A payment redirection scam is when a criminal poses as a supplier, contractor or colleague and convinces your business to pay a real invoice into their bank account instead of the genuine one. It's the single most common type of scam reported by small businesses to the National Anti-Scam Centre, and it works precisely because nothing about the email looks unusual — the amount is right, the logo is right, only the BSB and account number have quietly changed. With Scamwatch's national Scams Awareness Week running 24–28 August 2026, it's a timely moment for Perth business owners to check whether their payment process would actually catch this.
How big the problem actually is
This isn't a fringe threat. The National Anti-Scam Centre's most recent annual reporting put combined scam losses across Australia at $2.18 billion, up 7.8% on the year before, with payment redirection losses alone reaching $166.8 million — up more than 9%. In just the first three months of 2026, the Centre logged 45,816 scam reports nationally with an estimated $76.7 million lost. Businesses of every size feature heavily in that total, and false billing — fake or altered invoices — is consistently the most-reported scam type small businesses experience.
The reason it hits businesses harder than individuals is simple: businesses pay invoices constantly, to a rotating cast of suppliers, contractors and service providers, and the person approving payment usually isn't the person who has a personal relationship with that supplier. That gap is exactly what the scam is built to exploit.
What the scam actually looks like
Criminals don't usually invent a fake supplier out of nowhere — that's too easy to spot. Instead, they compromise or closely mimic a real one, then insert themselves into a genuine transaction. In practice that means:
- A "new bank details" email, timed to arrive shortly before a payment is due, claiming the supplier has switched banks or is updating their accounts system
- A compromised supplier mailbox — the scammer has actually broken into a real supplier's email account and is watching an existing conversation, then jumps in with a doctored invoice at exactly the right moment
- A lookalike domain, one character different from the real one, used to send a near-identical invoice from what looks like the right sender
- Urgency and authority — the message often references a real project, a real amount, or claims to come from a director or senior contact, and asks for the payment to be processed "today" or "before the deadline"
Construction, trades and professional services firms are particularly exposed because they routinely pay large progress payments and subcontractor invoices, often under time pressure to keep a project moving.
Why normal email security doesn't fully stop it
Spam filtering and antivirus are built to catch malware and obviously fake senders — they generally won't flag a payment redirection attempt, because the email often isn't malicious in the technical sense. There's no attachment to scan and no dodgy link to block. The email just contains different bank details, sent with confidence and good timing. That's why this scam slips past businesses that are otherwise well protected against viruses and phishing links.
Good email security still matters — a hardened mailbox is much harder to compromise in the first place, and modern filtering can flag lookalike domains and impersonation attempts before they land. But the decisive control is a human process, not a piece of software.
The one rule that stops most of these
Whenever a supplier's bank details change, or a large payment is requested with unusual urgency, verify it by phone — using a number you already have on file, never a number or link from the email itself. That single habit, applied consistently, blocks the overwhelming majority of payment redirection attempts, because the scammer doesn't control the phone line.
A few other habits worth adding this week:
- Require a second person to sign off on any bank detail change, no exceptions for "regular" suppliers.
- Call, don't reply. Replying to a suspicious email just confirms to the scammer that the address is active and being read.
- Watch for pressure and timing. Requests that arrive right before a long weekend, at end of month, or with a hard deadline are a classic scam pattern.
- Check the sending domain character-by-character, not just the display name — a single swapped letter is easy to miss at a glance.
- Brief everyone who touches invoices or payroll, not just the bookkeeper. Reception staff and project managers are targeted just as often.
If your team wants a refresher on spotting the underlying phishing techniques these scams rely on, our guide to how to identify phishing emails is a good five-minute read to circulate before Scams Awareness Week.
If a payment has already gone out
Speed matters more than anything else. Contact your bank immediately — banks can occasionally recall a payment if it's caught within hours, far less often after a day or two. Then report it to the National Anti-Scam Centre via Scamwatch, and separately notify the real supplier so they know their name (or mailbox) is being used to target their customers.
Building this into how your business actually runs
For businesses that pay a lot of suppliers, this is worth treating as a standing process rather than a one-off email reminder. Our IT security solutions work covers exactly this kind of practical, staff-facing control alongside the technical side, and our email protection service is set up to catch impersonation and lookalike-domain attempts before they reach a mailbox at all. We also work closely with Perth construction companies, where large progress payments make this scam especially costly if it succeeds.
Payment redirection scams keep working because they target trust and routine, not technical weaknesses — which means the fix is mostly about routine too. A simple "verify by phone, no exceptions" rule, applied every time, costs nothing and closes the door on the most expensive scam small businesses currently face. If you'd like us to look at your current payment process and email security setup ahead of Scams Awareness Week, get in touch — Computer Mechanics has been helping Perth businesses stay a step ahead of scammers since 1997.



