A supplier’s bank details change. The email looks legitimate, arrives in the usual thread and carries the right logo and signature. Your accounts team updates the details, pays the invoice and only learns days later that the supplier never received a cent. If you have asked, “what is business email compromise?”, this is the risk in practical terms.
Business email compromise, often called BEC, is a targeted scam where criminals use email to impersonate a trusted person or organisation. Their aim is usually to redirect a payment, steal sensitive information or gain access to a business system. It is not simply a badly written phishing email. The most convincing attacks rely on research, timing and a believable request that appears to come from someone your team already trusts.
For great Aussie businesses, the financial loss can be significant, but the disruption often goes further. A fraudulent payment can strain supplier relationships, create difficult customer conversations and take valuable time away from running the business.
What is business email compromise and how does it work?
A BEC attack usually begins before the suspicious email reaches your inbox. A scammer may study your website, LinkedIn profiles, public tender information and social media to understand who approves payments, which suppliers you use and how your business communicates.
In some cases, they compromise a real mailbox by stealing a password through phishing or by exploiting weak sign-in controls. They then read emails quietly, sometimes for weeks, watching for an invoice, property settlement, payroll run or purchase order they can intercept. Because they are using a genuine account and an existing conversation, the fraudulent request can be extremely difficult to spot.
Other attacks use a lookalike email address. For example, one letter in a supplier’s domain may be changed, or the sender name may be copied exactly while the actual address is different. The message may ask your team to update bank details, pay an urgent invoice, purchase gift cards or send employee records.
The pressure is deliberate. Criminals often send requests late on a Friday, when a director is travelling, or just before a payment deadline. They may ask for confidentiality to stop staff from checking the request with another person. A sense of urgency is one of their most effective tools.
The BEC scams small businesses see most often
Invoice redirection is the most common example. A criminal impersonates a supplier and sends new banking details, hoping the next payment goes to their account. Construction, manufacturing, logistics and professional services businesses can be exposed because they manage frequent invoices, subcontractors and changing project costs.
Executive impersonation is another common tactic. A message that appears to come from an owner, director or senior manager instructs an employee to make an urgent transfer. The request may be short and informal, which can make it feel more authentic if it matches the executive’s usual style.
Payroll and HR fraud targets employee data or wages. An attacker may pose as a staff member asking to change their pay account, or as a manager requesting tax file numbers, bank details or identification documents. These attacks can lead to both direct financial loss and a privacy incident.
Microsoft 365 accounts are a frequent target because email, files, contacts and calendars all sit in one place. Once an attacker accesses an account, they can set up hidden forwarding rules, impersonate the user internally and use genuine emails to target customers or suppliers.
Why business email compromise is harder to stop than ordinary spam
Traditional spam filtering still matters, but BEC does not always contain an obvious malicious link or attachment. It may be a plain-text email from a valid account saying, “Please process this today.” That means technology alone cannot carry the full load.
The risk also depends on your business processes. A company that accepts changed bank details by email without an independent check is exposed, even with good email filtering. Equally, a team that is trained to question unusual requests but has no multi-factor authentication can still have a mailbox taken over.
The strongest protection combines people, process and technology. Each layer catches something the others may miss.
Warning signs your team should not ignore
No single sign proves an email is fraudulent. The right response is to slow down when a request is unusual and verify it through a known, independent channel. Be particularly cautious when you see four or more of these signs:
- A request to change supplier or employee bank details, especially before an invoice is due.
- An urgent payment request that bypasses the usual approval process.
- A sender address with a small spelling change, unfamiliar domain or unexpected reply-to address.
- Wording that asks for secrecy, discourages a phone call or creates unnecessary pressure.
- An email that arrives from a trusted contact but has a tone, timing or request that does not feel right.
- New payment instructions in a reply thread where the previous conversation has been copied or altered.
Staff should not use the phone number included in the suspicious email to verify payment details. Instead, call a known contact using a number already held in your accounting system, contract records or official website. This one habit can prevent a costly mistake.
Practical controls that reduce BEC risk
Start with a clear payment verification process. Any change to bank details should require a call-back to a known contact, plus a second person to approve the change. For higher-value payments, consider a separate confirmation step before funds leave the account. It adds a small amount of administration, but that is a sensible trade-off against an irreversible transfer.
Multi-factor authentication should be enabled across email, Microsoft 365, finance platforms and remote access tools. A password alone is too easily stolen, guessed or reused. App-based authentication is generally preferable to SMS where available, although the best option depends on your systems and staff access needs.
Keep email security settings properly configured. This includes anti-phishing protection, external sender warnings, mailbox auditing and controls that flag suspicious forwarding rules. Domain protections can also reduce the chance of criminals impersonating your own business when they target your customers and suppliers.
Train staff using realistic scenarios, not annual box-ticking exercises. Accounts teams, payroll staff, office managers and directors need specific guidance because they receive different types of requests. Short, regular training and simulated phishing tests help people build the habit of checking before acting.
Finally, limit who can change payment details and who can approve transfers. Clear separation of duties is useful even in a smaller business. If one person must manage several steps, introduce an independent check from a director or another authorised team member for exceptions and large payments.
What to do if you think a payment or mailbox has been compromised
Act quickly, but do not delete evidence. If money has been transferred, contact your bank immediately and ask it to start its fraud response process. Time matters, as funds may be moved through multiple accounts quickly.
Next, contact the supplier or customer using a trusted phone number to confirm what happened. If an email account may have been accessed, reset passwords, revoke active sessions, review mailbox rules and check for unauthorised changes to multi-factor authentication. Your IT provider should also investigate how access was gained and whether other accounts, files or contacts were affected.
Report the incident to the relevant authorities and document the timeline, emails, bank details and affected systems. If personal information has been exposed, your business may also have privacy obligations. The correct response depends on the information involved and the scale of the incident, so seek appropriate advice early.
Make verification part of everyday business
BEC works when a reasonable person is rushed into trusting an email that looks familiar. The answer is not asking staff to be suspicious of everyone. It is building simple checks into the moments that matter most: changing bank details, releasing payments, sharing sensitive information and approving unusual requests.
For businesses across Sydney, Newcastle and the Central Coast, a proactive IT partner can help turn those checks into practical security controls around Microsoft 365, email and payment workflows. A quick phone call before a bank detail change may feel like a minor delay. It can also be the decision that protects months of hard-earned revenue.