A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
14 August 2026
5 min read
Cybersecurity
Business Email Compromise
Scams
Accounting
Perth Business

This is a representative scenario, not a specific client. It's a composite of the kind of business email compromise call we handle, written to show how we work the problem and why. Real incidents vary, and the details here are deliberately general.

An accounts clerk at a Perth accounting firm gets an email that looks completely normal: a supplier they pay every month, advising that their bank details have changed, with a polite request to use the new account for this month's invoice. Nothing about it feels off — the logo is right, the wording is right, the invoice is attached. This is business email compromise (BEC), and it's the single most expensive scam hitting Australian businesses. Here's how we respond when a client spots one (or nearly pays it), and the controls that stop it happening at all.

The moment it's noticed

Sometimes the clerk pauses because the bank account is interstate when the supplier is local. Sometimes the payment has already gone out and the real supplier chases the unpaid invoice a week later. Either way, the first call to us is usually: "I think we've been scammed — or nearly." Speed now matters enormously, because with a fraudulent transfer the money is often recoverable only in the first hours.

First: stop the money, then preserve the evidence

Two things happen in parallel the moment we're engaged:

  • Stop the payment. If the transfer hasn't cleared, the firm calls their bank immediately to attempt a recall, and we help them contact the receiving bank's fraud team. Time is everything here — a same-day flag can claw funds back that a next-day one can't.
  • Preserve, don't delete. The instinct is to delete the dodgy email. We keep it — headers and all — because it tells us whether the attacker simply spoofed the supplier from outside, or is actually inside a mailbox reading real conversations. That distinction changes everything about what we do next.

How we work out what actually happened

BEC comes in two flavours, and we confirm which one we're dealing with:

  • External spoofing — the attacker never got into any account; they forged a lookalike address (a swapped letter, a .co instead of .com.au) and guessed the payment cycle. Bad, but contained.
  • A compromised mailbox — the attacker has phished a real Microsoft 365 login and is sitting inside the firm's (or the supplier's) email, reading threads and striking at exactly the right moment. This is the dangerous one, and the tell-tale sign is a hidden inbox rule silently moving the supplier's real emails to a folder so nobody notices the conversation being hijacked.

We check the Microsoft 365 audit log for suspicious sign-ins, review every mailbox rule, and confirm whether multi-factor authentication actually held. If an account was compromised, we treat it as a full account takeover — reset credentials, revoke active sessions, and hunt for anything else the attacker touched.

Closing the hole — the real fix

Recovering the payment is the emergency; making it impossible next time is the job. What we put in place:

  • Payment-change verification as policy, not judgement. Any change to a supplier's bank details must be confirmed by phone on a known number (never the number on the new invoice) before a cent moves. This one habit stops most BEC losses outright.
  • Email protection** that flags impersonation** — external-sender warnings, lookalike-domain detection, and SPF/DKIM/DMARC configured so spoofed mail is rejected rather than delivered.
  • MFA everywhere, phishing-resistant where it counts, so a stolen password alone can't open the mailbox.
  • Staff awareness aimed squarely at finance roles, because they're the target — we walk teams through exactly what these emails look like (our guide on spotting business email compromise is a good primer).

Why this was preventable

Notice what BEC relies on: not a clever hack, but a trusted process with no verification step. The attacker doesn't need to break your systems if they can convince one busy person to change a bank account. That's why the fix is mostly procedural, backed by the right email controls — and why an accounting firm, which moves money on behalf of clients, has more to protect than almost anyone. It's the reason we take a dedicated approach to IT for Perth accounting practices, where confidentiality and trust-account discipline are the whole business.

How we help

For our managed IT clients, the anti-BEC controls above are standard: hardened email, MFA, audit logging that surfaces a suspicious sign-in early, and a documented payment-verification process. And if you're reading this because something has just landed in your inbox that doesn't feel right, don't pay it and don't delete it — call us on (08) 9325 1196 or get in touch and we'll help you check it safely. We've protected Perth businesses' money and data since 1997.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 29 years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With 29 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
14 August 2026
5 min read
Cybersecurity
Business Email Compromise
Scams
Accounting
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Exchange, Office 2021 and Windows Server 2012 All Lose Support in October 2026: Perth Guide

Exchange 2016/2019, Office 2021 and Windows Server 2012 all stop receiving security updates in October 2026. Here's what Perth businesses running any of them need to do before then. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

SonicWall's Remote-Access Gateway Just Scored a Perfect 10: What Perth Businesses Should Check

Two chained SonicWall SMA1000 flaws let an attacker take over the appliance without a password, and they're being exploited now. Here's what Perth businesses with remote staff should do this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Ransomware Gangs Are Naming Ordinary Australian Businesses: What Perth SMBs Should Do Now

Three ransomware groups have claimed attacks on ordinary Australian businesses in September 2026 — not banks or hospitals. Here's why Perth SMBs need an incident response plan before it happens, not after. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Payment Redirection Scams Are Costing Australian Businesses Millions: A Perth Guide
Scams
Cybersecurity

Payment Redirection Scams Are Costing Australian Businesses Millions: A Perth Guide

Payment redirection and invoice scams are the most common fraud reported by Australian small businesses, with losses in the hundreds of millions. Ahead of Scams Awareness Week 2026, here's how Perth businesses can stop them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/17/2026
Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore
Cybersecurity
AI

Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore

AI can now clone a voice from seconds of audio, and businesses are losing millions to fake 'CEO' calls. Here's how deepfake scams work, why Perth SMBs are targets, and the simple process that stops them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
7/13/2026
SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts
Cybersecurity
Scams

SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts

Reports of SIM-swap and phone port-out fraud are climbing in Australia, and the target is usually the SMS codes protecting your business banking and email. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/9/2026