The two-minute check before you pay, and what to do if the money has already gone.
Resources / The invoice arrived with new bank details. Is it a scam?
Treat it as a scam until you have confirmed it on a phone number you already had. A supplier changing bank details by email is exactly what payment redirection looks like, and it cost Australians $166.8 million in 2025.1 The email can come from your supplier's real address, in the real thread, with the right invoice attached. So the test is not whether it looks right. It is whether you heard it from them another way.
Lost to payment redirection scams in 2025
On a number you already had, before you pay
If the money has gone, call them before anyone else
Because most of it is real. In the common version, a criminal gets into your supplier's mailbox, usually with a password taken in a phishing email, and quietly reads it for weeks. They learn who pays what, when, and how the invoices are worded. Then, at the right moment, they reply in the genuine email thread with a genuine invoice and one small change: the bank account.
The other version uses a lookalike address, one letter off from the real one, or the same name at a different domain. Either way the timing is right, the amount is right, and the tone is right. There is usually a reason attached, such as a bank change, an audit, or an account being updated, and often some urgency.
That is why this is not about being careless. The people it catches are busy, doing their job, and paying a supplier they trust. The fix is a habit that does not rely on spotting anything.
Call the supplier on a number you already had: from an earlier invoice, your phone contacts, or their website typed in yourself. Never use a number, link or contact in the email that asked for the change, because if the email is fake, so is everything in it. Ask the person you normally deal with to confirm the new BSB and account number. If they sound surprised, stop there.
Then look closely at the email itself. Read the sender's address character by character, and check whether replying would go to a different address than the one it came from. A real address does not clear it, though. If their mailbox has been broken into, the address will be perfect.
Finally, watch your banking app when you enter the details. Since July 2025 Australian banks have been rolling out Confirmation of Payee, which checks the account name you type against the account and tells you whether it matches.3 A no-match on a supplier's new account is a reason to stop and call. A match is reassuring, but it is not proof, so make the call anyway.
Write one rule down and make sure everyone who pays bills knows it: bank details never change because of an email. Every change is confirmed by phone on a number you already had, and someone notes who they spoke to and when. It takes two minutes, and it is the step that catches most of these scams.
For bigger payments, add a second person. One person sets up or changes the payee, another approves the payment. It feels like red tape until the day it catches something. Some businesses also send a small amount first to new details and confirm by phone that it arrived before sending the rest.
Then close the loop in the other direction. Put a line on your own invoices saying you will never change your bank details by email, and that customers should call you if they get a message saying otherwise. It protects your customers and it protects your cash flow.
The same scam runs the other way. If a criminal is in your mailbox, it is your customers who receive the fake invoices, and you find out when someone says they paid and the money never arrived. Other signs are emails in Sent that you did not write, and replies that seem to go missing.
Change the password, turn on multi-factor sign-in, and check your mailbox for forwarding rules or filters you did not create. Criminals often set a rule that moves replies about payments out of sight, which is how they stay unnoticed. Then warn your customers directly, by phone where you can.
It is also worth making your domain harder to fake. Once DMARC is set to quarantine or reject, SPF, DKIM and DMARC records let receiving systems refuse email that fakes your exact address. They will not stop a lookalike address or a broken-into mailbox, but they close one door. Our free Email Security Checker shows whether yours are set.
Call your bank straight away, on the number on your card or the bank's own website. Tell them it is a scam payment and ask them to try to recall it from the receiving bank. Speed matters more than anything else here, because the money is usually moved on quickly, so do this before you do anything else, including telling the supplier.
Then report it through ReportCyber at cyber.gov.au.4 Let the real supplier know what happened, since their mailbox may be the source and other customers may be targeted too. If there is any chance it started in your own email, change the passwords and check the forwarding rules as above.
Whether you still owe the supplier depends on the circumstances, so talk to them early, and get advice if the amount matters. Keep every email, invoice and bank record, because the bank, the police and your insurer will all ask for them.
Common enough that it is worth the two-minute rule. In 2024-25, business email compromise fraud that caused a financial loss made up 15% of the cybercrime reports businesses made to the Australian Signals Directorate.2 The average self-reported cost of cybercrime for a small business was $56,600 per report, across all types of cybercrime.2
For most small businesses a loss that size is not an IT problem, it is a cash flow problem. The good news is that this is one of the few cyber risks where a free, low-tech habit does most of the work. One phone call, on a number you already had, every time.
CEO just emailed you asking for gift cards: here's why it's a scam: The same trick with a different disguise: urgency, authority and a payment that cannot be undone.
You clicked a phishing link. What should you do in the first hour?: How most mailboxes get broken into in the first place, and the first-hour checklist.
Free Email Security Checker: See whether your SPF, DKIM and DMARC are set, in about ten seconds.
Not until you have called them on a phone number you already had, not one from the email, and they have confirmed the new BSB and account number. Changed bank details by email is the signature of payment redirection scams, which cost Australians $166.8 million in 2025.
Yes. If the supplier's mailbox has been broken into, the scam email comes from their genuine address, often in a real email thread with a real invoice. That is why checking the address is not enough and the phone call matters.
It helps. Since July 2025 Australian banks have been rolling it out to check whether the account name you enter matches the account. A no-match warning on new details is a reason to stop, but a match is not proof the request is genuine, so still confirm by phone.
Call your bank immediately on a number from its website or your card and ask it to try to recall the payment. Then report it through ReportCyber at cyber.gov.au, tell the real supplier, and keep every email and record. Speed matters most in the first few hours.
Protect your mailbox with multi-factor sign-in and check it for forwarding rules you did not set. Tell customers on every invoice that you will never change bank details by email, and set up SPF, DKIM and DMARC so your exact address is harder to fake.
We check how your mailboxes are secured, turn on multi-factor sign-in, look for forwarding rules nobody meant to set, and set up SPF, DKIM and DMARC so your domain is harder to fake. Free 30-minute call, no obligation.
Prefer to talk? Call (02) 9053 8789.