Quick answer
A payment redirection scam — a form of business email compromise — is when a criminal poses as a supplier, customer or colleague and sends an invoice or email with changed bank details so money is paid to them instead. Always verify any change of bank details by phoning a number you already hold, not one in the email. If you've paid a scammer, call your bank immediately, then report to the Australian Cyber Security Hotline on 1300 292 371.
Key points
- Never accept a bank-detail change by email alone — call a known number.
- Scammers target busy, disrupted moments, including recovery after a disaster.
- If money has gone, your bank's fraud team is the first call.
- Multi-factor authentication on email stops many account takeovers.
Of all the crises on this site, this one is the most preventable. A supplier’s “new bank details” email arrives, someone pays the next invoice to the new account, and weeks later the real supplier asks why they haven’t been paid. The money went to a criminal.
These scams are often called business email compromise or payment redirection. They don’t need sophisticated hacking — just a convincing email at a busy moment. This guide explains how they work, why they spike during disruptions, and the simple habits that stop them.
How does a payment redirection scam work?
Scamwatch describes business email compromise scams as scammers pretending to be from a business you’ve used and sending you an invoice with new payee information so you pay them instead.
The common versions:
| Version | What happens |
|---|---|
| Fake supplier email | An email that looks like it’s from a regular supplier says their bank details have changed |
| Hacked supplier account | The real supplier’s email has been compromised, so the message comes from their genuine address |
| Hacked internal account | Your own email is compromised and used to send customers “updated” payment details |
| Fake executive request | An email appearing to come from the owner or director asks the bookkeeper to make an urgent payment |
| Intercepted invoice | A genuine invoice is altered before it reaches you |
The giveaway is almost always the same: a change to where money should be sent, communicated in writing only.
Why do these scams spike during a crisis?
A disruption is the perfect cover:
- staff are working from home or temporary premises
- suppliers genuinely are changing, after a supplier failure or a disaster
- normal checks get skipped because everyone’s rushed
- people expect odd emails and delays
- the owner is distracted by bigger problems
Scamwatch also warns that after natural disasters and major events, scammers impersonate genuine charities to collect donations. The same instinct to help or to hurry makes businesses vulnerable.
What are the warning signs?
- A request to change bank details, especially by email
- Urgency: “please pay today to avoid late fees”
- A slightly different email address (an extra letter, a different domain ending)
- Unusual tone, spelling or formatting from someone you know
- A request to keep the change quiet, or not to call
- A PDF invoice that looks right but has different bank details from last time
- Replies going to a different address from the one the email came from
How do you stop it happening?
The one rule that stops most scams
Never change a payee’s bank details based on an email or letter alone. Phone the supplier on a number you already have — from a previous invoice, your accounting records or their official website — and confirm the change with someone you know. Not the number in the email.
Write this rule down, share it with everyone who pays invoices, and put it in your business continuity plan.
Other protections
- Turn on multi-factor authentication for email, banking and accounting software.
- Use two-person approval for new payees and bank-detail changes in your banking platform.
- Tell your customers that your bank details won’t change by email, and that they should call you before paying new details.
- Check for mail-forwarding rules in your email — attackers often set these up to hide replies.
- Train staff once a year with real examples.
- Keep software updated and use a reputable security product.
What should you do if you’ve been scammed?
Speed matters more than anything else.
- Call your bank’s fraud team immediately. Ask them to try to stop or recall the payment. Every hour counts.
- Call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371) for advice and reporting.
- Contact IDCARE’s small business line on 1800 595 170 for free, expert support.
- Report to Scamwatch so others can be warned.
- Secure your email — change passwords from a clean device, turn on multi-factor authentication, and check for forwarding rules.
- Tell the real supplier or customer what’s happened, by phone.
- Keep evidence — the emails with full headers, invoices, payment records and report numbers.
Our cyber attack page covers the broader response if your systems were compromised.
What happens to the money you still owe?
