Insights › Email & Phishing

Business Email Compromise: The Scam That Costs Australian Businesses the Most

Ransomware gets the headlines, but business email compromise (BEC) quietly costs Australian businesses more. It needs no malware and triggers no antivirus alert, because the attack is conducted entirely with legitimate tools: your own email account.

Anatomy of the scam

  1. Access. The attacker phishes or buys a working email password. Without MFA, they’re in.
  2. Patience. They don’t announce themselves. They read. Invoices, payment runs, who approves what, how the director writes.
  3. The move. At the right moment, an email goes out: a real invoice with changed bank details, or an urgent transfer request in the boss’s voice, from the boss’s actual address. Often a mailbox rule hides the replies.
  4. The loss. Money moves to a mule account and is layered away within hours. Recovery is rare and slow.

The controls that break the chain

If it happens

Call your bank immediately, minutes matter for freezing transfers. Then reset the compromised account, revoke sessions, remove rogue mailbox rules, and report to ReportCyber (cyber.gov.au). If personal information was exposed, the Notifiable Data Breaches scheme may apply.

Could BEC happen to you?

Our free assessment checks MFA, email authentication and staff awareness, the exact controls that stop BEC, in about 10 minutes.

Get my free Security Score

Discover more from securityscore

Subscribe now to keep reading and get access to the full archive.

Continue reading