Invoice fraud is one of the most financially damaging scams targeting Australian small businesses. The emails are often indistinguishable from legitimate supplier invoices — same logo, same format, same invoice number structure. The difference is the bank account details, which have been swapped to an account controlled by the scammer. This guide covers the specific signals to check before any payment is approved.
Payment-change wording to question
Any email that changes bank account details for a regular supplier should be treated as high risk until verified by phone. Scammers intercept supplier email accounts, monitor invoicing patterns, and then send a carefully timed email — often just before a regular payment is due — notifying you of a "new" or "updated" bank account. The email arrives at a normal time, references real invoice details, and is formatted to look identical to the supplier's genuine emails.
Red flag phrases include: "Please note our new banking details," "We have changed our bank," "Please update your records with our new BSB and account number," and "All future payments should be made to the following account." These phrases on their own are not proof of fraud — suppliers do legitimately change banks — but they warrant direct verification before acting.
The critical verification step is a phone call to a number you already have for the supplier — not the number provided in the email. Look up the number from a previous correspondence or from the supplier's official website. If the account change is legitimate, the supplier will confirm it. If it is not, you have just prevented a potentially significant payment from leaving your account.
Supplier impersonation checks
Supplier impersonation attacks are sophisticated. Attackers may compromise the actual supplier's email account and send the fraudulent invoice from a genuine address, making sender verification alone insufficient. They may create a domain that differs from the supplier's real domain by one character — an easy miss when you are reviewing dozens of emails in a day.
Check the email headers if you have any doubt. The Reply-To address is often different from the From address in impersonation attacks, which means a reply goes to the attacker rather than the real supplier. Most email clients allow you to view headers from a message menu or properties option. Look for mismatches between From, Reply-To, and Return-Path.
Cross-reference the invoice details with your existing records. Does the invoice number follow the supplier's usual sequence? Does the invoice amount match what was agreed? Is the ABN on the invoice the same as the one on file?
Approval steps before money moves
A simple internal approval step stops the majority of invoice fraud. If any payment over a threshold — say, $500 or $1,000 — requires a second confirmation before processing, a single staff member receiving a fraudulent invoice cannot action it alone. This is not a bureaucratic step; it is a realistic control for a small business that does not need to spend money on fraud detection software.
- Any email requesting a bank account change should trigger a phone verification — no exceptions.
- Call a number from your existing records, not from the email requesting the change.
- Check the Reply-To address — it is often different from the From address in scam emails.
- Compare the ABN on the invoice with the ABN in your existing supplier records.
- Implement a two-person approval rule for payments above a set threshold.
- Report invoice fraud attempts to Scamwatch (scamwatch.gov.au) — it helps track emerging patterns.
Invoice scams work because they look routine and arrive during busy moments.
Check a suspicious email