Invoice fraud
A supplier invoice or genuine email thread is altered so an ordinary accounts-payable transfer goes to a different account. The amount and service may be completely real; only the destination changes.
Payment redirection fraud changes where legitimate money goes. The invoice, settlement, salary or deposit may be expected and correct. The criminal replaces only the destination—and relies on nobody checking it independently.
A payment redirection scam persuades a payer to send genuine funds to an account controlled by a criminal. It often arrives as a changed-bank-details notice inside a real business process. The attacker does not need to invent a purchase if they can intercept one.
Business email compromise is a common delivery method, but not the only one. False invoices, cloned websites, text messages, calls and compromised portals can carry the instruction. A phone call may appear to verify an email while actually giving the attacker control of both channels.
The target is not necessarily careless. These scams exploit ordinary work: suppliers update records, employees change banks, settlements have deadlines and deposits secure scarce opportunities. The effective control is a consistent check for the change, not a subjective judgement about whether the message looks fraudulent.
Protect the destination
Treat every new or changed payment destination as an identity event. Verify the authorised person through a trusted, separate channel before updating the record.
The fraud succeeds when accurate transaction context is mistaken for authority to change the destination.
The attacker learns who is paying whom, when money is due and which email thread or staff role can carry a believable change.
A compromised mailbox, lookalike address, false invoice, cloned website or impersonating call introduces attacker-controlled bank details.
Urgency, familiarity and transaction detail make the change feel routine. The attacker may provide a second false channel to confirm it.
The payer sends money to a mule or other controlled account. Funds may be split or moved quickly, reducing the chance of recovery.
The ACCC reported that Australians made 481,523 combined scam reports in 2025 and that 274,577 reports involved losses totalling $2.18 billion. The National Anti-Scam Centre's Targeting Scams 2025 report places payment redirection among the five highest-loss categories. These are combined national figures across reporting bodies, not a measure of any individual firm's likelihood of loss.
The same report warns that reporting data has limitations, including unreported losses and differences between data sets. A loss total should therefore provide context, not a marketing promise or prediction. For a firm, the practical exposure is visible in its own payment flows: the value, frequency and reversibility of transfers, and the strength of the process used to approve change.
Scamwatch's business email compromise guidance describes criminals intercepting or impersonating business communications to alter payment details. Its advice to contact the organisation using details found independently—not those in the suspect message—captures the central defence.
Anyone who can create, amend or approve payment records is valuable: accounts teams, payroll officers, property staff, conveyancers, lawyers, brokers, practice managers and business owners. Attackers also target clients directly when the firm's identity can make an instruction credible.
Professional services transactions combine trust with movement of money. Staff routinely receive instructions on behalf of others, and clients may be unfamiliar with the process. That makes a confident message from a known firm especially persuasive.
High-value transactions deserve strong controls, but repeated smaller transfers matter too. Payroll and invoice changes can persist across several payment cycles before discovery. A threshold-only policy can leave predictable fraud below the threshold unchecked.
A bank transfer may move through multiple accounts soon after receipt. Contacting the sending bank immediately gives its fraud team the best opportunity to attempt a recall or contact the receiving institution, but recovery is never guaranteed.
The payer should preserve the instruction, headers, invoices, call notes, approval records and transaction details; secure any compromised accounts; notify appropriate advisers and insurers; and report cybercrime through ReportCyber. Firms should follow their own incident and legal obligations.
The uncertainty after payment is why evidence before payment matters. A documented independent check can prevent loss and show which person, record and channel supported the decision.
A supplier invoice or genuine email thread is altered so an ordinary accounts-payable transfer goes to a different account. The amount and service may be completely real; only the destination changes.
A buyer, seller, conveyancer or legal practice receives replacement trust or settlement details near completion. High value, fixed deadlines and several participants create both pressure and plausible complexity.
An attacker impersonates an employee and asks payroll to send future salary to a new account. A compromised staff mailbox can make the request appear to pass the normal identity check.
A tenant, purchaser or client is sent false instructions for a bond, holding deposit, retainer or other upfront payment. A cloned listing, firm identity or message thread supplies credibility.
Each variant appears in different professional work, but the shared control is the same: a person claims authority to change a payment destination, and the firm must verify that person independently.
The attacker usually controls the incoming message and any contact details placed inside it. Verification breaks that control by returning to an identity record established before the request. The payer does not ask the suspicious email whether the email is genuine; it challenges the real person through a separate channel.
Vericode sends a code to the verified phone number held for that person. Completing the check demonstrates possession of the expected device. A compromised mailbox, cloned invoice or persuasive call does not provide that possession. The outcome can be recorded alongside the payment-change approval.
This control should complement—not replace—dual approval, account-name checks offered by financial institutions, transaction limits, separation of duties and bank alerts. Its role is to make identity verification consistent at the exact moment the destination changes.
The one habit that stops all four
“Out of band” means the check does not depend on the email, invoice, message, website or phone number that delivered the change. Use a trusted record and require the authorised person to prove possession before the destination is updated.
Make the rule universal. Familiar senders, small amounts and urgent deadlines are not exemptions; they are conditions attackers exploit. A repeatable control is easier for staff to apply and easier for clients to understand than an invitation to detect perfect forgeries.