Invoice fraud and payment redirection: the scam that costs the most

Invoice fraud and payment redirection: the scam that costs the most

Of everything that goes wrong with email, this is the one that takes real money out of a small business, and often tens of thousands of dollars at once. It is not a virus and it is not clever software. It is an ordinary email that asks you to pay the right amount, for the right job, into the wrong account.

It works because nothing about it looks wrong at the time.

What it actually looks like

An email from a real supplier, with changed bank details. This is the common one. Someone has got into your supplier's mailbox, read their sent items, and learned who owes them money. Then they send you the next invoice from the supplier's own address, in the supplier's own template, continuing the conversation you were already having. The only difference is the account number, usually with a line explaining it: we have changed banks, our old account is being audited, please use the new details below. The sender address is genuine, because the mailbox is genuine. There is nothing to hover over and catch.

A quick favour from the director. Short, informal, often the first message of the day or late on a Friday. "Are you around? I need you to process a payment for me, I am in meetings all day, just reply here." It comes from a lookalike address, or a mobile number, or occasionally the director's real mailbox. It leans on the fact that people do not ring the boss to double-check something the boss asked for, and it is deliberately written so that pushing back feels rude.

A new supplier detail arriving at the right moment. Attackers who are sitting in a mailbox wait. They send the change when a large invoice is genuinely due, so the payment feels expected.

Why nobody notices

This is the part that surprises people. There is no alert, no failed payment, no bounced email. The money leaves, the invoice is marked paid in your system, and everything looks finished. The fraud stays invisible until the real supplier chases the payment, which is typically two weeks to a month later, sometimes after the next invoice is issued.

By then the funds have usually been moved through several accounts. Recovery is possible but it depends almost entirely on how fast the bank is told, which is why the delay is the expensive part rather than the click.

The control that works

There is one, it is not technical, and it does not fail: before you pay new or changed bank details, ring the supplier on a number you already had.

The two words carrying the weight are already had. Not the number on the invoice. Not the number in the email signature. Not the mobile in the message. Those are all under the attacker's control, and if you ring them you will get a confident person who confirms the change. Use the number from your own records, a previous contract, an old statement, or the supplier's website that you navigate to yourself.

Speak to a person and read the account number back to them. It takes two minutes and it defeats the entire scam, because the attacker has the mailbox but not the phone.

The same applies to the director email. Ring or walk over. Any genuine director would rather be interrupted than lose the money, and if yours would not, tell them we said so.

Make it a written rule

A habit protects you until the day the person with the habit is on leave. A rule protects the business. Write it down, keep it short, and give it to everyone who can pay a bill, including the bookkeeper and any external accountant.

Something like this is enough:

  • Any new bank account, or any change to existing bank details, is verified by phone to a number we already held, before payment. No exceptions for urgency.
  • The person who verifies notes the date, the number called and who they spoke to, on the invoice record.
  • Payments over an agreed amount need a second person to approve.
  • Nobody will ever be criticised for delaying a payment to make that call.

That last line matters more than it looks. Most redirection payments are made by a careful person who felt they could not hold things up.

If you think you have already paid

Move immediately, in this order. Ring your bank and ask for a recall on the payment, then call us on 03 9028 4358, then ring the real supplier on a known number to confirm they never sent it. Do not delete the emails, and do not reply to the fraudulent thread. Report it to Scamwatch and to police through ReportCyber. Speed is the whole game here, so make the bank call before you finish working out what happened.

Still stuck?

Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.

Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.

    • Related Articles

    • How to spot a phishing email

      Phishing is an email designed to get you to do one of three things: type your password into a fake page, open an attachment, or pay someone. The good ones do not look like scams. They look like a Microsoft notice, a delivery slip, a signature ...
    • Why we send you security alerts, and which ones matter

      If we look after your systems, you will get emails from us about security. Some ask you to do something, most do not, and after a while it is easy to stop reading them. That is the outcome we most want to avoid, so here is exactly what we send and ...
    • You think you have been phished: what to do in the first ten minutes

      You clicked a link, typed your password into a page that looked right, and something feels off. Maybe the page reloaded and asked again. Maybe a colleague replied to an email you never sent. This one catches everyone, including people who are good ...
    • Fake support calls and virus warning pop-ups

      Two versions of the same scam. In one, a page takes over your screen with sirens or a beeping alarm, a Windows or Apple logo, and a warning that your computer is infected and you must ring a support number now. In the other, the phone rings and a ...
    • Using your own phone or laptop for work, safely

      Most small businesses run on personal devices to some extent. Someone checks email on their own phone, a director works from a home laptop, a part-timer uses their own machine two days a week. That is normal and it can be done safely. The risk is not ...