Ransomware gets the headlines, but business email compromise (BEC) quietly costs Australian businesses more. It needs no malware and triggers no antivirus alert, because the attack is conducted entirely with legitimate tools: your own email account.
Anatomy of the scam
- Access. The attacker phishes or buys a working email password. Without MFA, they’re in.
- Patience. They don’t announce themselves. They read. Invoices, payment runs, who approves what, how the director writes.
- The move. At the right moment, an email goes out: a real invoice with changed bank details, or an urgent transfer request in the boss’s voice, from the boss’s actual address. Often a mailbox rule hides the replies.
- The loss. Money moves to a mule account and is layered away within hours. Recovery is rare and slow.
The controls that break the chain
- MFA on email. Kills the initial access for the vast majority of attempts. Non-negotiable.
- Out-of-band verification for payment changes. Any change of bank details gets confirmed by phone on a number you already hold. Make it policy; print it on your invoices too, so your customers do the same for you.
- SPF, DKIM and DMARC on your domain. Stops criminals sending as you to your customers and suppliers.
- Mailbox rule audits. A forwarding or delete rule nobody created is the classic sign of a compromised mailbox; check them after any suspicious activity.
- Dual approval on payments above a threshold. Two sets of eyes defeat manufactured urgency.
If it happens
Call your bank immediately, minutes matter for freezing transfers. Then reset the compromised account, revoke sessions, remove rogue mailbox rules, and report to ReportCyber (cyber.gov.au). If personal information was exposed, the Notifiable Data Breaches scheme may apply.