Insights › Email & Phishing

Payment Redirection Fraud and Fake Invoice Scams

Conceptual illustration of an invoice with bank details being swapped and funds redirected on a navy background.

Your accounts team receives an invoice from a supplier you have paid dozens of times. The logo is right, the ABN is right, the amount looks about right, and it even lands in the middle of an email thread you were already having. The only thing that has changed is the bank account it asks you to pay into. That single altered detail is the whole scam, and it is one of the most expensive tricks facing Australian businesses today.

Payment redirection fraud, sometimes called false billing or fake invoice fraud, works because it hides inside your normal routine. There is no dodgy link to click and no obvious spelling mistakes to catch. The money simply goes to a criminal instead of your supplier, and you often do not find out until the real supplier calls to ask why they have not been paid. This guide explains how the scam works, how to spot it, and the simple verification habits that stop it cold.

How payment redirection fraud actually works

Most payment redirection scams start with a compromised email account. A criminal gains access to an inbox somewhere in the supply chain, often through a stolen password or a convincing phishing email, then quietly watches. They read past conversations, learn who pays whom, note the language people use, and wait for a genuine invoice to be discussed. When the moment is right, they step in.

Sometimes they send a fresh invoice that copies your supplier’s branding exactly. Sometimes they reply inside an existing thread and simply say the company has changed banks, so please update the payment details. Because the message comes from a real address, or one that is almost identical, your accounts team has little reason to doubt it. The Australian Competition and Consumer Commission, through Scamwatch, describes these as fake business invoice scams, where a genuine looking invoice carries a different BSB and account number to the real business.

The compromised account can sit on your side or your supplier’s side. That is what makes this fraud a shared risk rather than a problem you can solve on your own. If your supplier’s email is breached, the fraudulent invoice really does come from their address. This is the same underlying threat we cover in our guide to business email compromise, and payment redirection is simply its most common and most profitable form.

Why fake invoices are so hard to spot

Traditional scam advice tells people to look for poor grammar, strange sender addresses, and urgent threats. Payment redirection fraud defeats all of that. The criminals have done their homework, so the invoice reads like every other invoice you receive. They copy authentic logos and ABNs, they match the format you are used to, and they time the request to line up with work you are genuinely expecting to pay for.

Two techniques make these scams especially convincing. The first is thread hijacking, where the fraudulent message is inserted into a real email conversation so it inherits all the trust of the messages above it. The second is lookalike domains, where an address changes by a single character that is easy to miss when you are moving quickly. Your eye reads what it expects to read, and a busy afternoon is exactly when that happens. Because the only thing that has really changed is a line of banking detail, no security software will flag it for you. The defence has to be a human habit, not a piece of technology.

The warning signs to train your team on

The single biggest red flag is any request to change bank account details. Treat it as a stop sign every time, no matter how reasonable the explanation sounds. Alongside that, the Australian Signals Directorate’s Australian Cyber Security Centre lists several signs that an email account in the chain may have been compromised. Share these with everyone who touches invoices or payments:

Learning to read an email with a critical eye is a skill worth building across the whole team. Our guide on how to spot a phishing email is a good starting point for the people who process your payments.

How to verify a payment before you send it

Scamwatch sums up the right instinct in three words: stop, think, protect. Stop and give yourself permission to slow down, because scammers rely on you being busy. Think about who you are really dealing with and whether anything has changed. Protect your money by verifying before you pay. In practice, that means building a small set of non negotiable checks into your payment process:

None of these steps needs new software or a big budget. They are process habits, and a phone call to a number you already trust is the cheapest fraud control your business will ever put in place.

What to do if you have already paid a fake invoice

Speed matters more than anything once money has left your account. If you realise a payment has gone to the wrong place, contact your bank immediately and ask them to attempt a recall of the funds. The sooner you act, the better the chance the money can be frozen before the criminal moves it on. Do this even if you are not yet certain, because the bank can investigate faster than you can.

Next, secure the email accounts involved. Change passwords, sign out of active sessions, and check for any mail rules that may be hiding or forwarding messages. Then report the incident. You can report cybercrime to the Australian Signals Directorate through ReportCyber at cyber.gov.au, and report the scam to Scamwatch, which helps authorities track the criminals and warn other businesses. Finally, tell the genuine supplier so they can check whether their own systems have been breached and warn their other customers.

Building a habit that scammers cannot beat

Payment redirection fraud is not really a technology problem, so it does not have a purely technical fix. The businesses that avoid it are the ones that make verification a normal, expected part of paying an invoice, rather than an insult to a trusted supplier. When your whole team understands that a call back on changed bank details is simply how you do things, the scam has nowhere to land.

That said, a few technical basics make the fraud far harder to pull off in the first place. Strong, unique passwords and multi-factor authentication on every email account make it much harder for a criminal to break in and watch your conversations. Since the scam so often begins with a single compromised inbox, protecting those accounts protects everyone you trade with. Combine that with a clear payment verification process and you have covered both sides of the problem.

Find out where you stand

Payment redirection fraud thrives where email accounts are weakly protected and payment checks are informal. If you are not sure how your business measures up on either front, a quick self-assessment is a good place to start. Our free security self-assessment asks 27 plain-English questions and gives you a personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2. It takes about five to ten minutes and there is nothing to install.

Take the free assessment now and see exactly where your defences are strong and where a scammer might find a gap.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading