Australian finance teams face payment scam risks as growing organisations handle more suppliers, invoices and approval processes.
ProSpend executives have pointed to payment redirection, supplier impersonation and compromised email as areas where finance teams can face exposure. They argue that payment controls need to account for both external scams and broader forms of fraud as transaction volumes increase.
Scam distinction
Scams and fraud can create different risks for finance departments. External scams can involve criminals impersonating suppliers or executives to redirect payments. Fraud can also include internal activity such as duplicate payments or inflated expense claims.
The distinction affects how organisations design financial controls. Verification of changes to bank details, separation of approval and payment responsibilities, and maintaining an audit trail are among the controls identified by ProSpend.
"Finance teams tend to use 'scam' and 'fraud' interchangeably, but the distinction changes how you defend against them. A scam comes from outside, for example someone impersonating a supplier or executive to redirect a payment. Fraud is broader and includes internal risks like duplicate payments and inflated expense claims. Australians reported $2.18 billion in scam losses last year, up 7.8% (National Anti-Scam Centre, 2025). The useful part for finance teams is that the controls overlap: verify a bank-detail change, separate who approves from who pays, keep an audit trail. Map your controls against both, because the gaps hide in between," said Tanu Kaushik, Director of Marketing, ProSpend.
Scaling risks
The task of reviewing individual invoices can become more complex as organisations grow. Finance staff may have less direct knowledge of who placed an order, which department requested it or whether a new supplier has previously been verified.
Email also remains part of the payment scam threat. ProSpend cited Australian Signals Directorate data stating that roughly one in three business cybercrime reports begins with a compromised or spoofed email.
"Ten years ago, when it was just our founder and I at ProSpend, we were both across every invoice that needed paying. But as the company grew, scams became harder to spot. Now invoices arrive in the finance inbox, and you're not always sure who ordered it, which department it's for, whether it was pre-approved, or whether a new supplier is as legitimate as it looks. The Australian Signals Directorate found roughly one in three business cybercrime reports starts with a compromised or spoofed email (ASD Annual Cyber Threat Report 2024–25), which is exactly how a payment redirection scam gets in. Expecting one person to catch a changed bank account on the right day stops being realistic. The teams handling this well have stopped relying on eyes and memory, instead they've built the check into how a payment gets approved," said Phillip Vella, Director of Sales & Partnerships, ProSpend.
Payment checks
Payment redirection scams involve criminals changing or substituting supplier payment details so that legitimate invoices are paid into accounts controlled by the attacker.
ProSpend cited National Anti-Scam Centre figures putting Australian losses from payment redirection scams at AUD $166.8 million last year. The company has built a control that compares bank details appearing on an invoice with supplier information already stored in its system. A mismatch is flagged before the payment approval stage.
"Payment redirection scams cost Australians $166.8 million last year (National Anti-Scam Centre, 2025), and they follow a familiar pattern: a supplier's bank details appear to change, and a genuine invoice gets paid to the wrong account. When we design for this, we try to target where in the workflow a mismatch would surface. At ProSpend, we built a check that compares the bank details on an invoice against the supplier record already held, and flags anything that doesn't match before approval. It won't stop every scam, but it forces a pause when invoices come into the system," said Radha Ramtej Pathi Reddy, Director of Product, ProSpend.
Loss patterns
ProSpend also pointed to changes in the distribution of scam losses in Australia. Its executives said total scam losses have fallen by nearly 30% from their 2022 peak as consumer protections have expanded.
Payment redirection has become the country's second-largest category for scam losses, according to figures cited by ProSpend. The company argues this shifts more attention towards verification processes used by finance teams when handling supplier bank details.
"The theme 'No one's just a number' matters more than it sounds, because the numbers are telling us something uncomfortable. Australia's total scam losses are down nearly 30% from their 2022 peak, driven by consumer protections that banks and platforms are now obligated to build. But payment redirection is now the second-largest loss category. Fraud reallocates. As verification gets industrialised in consumer payments, organised attackers move to the channel where verification is still one busy person checking bank details against an email. Finance teams didn't get worse. They got left on the wrong side of the investment," said Arnaud Picard, Head of Customer, ProSpend.