RESOURCES · SECURITY & EMAIL

Business email compromise,
explained

Business Email Compromise (BEC) is one of the most expensive scams hitting Australian businesses — and it rarely involves any obvious "hacking". It's a con that quietly reroutes a genuine payment into a criminal's account, usually by slipping into an email conversation about money. Here's how it works, and how to shut it down.

Applies to: Anyone who pays invoices Read: ~5 min Level: Non-technical
Quick answer

In a BEC scam, an attacker either impersonates a supplier or colleague, or quietly gets inside a real mailbox, then sends a believable message changing the bank details on an invoice. The money lands in the criminal's account. The fix is process, not just technology: always verify any bank-detail change or payment by phone, to a number you already know.

THE TWO FLAVOURS

Two ways it plays out.

Almost every BEC scam falls into one of two buckets — and one is far harder to catch:

THE CLASSIC PLAY

How the money goes missing.

The attacker watches a real invoice conversation and waits for exactly the right moment — a genuine bill is due, everyone is expecting a payment. Then they send the line that does the damage: "our bank details have changed — please use these for this invoice."

It looks routine, so the payment gets made — straight into the criminal's account. Worse still, it's often not spotted for weeks, until the real supplier chases the unpaid bill and everyone realises the money went somewhere else entirely.

WARNING SIGNS

Red flags to train your team on.

None of these are proof on their own — but any of them should stop a payment until it's verified:

HOW TO PREVENT IT

Make the scam fail.

The good news: a few simple habits make BEC very hard to pull off.

  1. Verify every payment or bank-detail change by phoneMake it a firm, no-exceptions rule — confirm on a number you already know, never the number written in the email. This one habit stops the vast majority of BEC scams cold.
  2. Require dual approval for larger paymentsFor any payment above a set amount, insist a second person signs off. Two sets of eyes catch what a single, busy person might miss.
  3. Train staff to expect and question these requestsWhen your team knows exactly what a "new bank details" scam looks like, they stop being an easy target — and start being your best defence.
  4. Add the technical layersEmail authentication, impersonation protection, MFA and monitoring all help — catching look-alike domains and spotting a mailbox takeover early, before it turns into a redirected payment.
Why "it looked completely legitimate" is the whole point. The account-takeover version is so convincing because it comes from a real address, inside a real thread — which is exactly why victims describe it as looking completely legitimate. You can't spot it by reading the email harder. Verifying by phone, to a number you already know, is what saves you.
STOP THE PAYMENT REDIRECT

Could a fake "new bank details" email fool your team?

BEC is designed to look ordinary — which is why so many good businesses get caught. Our free IT Health Check reviews your email protection, mailbox monitoring and payment-verification habits, and shows you the simple layers that make this scam fail before a cent leaves your account.

KEEP READING

Related resources