IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
PhishByte warns of rising BEC scams hitting Australian firms

PhishByte warns of rising BEC scams hitting Australian firms

Tue, 1st Sep 2026 (Today)
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

PhishByte has warned Australian businesses about a rise in business email compromise scams, with payment redirection fraud costing them AUD $166.8 million in the latest ACCC reporting period.

The warning comes as courts and cybersecurity specialists highlight fraud schemes that rely on impersonation and altered payment details rather than malware or malicious links. In one recent Western Australian case, a business that paid a fraudulent invoice was ordered to pay the legitimate contractor a second time.

Business email compromise, often shortened to BEC, involves criminals gaining access to or imitating a trusted email account to divert payments. The fraud typically targets finance teams, payroll staff, or executives with authority over transfers, and it can remain undetected until funds have moved through multiple accounts.

Attackers often begin by harvesting login credentials through phishing, then monitor a compromised inbox for days or weeks. They study invoice cycles, supplier relationships, and the communication style of senior staff before stepping in when a large payment is due or a decision-maker is unavailable.

Rather than sending an obviously malicious message, the attacker inserts false bank account details into an existing email exchange or sends a near-identical request from a lookalike domain. Because the message may come from a genuine account and contain no attachment or link, standard email checks may not flag it.

Court warning

A legal dispute in Western Australia has added weight to concerns about the threat. In Mobius Group v Inoteq, attackers compromised an electrical contractor's email system, intercepted a legitimate invoice, and changed the BSB and account number before it was sent to the client.

The client transferred AUD $235,400 to a criminal-controlled account. The Western Australian District Court then ordered the client to pay the contractor again in full, finding that the payer bore the loss because it had not independently verified the altered banking details.

The ruling has sharpened attention on payment verification procedures, particularly for businesses that rely heavily on emailed invoices and account change requests. It also underlines the legal risk alongside the direct financial loss from a scam.

Common tactics

PhishByte identified four forms of BEC commonly aimed at Australian organisations: invoice fraud and payment redirection, executive impersonation, payroll diversion, and the interception of legal and conveyancing transactions.

Invoice fraud typically involves compromising a supplier's email account and substituting bank details on a genuine bill. Executive impersonation often uses a lookalike domain to mimic a senior manager requesting an urgent transfer while claiming to be unavailable by phone.

Payroll diversion targets human resources or payroll teams with a message purporting to come from an employee asking for salary payments to be redirected to a new account. In property and legal transactions, criminals seek to alter trust account details shortly before settlement, when time pressure is intense and routine checks may be skipped.

Human target

BEC differs from many other forms of cyber attack because it is designed to exploit decision-making rather than software flaws, PhishByte argued. A message can pass common authentication checks if it is sent from a legitimate but compromised account, and advances in generative AI have made fraudulent writing harder to distinguish from genuine internal communication.

PhishByte said this helps explain why the scams are effective.

"BEC succeeds because attackers deliberately exploit the cognitive biases every human brain has - authority, urgency, and familiarity," PhishByte said. "No technical control stops an employee who has been socially engineered into processing a payment that looks completely legitimate. The only effective control is an employee who has been trained to question process deviations regardless of who appears to be asking."

Verification step

PhishByte said the most effective defence is a mandatory callback process for any change to supplier banking details. Under that approach, staff must verify the request by calling a known number held in existing records rather than any number provided in the email.

Other measures include dual approval for outbound payments above a set threshold and fixed payment procedures that require verbal confirmation of account changes. Businesses are also using regular internal exercises with realistic scam scenarios to test whether finance and administrative teams follow established controls.

For Australian businesses, the concern is not only that the fraud can evade technical filters, but also that losses can be difficult to recover once the money has been transferred and dispersed. In many cases, funds are moved rapidly through local mule accounts and then converted into cryptocurrency, leaving little prospect of retrieval.

The Western Australian ruling turned that operational weakness into a legal and financial lesson: a single unverified change in bank details can leave a business out of pocket once to criminals and a second time to the legitimate supplier.