Business email compromise (BEC) is, dollar for dollar, one of the most damaging cyber threats facing Australian SMEs — and it barely involves hacking in the technical sense. It works by manipulating people into moving money or changing payment details, using email that looks entirely legitimate. There's no malware to detect and no alarm to trip. Understanding how it works is most of the defence.
How the scam actually plays out
BEC comes in a few recurring shapes. In the classic invoice fraud, an attacker who has been quietly watching an email account intercepts or imitates a genuine supplier invoice and changes the bank account details to their own, so your legitimate payment lands in the criminal's account. In CEO or executive fraud, someone poses as the owner or a senior manager and emails the finance team with an urgent request to pay a bill or transfer funds "before end of day, and keep it confidential." In account takeover, the attacker has real access to a genuine mailbox — often a supplier's — and sends the fraudulent request from the actual address, which is why it's so convincing. The common thread is a plausible request to send money or change payment details, wrapped in urgency and authority.
Why SMEs are squarely in the crosshairs
Small and medium businesses are attractive targets for practical reasons. They handle meaningful payments but often lack the layered controls of a large finance department. Approval processes are informal — a single person can frequently authorise a transfer. Staff are busy and inclined to be helpful, especially when the boss appears to be asking. And the request usually arrives from a real, trusted contact or a near-perfect imitation of one. None of the usual technical defences help, because nothing is technically "broken": a person is being persuaded to do something they're authorised to do.
The single most effective control
If you take one thing from this: verify any request to change bank details or make an unusual payment through a separate, trusted channel before you act. If a supplier emails new account details, phone them on a number you already hold — not the number in the email — and confirm. If "the CEO" emails an urgent transfer request, speak to them directly. This out-of-band verification is the control that defeats BEC, because it breaks the attacker's reliance on the compromised or spoofed email being the only line of contact. Make it a firm rule, not a judgement call: every change of payment details gets verified by voice, no exceptions, no matter how senior or urgent the sender appears.
Build process controls that don't depend on vigilance
Human alertness is necessary but not sufficient — people get tired and rushed. Bake protection into the process:
- Dual authorisation for payments above a sensible threshold, so no single person can move significant money alone.
- A documented supplier bank-detail change procedure that mandates verification through known contact details before any change is made in your system.
- Scepticism of urgency and secrecy as a cultural norm — "urgent and confidential, don't check with anyone" is a hallmark of the scam, not of legitimate business.
- A clear, blame-free escalation path so a junior staff member feels safe pausing a suspicious request from a senior person.
The goal is a system where doing the safe thing is the default, not something that depends on the right person being switched on at the right moment.
Harden the technical basics too
Process controls sit on top of sound email hygiene. Turn on multi-factor authentication across all business email accounts — this alone stops most account-takeover attempts. Configure your email authentication records (SPF, DKIM and DMARC) so spoofed messages are more likely to be caught, and be alert to lookalike domains where one character has been swapped. These measures map directly to the practical, prioritised controls in the ASD's Essential Eight, which is a sound baseline for any Australian SME's operations and IT posture.
If it happens to you
Speed matters enormously once a fraudulent payment has gone out. Contact your bank immediately and ask them to attempt a recall — funds are sometimes recoverable if you move within hours. Report the incident to ReportCyber and to Scamwatch, change the credentials on any affected accounts, and review your mailbox for forwarding rules an attacker may have set up to hide their tracks. Then treat it as a lesson: tighten the verification process that would have caught it.
This is general information, not security or financial advice. Consult the Australian Signals Directorate's Australian Cyber Security Centre and a qualified IT security professional for guidance tailored to your business.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →