Can’t find what you’re looking for? Call 1300 688 648 for expert IT assistance

Email warning about overdue payment request

Business Email Compromise (BEC) is a targeted fraud where criminals impersonate a trusted person, such as your CEO, a supplier, or a lawyer, to trick employees into transferring money or sensitive information. Unlike traditional phishing, BEC does not rely on malware or suspicious links. It relies on deception, authority, and urgency. For Australian businesses, BEC is one of the most financially damaging cyber threats in operation today.

This guide explains how BEC works, why it is so difficult to detect, and what your business can do to stop it before money leaves your account.

How BEC Differs from Phishing

Most people are familiar with phishing, the bulk emails pretending to be banks or delivery companies, loaded with dodgy links. BEC is a different category of threat entirely. There is no malware to catch, no suspicious attachment to block, and no generic message sent to thousands of inboxes.

BEC is targeted and personal. The attacker researches your business, identifies who handles payments, and crafts a believable email from someone the recipient trusts. The email looks legitimate because it is designed to look exactly that way. Your email security tools may see nothing wrong with it at all.

The Most Common BEC Scenarios in Australia

CEO Fraud

An employee in finance receives an urgent email that appears to come from the CEO or Managing Director. The message requests a confidential payment or wire transfer, often framed as time-sensitive and asking them not to follow the usual process. The attacker impersonates the CEO using a spoofed or lookalike email address.

Invoice Fraud

A supplier or vendor sends what looks like a routine invoice. Hidden in the email is a request to update bank account details for future payments. The business updates the details, pays the next invoice, and the money goes directly to the attacker. The real supplier has no idea and eventually chases the payment themselves.

Payroll Diversion

An attacker impersonates an employee and contacts the HR or payroll team. They request a change to their bank account details, claiming they have switched banks. The next pay cycle, the employee’s salary is transferred to a fraudulent account.

Lawyer or Conveyancer Impersonation

During property settlements or legal matters, attackers impersonate the law firm or conveyancer involved. They intercept communication at a critical moment and redirect settlement funds to their own accounts. These losses are often very large and rarely recoverable in full.

How a BEC Attack Works in Practice

Understanding the steps involved helps make clear why BEC is so effective.

  1. Reconnaissance: The attacker researches your business using LinkedIn, your website, ASIC records, and social media. They identify key people, understand your supply chain, and find out who approves payments.
  2. Email setup: The attacker either spoofs a legitimate email address (making it appear to come from a real domain) or registers a lookalike domain (for example, ottoit.com.au becomes ott0it.com.au). They may also compromise a real email account if credentials have been leaked.
  3. The approach: The attacker sends a targeted email at a strategic moment, often just before a weekend, during a period when the real executive is travelling, or during a busy financial period like end of quarter.
  4. The ask: The request is urgent, framed as confidential, and discourages the recipient from following normal verification steps. Time pressure is a deliberate tool.
  5. The transfer: If the target complies, the money moves. Attackers often use accounts that quickly forward funds offshore, making recovery extremely difficult.

Why BEC Is So Hard to Detect

BEC succeeds because it is designed to look normal. There is no virus, no suspicious link, and no attachment triggering your antivirus software. The email may arrive from what appears to be a known address. The language is professional and matches how the impersonated person typically communicates.

Traditional security tools are built to stop malware and phishing links. They are not built to detect a well-crafted impersonation email written entirely in plain text. This is why human awareness and verification processes matter as much as, if not more than, technical controls.

The Australian Picture: What the Data Shows

The Australian Signals Directorate (ASD), through its Annual Cyber Threat Report, consistently identifies BEC as one of the top causes of financial loss for Australian businesses. The Australian Federal Police and the Australian Competition and Consumer Commission (ACCC) have reported that BEC and related payment redirection scams cost Australian businesses hundreds of millions of dollars annually.

The ACCC’s Scamwatch data and the AFP’s Project Guardian have highlighted invoice fraud and payment redirection as primary threat vectors. Many incidents go unreported due to reputational concerns, meaning the true figure is likely higher than what is publicly known.

Small and medium-sized businesses are disproportionately affected. They often lack dedicated security teams and may rely on informal payment processes that are easier to exploit.

For broader context on how cyber threats affect Australian businesses, see our guide on what a cyber attack is and how it happens in Australia.

Warning Signs of a BEC Attempt

These are the red flags your team should know to look for.

  • An unexpected request to change bank account details for a supplier or employee
  • An urgent payment request that bypasses normal approval steps
  • A request marked as confidential that discourages you from discussing it with others
  • An email from a senior person that does not match their usual communication style
  • A sender address that looks almost right but is slightly different from what you know
  • Pressure to act quickly, especially before a deadline, weekend, or public holiday
  • A supplier advising their bank details have changed, arriving via email only
  • An email arriving at an unusual time of day or from an unexpected location

Technical Controls That Help

These tools do not stop all BEC, but they reduce the attack surface and make spoofing harder.

SPF (Sender Policy Framework)

SPF is a DNS record that specifies which mail servers are authorised to send email on behalf of your domain. If an attacker tries to spoof your domain, a properly configured SPF record tells the receiving mail server to be suspicious of that message. Think of it as a whitelist for who is allowed to send email using your domain name.

