
The scam costing Australian businesses the most isn’t the one you’re picturing.
Ask most business owners what a cyber scam looks like and they’ll describe something obviously wrong: bad spelling, a dodgy link, an email from a stranger. Business email compromise (an attacker taking over or convincingly impersonating a real mailbox to redirect a payment) has repeatedly ranked among the costliest categories of cybercrime reported to Australian authorities, and it looks nothing like the scam most people picture. It looks exactly like your normal correspondence, because in a growing number of cases, it’s sent from inside a mailbox that belongs to someone you trust.
The pattern we see most often starts with one compromised mailbox, often a supplier’s accounts team, a conveyancer, or a bookkeeper, usually through a stolen password with no MFA behind it. Rather than sending an obvious phishing blast, the attacker sits quietly and reads. They learn who invoices whom, what your usual payment terms look like, when a big settlement or payroll run is due. Then, at exactly the right moment, they insert themselves into a real conversation thread and send a bank detail change from someone you already trust, in a tone that matches every other email in it. In many cases they’ve quietly set up a mailbox rule to intercept and hide the real replies, so nothing looks amiss on either end until the money’s gone. No spelling mistakes, no suspicious link, no reason for your bookkeeper to think twice, because nothing about the email looked wrong. That’s precisely why it works, and why “we’d notice” is the belief this scam is built to defeat.
The Mailbox Rule That Hides the Evidence
Once an attacker is inside a mailbox, one of the first things they often do is quietly create a forwarding or filing rule: something like emails containing “invoice” or “payment” get moved to an obscure folder, or forwarded to an external address and then deleted from the inbox. The account owner keeps sending and receiving email normally and notices nothing wrong, because the interception happens silently in the background. This is why a compromised mailbox can sit undetected for weeks, and why checking for unfamiliar mail rules is one of the simplest, highest-value things a business can do after any suspected compromise.
Why Your Approval Process and Your Bank Won’t Catch It
Plenty of businesses assume a second approver will catch a fake bank detail. Two-step payment approval inside your accounting software doesn’t help unless one of the steps involves an actual phone call. If the fraudulent detail arrives inside a genuine email thread, both approvers are looking at the same convincing email. Two people clicking approve on a fraudulent detail is still fraud, approved twice. Your bank is unlikely to catch it either: a payment to an account matching the name on the invoice, for an amount matching a real, expected payment, rarely triggers anything on their end. Trades, professional services, and any business regularly handling supplier payments or client settlements are squarely in scope. The verification responsibility sits with your business, which also means the fix is in your hands.
What Stops This
The fix isn’t more software or a bigger budget. It’s one habit that survives being inconvenient: any change to bank details, however it arrives, gets verified by phone using a number you already had on file, never one from the email itself, before a cent moves. Treat that rule as non-negotiable, even when the request comes from your own director, your longest-standing supplier, or arrives at the worst possible time to slow down and check. On your own systems, MFA on every mailbox and a periodic check for mailbox rules nobody remembers creating will close most of the rest of the gap. That quiet forwarding or auto-delete rule is often the only trace an attacker leaves behind, and it’s a five-minute check in your email admin settings.
The Pritech Approach
At Pritech, we help Tasmanian businesses review exactly this kind of exposure, particularly around payment processes, as part of a broader security check. It’s usually a shorter conversation than people expect. Multi-factor authentication is also one of the ACSC’s Essential Eight strategies, the baseline the Australian Government recommends for Australian businesses. As an accredited ACSC Essential Eight auditor, we can show you where your business sits against that baseline, and which gaps matter most.
If you want a second set of eyes on how exposed your business is, get in touch with our team today.



