Invoice redirection scams are an increasingly common threat to Australian businesses. A criminal impersonates a supplier, employee or company director and asks for a payment to be sent to a different bank account.
Some attackers compromise a genuine email account and monitor conversations until an invoice is due. They then send convincing payment instructions from the real mailbox or a similar-looking email address.
Warning signs
Watch for:
-
Unexpected changes to bank account details
-
Requests marked as urgent or confidential
-
Pressure to bypass normal payment procedures
-
Slight changes in an email address or domain name
-
Unusual grammar, formatting or email signatures
-
A supplier refusing to confirm the request by telephone
Before changing payment details
Always verify new bank details by calling the supplier using a telephone number you already trust. Do not rely on contact details contained in the suspicious email.
Businesses should also require approval from two people for large payments or changes to supplier banking information.
Protect your email accounts
Use a unique password for every email account and enable multi-factor authentication wherever possible. Administrators should regularly check for unfamiliar forwarding rules, recovery addresses and login activity.
Never send passwords or authentication codes by email.
What to do if money has been transferred
Contact your bank immediately. The sooner the bank is notified, the greater the chance that it may be able to stop or recover the payment.
Preserve the original emails, invoices, payment records and email headers. Report the incident through ReportCyber and Scamwatch.
If you believe a MediaRack-hosted mailbox has been compromised, change its password immediately and submit an urgent support ticket through the MediaRack client area. Do not include your password in the ticket.
Quinta, Setembro 18, 2025