DKIM (DomainKeys Identified Mail)

DKIM adds a digital signature to outgoing emails. When your email arrives at its destination, the receiving server checks the signature against a public key published in your DNS records. If the signature does not match, the email is flagged. This confirms the message genuinely came from your server and was not tampered with in transit.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

DMARC builds on SPF and DKIM by giving domain owners control over what happens when an email fails those checks. You can instruct receiving mail servers to quarantine or reject messages that fail authentication. DMARC also provides reporting so you can see who is sending email using your domain, including unauthorised senders.

Together, SPF, DKIM, and DMARC make it significantly harder for attackers to impersonate your domain. However, they do not stop attackers using lookalike domains, which is why human verification remains essential.

Our managed cybersecurity services include email security configuration, domain monitoring, and ongoing protection to help close these gaps.

Human Controls: Your Most Important Defence

Technical tools can only go so far. The most effective defence against BEC is a team that knows what to do when a suspicious request lands in their inbox.

Verify before you transfer

Any request to transfer money or change bank details should trigger a verification call. Use a phone number you already have on file, not the number provided in the email itself. Call the supplier, the executive, or the employee directly and confirm the request verbally before taking any action.

Enforce a dual-approval rule for payments

No single employee should be able to authorise a significant payment alone. Require two people to approve transfers above a defined threshold. This simple control removes the single point of failure that BEC exploits.

Establish a bank change process

Any request to update bank account details, whether for a supplier or an employee, should follow a documented process. That process should include verbal verification, written confirmation from a known contact, and sign-off from a manager before the change takes effect.

Train your team regularly

Awareness training should be specific and practical. Employees need to see examples of real BEC emails, understand the pressure tactics attackers use, and feel comfortable slowing down or pushing back on an unusual request, even if it appears to come from a senior person.

How Microsoft Copilot Can Help Your Team

Microsoft 365 Copilot can assist with BEC preparedness in practical ways. Your team can use Copilot to draft internal verification procedures that are clear, specific, and easy to follow. Copilot can also help your operations or IT team generate training materials, including realistic example scenarios that illustrate how a BEC email might look.

For businesses running security awareness programmes, Copilot can speed up the production of training content, policy documents, and response checklists, reducing the time it takes to get practical guidance in front of the people who need it.

What to Do If You Have Already Sent Money

Speed is everything. If you realise a payment has gone to a fraudulent account, take these steps immediately.

  1. Contact your bank straight away. Call your bank’s fraud line the moment you suspect something is wrong. Banks have processes to attempt payment recalls, but these must be initiated quickly before the funds are moved further or withdrawn.
  2. Report to the Australian Federal Police. BEC is a federal crime. Report to the AFP or through the ReportCyber portal at cyber.gov.au. Reporting also helps law enforcement track patterns and warn other businesses.
  3. Report to Scamwatch. The ACCC’s Scamwatch (scamwatch.gov.au) tracks payment fraud and can provide guidance on next steps.
  4. Notify your IT provider or cybersecurity team. If the attacker accessed an internal email account, you need to know the extent of the compromise. Change passwords, check for mail forwarding rules, and review account activity.
  5. Document everything. Keep all emails, records of the transaction, and a timeline of events. This is important for the investigation and for any insurance claim.

Do not assume recovery is impossible. Some businesses do recover funds through prompt action. Every minute counts.

Frequently Asked Questions

Is BEC the same as phishing?

No. Phishing typically involves bulk emails with malicious links or attachments. BEC is a targeted attack that uses impersonation to manipulate a specific person into taking a specific action, usually a financial transfer. BEC emails often contain no malware at all.

Can my email security filter stop BEC?

Standard spam and phishing filters are not designed to catch well-crafted BEC emails. Technical controls like SPF, DKIM, and DMARC reduce the risk of domain spoofing, but attackers using lookalike domains or compromised accounts can bypass these. Human verification processes are essential.

How do attackers know who handles payments in my business?

LinkedIn, your company website, and public records often contain enough information for attackers to identify finance managers, accounts payable staff, and executives. Attackers invest time in research before approaching a target.

What is the most common type of BEC in Australia?

Invoice fraud and payment redirection are consistently among the most reported BEC types in Australia, according to the ASD and the ACCC. These involve intercepting or impersonating supplier communications to redirect legitimate payments.

Should I report a BEC attempt even if no money was lost?

Yes. Reporting attempted BEC through ReportCyber helps law enforcement identify patterns and active campaigns. It also creates a record that can be useful if the attacker targets your business again or targets others in your industry.

Does cyber insurance cover BEC losses?

Some cyber insurance policies cover BEC losses, but coverage varies significantly. Review your policy carefully and discuss BEC specifically with your insurer. Some policies require specific controls to be in place for claims to be valid.


BEC is not a future threat. It is happening to Australian businesses right now, and many do not discover the fraud until the money is already gone. The good news is that simple, practical controls, a verification call before a payment, a dual-approval rule, and a team that knows what to look for, can make your business a much harder target.

If you want to review your email security configuration or strengthen your team’s defences against BEC, book a call with our team. We work with Australian businesses every day to close the gaps that attackers exploit.

managed it support articles

Related Blog Articles

Discover more insights to optimise your business with the latest IT trends and best practices. Stay ahead of the curve by learning how to leverage cutting-edge technology for success. Explore expert advice and valuable guidance to navigate the evolving world of IT solutions

Learn More