Business email compromise: the invoice scam actually hitting Australian trade businesses
19 August 2026 · 5 min read
Business email compromise (BEC) — an attacker impersonating a supplier or client to redirect a payment — is the most-reported cybercrime category against Australian small businesses, and trade businesses are a specific target because of high-value supplier invoices and client progress payments moving through email with little friction.
What the scam actually looks like
It rarely looks like a scam. The two common patterns: a supplier's email account is compromised and sends a genuine-looking invoice with new bank details attached, or an attacker registers a lookalike domain (one character different from your supplier's real one) and emails you directly saying their account changed. Both arrive as ordinary business correspondence, often mid-conversation on a real, existing job.
Why trade businesses specifically get targeted
- Supplier invoices are large and irregular enough that a changed amount or new account doesn't immediately look wrong.
- Client progress payments on bigger jobs move real money on a schedule an attacker can predict from a compromised inbox.
- Small teams often have one person handling payments, with no second check before a bank transfer goes out.
What actually stops it
- Any bank-detail change, from anyone, gets confirmed by phone on a number you already have on file — never a number in the email.
- Multi-factor authentication on every email account that can send or receive invoices, not just the owner's.
- A second person (even informally) glances at any transfer over a set amount before it goes out.
- Check the sender's actual email address, not just the display name, on anything asking to change payment details.
None of this requires new software — it's a habit change that costs nothing, and it's the single highest-value five minutes most trade businesses could spend on cybersecurity this month.
Our free scan checks the parts of this attack surface you can verify externally — DKIM/SPF/DMARC on your own domain, and what's publicly exposed.
RELATED
The ACSC Essential Eight, translated for a one-van trade business
"Application whitelisting" means nothing to a solo electrician. "Only install apps from the app store" does.
ReadHow to tell if a "free scan" offer is legitimate (and how to verify mine in five minutes)
A free scan that asks for payment details before showing results isn't a free scan. Here's what a legitimate one looks like.
ReadWANT THIS APPLIED TO YOUR BUSINESS?
15 minutes is enough to know if there's a real gap worth closing.
BOOK YOUR FREE AI AUDIT CALL