Payment Redirection Scams Are Costing Australian Businesses Millions: A Perth Guide

Payment redirection and invoice scams are the most common fraud reported by Australian small businesses, with losses in the hundreds of millions. Ahead of Scams Awareness Week 2026, here's how Perth businesses can stop them. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
17 August 2026
5 min read
Scams
Cybersecurity
Business Email Compromise
Perth Business
A supplier invoice email being carefully checked before payment to prevent a redirection scam

A payment redirection scam is when a criminal poses as a supplier, contractor or colleague and convinces your business to pay a real invoice into their bank account instead of the genuine one. It's the single most common type of scam reported by small businesses to the National Anti-Scam Centre, and it works precisely because nothing about the email looks unusual — the amount is right, the logo is right, only the BSB and account number have quietly changed. With Scamwatch's national Scams Awareness Week running 24–28 August 2026, it's a timely moment for Perth business owners to check whether their payment process would actually catch this.

How big the problem actually is

This isn't a fringe threat. The National Anti-Scam Centre's most recent annual reporting put combined scam losses across Australia at $2.18 billion, up 7.8% on the year before, with payment redirection losses alone reaching $166.8 million — up more than 9%. In just the first three months of 2026, the Centre logged 45,816 scam reports nationally with an estimated $76.7 million lost. Businesses of every size feature heavily in that total, and false billing — fake or altered invoices — is consistently the most-reported scam type small businesses experience.

The reason it hits businesses harder than individuals is simple: businesses pay invoices constantly, to a rotating cast of suppliers, contractors and service providers, and the person approving payment usually isn't the person who has a personal relationship with that supplier. That gap is exactly what the scam is built to exploit.

What the scam actually looks like

Criminals don't usually invent a fake supplier out of nowhere — that's too easy to spot. Instead, they compromise or closely mimic a real one, then insert themselves into a genuine transaction. In practice that means:

  • A "new bank details" email, timed to arrive shortly before a payment is due, claiming the supplier has switched banks or is updating their accounts system
  • A compromised supplier mailbox — the scammer has actually broken into a real supplier's email account and is watching an existing conversation, then jumps in with a doctored invoice at exactly the right moment
  • A lookalike domain, one character different from the real one, used to send a near-identical invoice from what looks like the right sender
  • Urgency and authority — the message often references a real project, a real amount, or claims to come from a director or senior contact, and asks for the payment to be processed "today" or "before the deadline"

Construction, trades and professional services firms are particularly exposed because they routinely pay large progress payments and subcontractor invoices, often under time pressure to keep a project moving.

Why normal email security doesn't fully stop it

Spam filtering and antivirus are built to catch malware and obviously fake senders — they generally won't flag a payment redirection attempt, because the email often isn't malicious in the technical sense. There's no attachment to scan and no dodgy link to block. The email just contains different bank details, sent with confidence and good timing. That's why this scam slips past businesses that are otherwise well protected against viruses and phishing links.

Good email security still matters — a hardened mailbox is much harder to compromise in the first place, and modern filtering can flag lookalike domains and impersonation attempts before they land. But the decisive control is a human process, not a piece of software.

The one rule that stops most of these

Whenever a supplier's bank details change, or a large payment is requested with unusual urgency, verify it by phone — using a number you already have on file, never a number or link from the email itself. That single habit, applied consistently, blocks the overwhelming majority of payment redirection attempts, because the scammer doesn't control the phone line.

A few other habits worth adding this week:

  1. Require a second person to sign off on any bank detail change, no exceptions for "regular" suppliers.
  2. Call, don't reply. Replying to a suspicious email just confirms to the scammer that the address is active and being read.
  3. Watch for pressure and timing. Requests that arrive right before a long weekend, at end of month, or with a hard deadline are a classic scam pattern.
  4. Check the sending domain character-by-character, not just the display name — a single swapped letter is easy to miss at a glance.
  5. Brief everyone who touches invoices or payroll, not just the bookkeeper. Reception staff and project managers are targeted just as often.

If your team wants a refresher on spotting the underlying phishing techniques these scams rely on, our guide to how to identify phishing emails is a good five-minute read to circulate before Scams Awareness Week.

If a payment has already gone out

Speed matters more than anything else. Contact your bank immediately — banks can occasionally recall a payment if it's caught within hours, far less often after a day or two. Then report it to the National Anti-Scam Centre via Scamwatch, and separately notify the real supplier so they know their name (or mailbox) is being used to target their customers.

Building this into how your business actually runs

For businesses that pay a lot of suppliers, this is worth treating as a standing process rather than a one-off email reminder. Our IT security solutions work covers exactly this kind of practical, staff-facing control alongside the technical side, and our email protection service is set up to catch impersonation and lookalike-domain attempts before they reach a mailbox at all. We also work closely with Perth construction companies, where large progress payments make this scam especially costly if it succeeds.

Payment redirection scams keep working because they target trust and routine, not technical weaknesses — which means the fix is mostly about routine too. A simple "verify by phone, no exceptions" rule, applied every time, costs nothing and closes the door on the most expensive scam small businesses currently face. If you'd like us to look at your current payment process and email security setup ahead of Scams Awareness Week, get in touch — Computer Mechanics has been helping Perth businesses stay a step ahead of scammers since 1997.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 25+ years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With more than 25 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
17 August 2026
5 min read
Scams
Cybersecurity
Business Email Compromise
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

A Phishing Link at a Perth Medical Practice Becomes an Account Takeover

A representative walkthrough of how we respond when a staff member at a Perth medical practice is phished and their Microsoft 365 account is taken over — contain, assess breach exposure, and harden patient data. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

A Perth Business's Server Dies — and the Backup Hadn't Run in Weeks

A representative walkthrough of how we recover a Perth business after a server failure — and what we do when the backup everyone trusted had silently stopped running. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond
Cybersecurity
Business Email Compromise

A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/14/2026
Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore
Cybersecurity
AI

Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore

AI can now clone a voice from seconds of audio, and businesses are losing millions to fake 'CEO' calls. Here's how deepfake scams work, why Perth SMBs are targets, and the simple process that stops them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
7/13/2026
Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
Call us