Skip to main content
SECURITY

Business email compromise: the invoice scam actually hitting Australian trade businesses

19 August 2026 · 5 min read

← Back to the blog

Business email compromise (BEC) — an attacker impersonating a supplier or client to redirect a payment — is the most-reported cybercrime category against Australian small businesses, and trade businesses are a specific target because of high-value supplier invoices and client progress payments moving through email with little friction.

What the scam actually looks like

It rarely looks like a scam. The two common patterns: a supplier's email account is compromised and sends a genuine-looking invoice with new bank details attached, or an attacker registers a lookalike domain (one character different from your supplier's real one) and emails you directly saying their account changed. Both arrive as ordinary business correspondence, often mid-conversation on a real, existing job.

Why trade businesses specifically get targeted

  • Supplier invoices are large and irregular enough that a changed amount or new account doesn't immediately look wrong.
  • Client progress payments on bigger jobs move real money on a schedule an attacker can predict from a compromised inbox.
  • Small teams often have one person handling payments, with no second check before a bank transfer goes out.

What actually stops it

  1. Any bank-detail change, from anyone, gets confirmed by phone on a number you already have on file — never a number in the email.
  2. Multi-factor authentication on every email account that can send or receive invoices, not just the owner's.
  3. A second person (even informally) glances at any transfer over a set amount before it goes out.
  4. Check the sender's actual email address, not just the display name, on anything asking to change payment details.

None of this requires new software — it's a habit change that costs nothing, and it's the single highest-value five minutes most trade businesses could spend on cybersecurity this month.

Our free scan checks the parts of this attack surface you can verify externally — DKIM/SPF/DMARC on your own domain, and what's publicly exposed.

RUN THE FREE SCAN →

RELATED

Security19 Aug 20266 min read

The ACSC Essential Eight, translated for a one-van trade business

"Application whitelisting" means nothing to a solo electrician. "Only install apps from the app store" does.

Read
Trust18 Aug 20264 min read

How to tell if a "free scan" offer is legitimate (and how to verify mine in five minutes)

A free scan that asks for payment details before showing results isn't a free scan. Here's what a legitimate one looks like.

Read

WANT THIS APPLIED TO YOUR BUSINESS?

15 minutes is enough to know if there's a real gap worth closing.

BOOK YOUR FREE AI AUDIT CALL
Book Free AI Audit Call