A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
14 August 2026
5 min read
Cybersecurity
Business Email Compromise
Scams
Accounting
Perth Business

This is a representative scenario, not a specific client. It's a composite of the kind of business email compromise call we handle, written to show how we work the problem and why. Real incidents vary, and the details here are deliberately general.

An accounts clerk at a Perth accounting firm gets an email that looks completely normal: a supplier they pay every month, advising that their bank details have changed, with a polite request to use the new account for this month's invoice. Nothing about it feels off — the logo is right, the wording is right, the invoice is attached. This is business email compromise (BEC), and it's the single most expensive scam hitting Australian businesses. Here's how we respond when a client spots one (or nearly pays it), and the controls that stop it happening at all.

The moment it's noticed

Sometimes the clerk pauses because the bank account is interstate when the supplier is local. Sometimes the payment has already gone out and the real supplier chases the unpaid invoice a week later. Either way, the first call to us is usually: "I think we've been scammed — or nearly." Speed now matters enormously, because with a fraudulent transfer the money is often recoverable only in the first hours.

First: stop the money, then preserve the evidence

Two things happen in parallel the moment we're engaged:

  • Stop the payment. If the transfer hasn't cleared, the firm calls their bank immediately to attempt a recall, and we help them contact the receiving bank's fraud team. Time is everything here — a same-day flag can claw funds back that a next-day one can't.

  • Preserve, don't delete. The instinct is to delete the dodgy email. We keep it — headers and all — because it tells us whether the attacker simply spoofed the supplier from outside, or is actually inside a mailbox reading real conversations. That distinction changes everything about what we do next.

How we work out what actually happened

BEC comes in two flavours, and we confirm which one we're dealing with:

  • External spoofing — the attacker never got into any account; they forged a lookalike address (a swapped letter, a .co instead of .com.au) and guessed the payment cycle. Bad, but contained.

  • A compromised mailbox — the attacker has phished a real Microsoft 365 login and is sitting inside the firm's (or the supplier's) email, reading threads and striking at exactly the right moment. This is the dangerous one, and the tell-tale sign is a hidden inbox rule silently moving the supplier's real emails to a folder so nobody notices the conversation being hijacked.

We check the Microsoft 365 audit log for suspicious sign-ins, review every mailbox rule, and confirm whether multi-factor authentication actually held. If an account was compromised, we treat it as a full account takeover — reset credentials, revoke active sessions, and hunt for anything else the attacker touched.

Closing the hole — the real fix

Recovering the payment is the emergency; making it impossible next time is the job. What we put in place:

  • Payment-change verification as policy, not judgement. Any change to a supplier's bank details must be confirmed by phone on a known number (never the number on the new invoice) before a cent moves. This one habit stops most BEC losses outright.

  • Email protection that flags impersonation — external-sender warnings, lookalike-domain detection, and SPF/DKIM/DMARC configured so spoofed mail is rejected rather than delivered.

  • MFA everywhere, phishing-resistant where it counts, so a stolen password alone can't open the mailbox.

  • Staff awareness aimed squarely at finance roles, because they're the target — we walk teams through exactly what these emails look like (our guide on spotting business email compromise is a good primer).

Why this was preventable

Notice what BEC relies on: not a clever hack, but a trusted process with no verification step. The attacker doesn't need to break your systems if they can convince one busy person to change a bank account. That's why the fix is mostly procedural, backed by the right email controls — and why an accounting firm, which moves money on behalf of clients, has more to protect than almost anyone. It's the reason we take a dedicated approach to IT for Perth accounting practices, where confidentiality and trust-account discipline are the whole business.

How we help

For our managed IT clients, the anti-BEC controls above are standard: hardened email, MFA, audit logging that surfaces a suspicious sign-in early, and a documented payment-verification process. And if you're reading this because something has just landed in your inbox that doesn't feel right, don't pay it and don't delete it — call us on (08) 9325 1196 or get in touch and we'll help you check it safely. We've protected Perth businesses' money and data since 1997.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 25+ years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With more than 25 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
14 August 2026
5 min read
Cybersecurity
Business Email Compromise
Scams
Accounting
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

A Phishing Link at a Perth Medical Practice Becomes an Account Takeover

A representative walkthrough of how we respond when a staff member at a Perth medical practice is phished and their Microsoft 365 account is taken over — contain, assess breach exposure, and harden patient data. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

A Perth Business's Server Dies — and the Backup Hadn't Run in Weeks

A representative walkthrough of how we recover a Perth business after a server failure — and what we do when the backup everyone trusted had silently stopped running. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Hackers Are Scanning Every Business Website for a Way In: ACSC Alert Explained

The ACSC has warned that hackers are scanning websites worldwide, including many Perth small businesses, for outdated CMS software and plugins to plant hidden backdoors. Here's what to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore
Cybersecurity
AI

Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore

AI can now clone a voice from seconds of audio, and businesses are losing millions to fake 'CEO' calls. Here's how deepfake scams work, why Perth SMBs are targets, and the simple process that stops them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
7/13/2026
Call us