
This is a representative scenario, not a specific client. It's a composite of the kind of business email compromise call we handle, written to show how we work the problem and why. Real incidents vary, and the details here are deliberately general.
An accounts clerk at a Perth accounting firm gets an email that looks completely normal: a supplier they pay every month, advising that their bank details have changed, with a polite request to use the new account for this month's invoice. Nothing about it feels off — the logo is right, the wording is right, the invoice is attached. This is business email compromise (BEC), and it's the single most expensive scam hitting Australian businesses. Here's how we respond when a client spots one (or nearly pays it), and the controls that stop it happening at all.
The moment it's noticed
Sometimes the clerk pauses because the bank account is interstate when the supplier is local. Sometimes the payment has already gone out and the real supplier chases the unpaid invoice a week later. Either way, the first call to us is usually: "I think we've been scammed — or nearly." Speed now matters enormously, because with a fraudulent transfer the money is often recoverable only in the first hours.
First: stop the money, then preserve the evidence
Two things happen in parallel the moment we're engaged:
Stop the payment. If the transfer hasn't cleared, the firm calls their bank immediately to attempt a recall, and we help them contact the receiving bank's fraud team. Time is everything here — a same-day flag can claw funds back that a next-day one can't.
Preserve, don't delete. The instinct is to delete the dodgy email. We keep it — headers and all — because it tells us whether the attacker simply spoofed the supplier from outside, or is actually inside a mailbox reading real conversations. That distinction changes everything about what we do next.
How we work out what actually happened
BEC comes in two flavours, and we confirm which one we're dealing with:
External spoofing — the attacker never got into any account; they forged a lookalike address (a swapped letter, a
.coinstead of.com.au) and guessed the payment cycle. Bad, but contained.A compromised mailbox — the attacker has phished a real Microsoft 365 login and is sitting inside the firm's (or the supplier's) email, reading threads and striking at exactly the right moment. This is the dangerous one, and the tell-tale sign is a hidden inbox rule silently moving the supplier's real emails to a folder so nobody notices the conversation being hijacked.
We check the Microsoft 365 audit log for suspicious sign-ins, review every mailbox rule, and confirm whether multi-factor authentication actually held. If an account was compromised, we treat it as a full account takeover — reset credentials, revoke active sessions, and hunt for anything else the attacker touched.
Closing the hole — the real fix
Recovering the payment is the emergency; making it impossible next time is the job. What we put in place:
Payment-change verification as policy, not judgement. Any change to a supplier's bank details must be confirmed by phone on a known number (never the number on the new invoice) before a cent moves. This one habit stops most BEC losses outright.
Email protection that flags impersonation — external-sender warnings, lookalike-domain detection, and SPF/DKIM/DMARC configured so spoofed mail is rejected rather than delivered.
MFA everywhere, phishing-resistant where it counts, so a stolen password alone can't open the mailbox.
Staff awareness aimed squarely at finance roles, because they're the target — we walk teams through exactly what these emails look like (our guide on spotting business email compromise is a good primer).
Why this was preventable
Notice what BEC relies on: not a clever hack, but a trusted process with no verification step. The attacker doesn't need to break your systems if they can convince one busy person to change a bank account. That's why the fix is mostly procedural, backed by the right email controls — and why an accounting firm, which moves money on behalf of clients, has more to protect than almost anyone. It's the reason we take a dedicated approach to IT for Perth accounting practices, where confidentiality and trust-account discipline are the whole business.
How we help
For our managed IT clients, the anti-BEC controls above are standard: hardened email, MFA, audit logging that surfaces a suspicious sign-in early, and a documented payment-verification process. And if you're reading this because something has just landed in your inbox that doesn't feel right, don't pay it and don't delete it — call us on (08) 9325 1196 or get in touch and we'll help you check it safely. We've protected Perth businesses' money and data since 1997.



