most financially damaging cyber crimes affecting Australian small businesses. Attackers impersonate trusted contacts such as CEOs, suppliers, or finance teams to redirect invoice payments or trick staff into transferring funds. This guide explains how to recognise the warning signs and the verification steps your team should follow before any payment is made.
What is a BEC scam?
BEC scams involve an attacker gaining access to, or spoofing, a legitimate business email account. They then send convincing messages designed to alter normal payment processes. Common variants include:
- Invoice redirection: A supplier's email is compromised and you receive an "updated" bank account details notice.
- CEO impersonation: An email appears to come from your manager or director requesting an urgent, confidential transfer.
- Payroll change requests: A staff member's email is used to request a change to their direct deposit account.
- Supplier impersonation: A new vendor or contractor provides bank details that route funds to the attacker.
Warning signs to watch for
Train your team to pause and verify when any of the following appear:
- Urgency or pressure to act quickly, often outside business hours.
- Requests to keep the transaction confidential or bypass normal approval processes.
- Last-minute changes to bank account details, payment addresses, or contact information.
- Email addresses that are almost correct, such as a single character changed or a different domain extension (for example,
.cominstead of.com.au). - Display names that match a real person but the underlying email address does not.
- Poor spelling, unusual phrasing, or a tone that does not match the sender's normal style.
- Links that, when hovered, point to unfamiliar domains.
Always inspect the full email address, not just the display name. On most email clients you can hover over or click the sender's name to reveal the actual address.
Verification steps before any payment change
Implement a two-person verification policy for any change to payment details. The following process should become standard practice across your organisation.
Step-by-step verification procedure
- Do not reply to the email or use any phone numbers or links contained within it.
- Open a new email or message thread and contact the sender using a known, previously verified address or phone number from your own records.
- Confirm verbally that the request is genuine and document the call, including who you spoke with and when.
- Cross-check the new bank details against those held in your finance system. A change in BSB or account number is a major red flag.
- Obtain secondary sign-off from a second authorised person before processing the payment.
- Wait at least 24 hours for any "urgent" request involving new payment details. Genuine suppliers will understand the delay.
Even if the email appears to come from your CEO or a long-standing supplier, the same verification rules apply. Attackers deliberately target these relationships because employees are less likely to question them.
Technical red flags in the email itself
Beyond the message content, the technical details of an email can reveal a scam:
- Reply-to mismatch: The reply-to address differs from the sender's address.
- Domain lookalikes: Slight variations such as extra characters, swapped letters, or alternative country code top-level domains (for example,
.cominstead of.com.au). - Unexpected authentication results: Missing or failed SPF, DKIM, or DMARC checks. Your IT team or email provider can confirm these in the message headers.
- Unusual sending patterns: Emails sent at odd hours, or from devices or locations inconsistent with the sender's normal behaviour.
How to report a suspected BEC email to 220 Internet Services
If you receive a suspicious email targeting your business, report it as quickly as possible. Early reporting can prevent further attempts and protect other customers.
Reporting steps
- Do not delete or forward the email from your normal inbox.
- In Microsoft Outlook, open the message and select Home > Report Message > Phishing. In Google Workspace, use the Report phishing option from the message menu.
- If you have already clicked a link or replied, change any exposed passwords immediately and notify your account holder.
- Open a support ticket through the 220 customer portal and attach the original email as an
.emlor.msgfile. Include a brief timeline of what occurred and whether any funds were transferred. - If funds have already been sent, contact your bank immediately to attempt a recall, then report the incident to the Australian Cyber Security Centre at
cyber.gov.au/report.
If money has been transferred, time is critical. Contact your bank the moment the scam is identified. The sooner a recall request is lodged, the greater the chance of recovering the funds.
Preventative measures for your organisation
Reduce your exposure to BEC scams with these ongoing practices:
- Enable multi-factor authentication on all email accounts, particularly those used by finance and executive staff.
- Use email authentication protocols (SPF, DKIM, DMARC) on your domain. 220 can assist with configuration.
- Establish clear internal procedures for verifying any change to supplier or payroll bank details.
- Conduct regular phishing awareness training and simulated BEC exercises for staff who handle payments.
- Restrict who can approve wire transfers and require dual authorisation above a defined dollar threshold.
- Keep regular, offline backups of critical financial records and contact lists.
Strong, unique passwords combined with multi-factor authentication are the foundation of email security. Speak with the 220 team if you need help configuring MFA on your mail accounts.
What to do if your email account has been compromised
If you suspect an attacker has gained access to a mailbox:
- Change the account password immediately from a clean device.
- Review and revoke any active sessions or connected apps in your email settings.
- Enable or re-confirm multi-factor authentication.
- Check mailbox rules for auto-forwarding or filters you did not create.
- Notify contacts who may have received fraudulent messages from the account.
- Open a ticket with 220 so our team can review account logs and assist with remediation.
Reporting suspicious emails quickly helps protect your business and the wider 220 customer community. If you are ever unsure whether a payment request is genuine, pause and verify through an independent channel before acting.
Still Having Issues?
💻 Open a Ticket