This is the hard part. If you paid a scammer instead of your supplier, you usually still owe the supplier. If a customer paid a scammer instead of you, you may have a difficult conversation about who bears the loss. Either way, the business can suddenly be short.
| Situation | Cash impact |
|---|---|
| You paid a fake supplier account | You still owe the real supplier |
| Your customer paid a fake account | Your invoice remains unpaid while it’s sorted out |
| Payroll was redirected | Staff still need to be paid |
| Partial recovery by the bank | The gap shrinks but often doesn’t close |
If the loss leaves a hole in your cash flow, a short enquiry gets a real person looking at options — there’s no credit check at enquiry stage. Unsecured funding sized on your bank statements can bridge a loss like this while recovery efforts continue; see unsecured emergency cash.
Illustrative example only: a small freight business receives an email that appears to come from its fuel supplier with new bank details, and pays a month’s fuel account to the new account. The real supplier calls two weeks later. The bank recovers part of the payment. The owner uses a short unsecured facility to pay the supplier and keep the account open, and brings in a call-back rule for all bank-detail changes.
How do you talk to customers about it?
If your email was used to scam customers, tell them quickly and plainly:
- what happened and when
- that your bank details haven’t changed
- that they should phone you before paying any new details
- who to contact with questions
Customers generally respond well to honesty. Silence is what damages trust.
What should your payment process look like?
A written process removes the pressure from individual staff members, who can simply say “that’s our policy”. A simple version:
| Step | Rule |
|---|---|
| New supplier | Bank details collected on letterhead and confirmed by phone to a known number |
| Change of bank details | Never actioned from email alone; call-back to a known number, logged with date and name |
| Approval | A second person approves any new payee or changed details in the banking platform |
| Urgent requests | Treated with extra suspicion, never with extra speed |
| Large payments | Confirm by phone even when details haven’t changed |
| Records | Keep the call-back log with the supplier’s file |
Review the process once a year and whenever staff who pay invoices change. It’s worth including in your one-page business continuity plan.
Why do small businesses get targeted?
Scammers look for businesses where one person handles payments, where email is the main channel with suppliers, and where there’s pressure to pay quickly. Those describe most small businesses — especially during a crisis. That’s not a reason to worry; it’s a reason to make the call-back rule automatic.
What if the scam came through your own hacked email?
Act as if the attacker may still have access. Change passwords from a clean device, turn on multi-factor authentication, check for forwarding rules and unfamiliar logins, and get your IT provider to confirm the account is secure before you rely on it again. Then phone every customer who may have received a fake invoice — a phone call is the only message they can be sure came from you.
The takeaway
Most of these scams are stopped by one phone call to a known number. If one has already hit your cash flow, we can help you look at a bridge.
A human being, not an auto-dialler, calls to talk it through with you. We won’t pull your credit file just because you asked a question — that waits until you say go. You won’t get a wave of calls from lenders you’ve never heard of, because we don’t pass enquiries around.
Honest, precise answers — the sum, what it pays for, your state, any real estate — mean we can point you in the right direction straight away. Open the enquiry form.
Frequently asked questions
What is a business email compromise scam?
Scamwatch describes it as scammers pretending to be from a business you've used and sending an invoice with new payee information so you pay them instead. It can also involve a hacked email account inside your own business.
What should I do if we've paid a fake invoice?
Contact your bank's fraud team immediately — the sooner, the better the chance of stopping or recalling the payment. Then report it through the Australian Cyber Security Hotline (1300 292 371) and Scamwatch, and change your email passwords.
How can I verify a change of bank details?
Phone the supplier on a number you already have — from a previous invoice, their website or your records — not the number in the email. Ask a specific question only the real supplier would know.
Why are scams more common after a disaster?
Businesses are busy, staff are working in unusual ways, suppliers are changing, and people expect disruption. Scamwatch also warns that scammers impersonate charities after natural disasters and major events.
Who can help my small business recover from a scam?
IDCARE offers free support for small businesses on 1800 595 170, and the Australian Cyber Security Hotline is 1300 CYBER1 (1300 292 371).