No. Never change a supplier’s bank details on the strength of an email alone, however genuine it looks. Call the supplier on a number you already have on file and ask them to confirm the change. This one habit stops the costliest scam reported by Australian businesses, known as business email compromise or payment redirection fraud.
What this scam is
A criminal gets inside an email account, either at your supplier or in your own business, and waits. They read the mail for weeks and learn who pays the invoices. Then, just before a real invoice is due, they send a polite note saying the supplier has changed banks. Your staff pay the real invoice into the criminal’s account, and by the time the supplier chases it the money is long gone.
Why the email looks real
Because it is real. It came from the real mailbox, or from one set up to look identical. There is no spelling mistake to catch, no strange link, no unknown sender. It arrives in the middle of a genuine conversation thread, often with the actual invoice attached and only the bank details edited. Scamwatch and the ACSC report that this fraud costs Australian businesses more than any other scam.
The rule that protects you
Any change to bank details is confirmed by phone, using a number from your own records, not a number in the email. The email may give you a helpful number to call. Ignore it, because it may ring through to the scammer. Use the number on a previous invoice or on the supplier’s website. Speak to a person you know, and read the new BSB and account number back to them.
Put it in writing
Make it a two person check. Write a short procedure that says bank detail changes need a phone confirmation by one person and a sign off by a second, with both names recorded. A genuine supplier will not mind a call, and a scammer cannot survive one. Warn your own customers too that you will never change your bank details by email alone.
Signs in the email
The warning signs are usually in the circumstances rather than the wording.
- A change of bank details, especially close to a payment date.
- A sense of urgency, or a request to keep the change quiet until the payment clears.
- A reply address that differs slightly from the sender, often by one letter.
- A new contact person you have not dealt with before.
- A new bank that does not match the supplier’s home state or country.
If the money has already gone
Call your bank the moment you realise, even if it is after hours. Banks can sometimes recall a transfer within the first day. Then report the incident to the ACSC through its online cyber reporting portal, and to Scamwatch. Tell the supplier, because other customers may be next. If your own mailbox was the way in, change every password, turn on two factor sign in, and have someone check for forwarding rules the criminal left behind.
What to do next
Write the two person rule down this week and brief everyone who pays invoices. If you want the mailboxes hardened so the criminal never gets in, that is the core of our cyber security service, and our guide to the signs your business has been hacked covers what a compromised mailbox looks like.
The supplier confirmed the change by replying to my email. Is that enough?
No. If their mailbox is compromised, the criminal is the one replying. Only a call to a number from your own records counts.
Will the bank refund the money if we were tricked?
Sometimes, if you call quickly enough for the transfer to be recalled. Once the funds move on, recovery is rare.
How do I know whether it was their mailbox or ours that was hacked?
If the sender address was exactly right, the supplier is likely compromised. Either way, have your own mailboxes checked for unusual sign ins.
If this is happening in your business and you would like it sorted, call DM1 on (08) 6202 6012 or send us a message. We look after IT, Microsoft 365, websites and domain names for Perth small businesses.
