One Unified Platform for spend management and proactive control

Expense Manager

AP Manager

Business Payment Scams Australia: What Finance Teams Should Check to Protect Their Business

Learn how Australian finance teams can prevent business payment scams, payment redirection and invoice fraud with stronger controls

Author Trieu Doan
Read time 8 minutes
Published Aug 24, 2026
Last updated Aug 24, 2026

TL;DR

Business payment scams Australia-wide are putting finance teams under increasing pressure, particularly through payment redirection, business email compromise and false billing. This guide explains the controls CFOs, Finance Managers and AP teams should review to reduce payment risk.

What are business payment scams?

Business payment scams are scams where criminals deceive an organisation into sending money to the wrong person, account or supplier. Common examples include payment redirection, business email compromise (BEC), false billing and impersonation of suppliers or executives.

The key risk for finance teams is simple: a legitimate payment can look completely normal right up until the bank details change.

That makes payment verification, rather than simply spotting suspicious emails, an important part of your control environment.

Scam vs Fraud: Why the Difference Matters

The terms are often used interchangeably, but there is a useful distinction for finance teams.

A scam is external deception designed to trick your business into making a payment or handing over information.

Fraud is broader. It can include external scams as well as internal risks such as duplicate payments, manipulated invoices, inflated expense claims or abuse of weak controls.

The important point is that many of the controls overlap.

Supplier verification, separation of duties, approval thresholds, duplicate detection and audit trails can help protect against both external scams and broader fraud risks.

Why Business Payment Scams Matter to Finance Teams

Scams are not just an IT problem. For finance teams, they can become a direct accounts payable and payment-control risk.

The National Anti-Scam Centre's Targeting Scams Report 2025 recorded $2.18 billion in reported scam losses in Australia during 2025, up 7.8% on 2024. Payment redirection accounted for $166.8 million, up 9.3% from $152.6 million in 2024. It was one of the few top-five scam categories to increase year-on-year.

For small businesses, false billing was the most frequently reported scam type in the 2025 reporting data.

The Australian Signals Directorate's Annual Cyber Threat Report 2024–25 also found that email compromise without financial loss represented 19% of business cybercrime reports, while BEC fraud resulting in financial loss represented 15%. Together, these categories accounted for roughly one-third of reported business cybercrime.

For finance leaders, the message is clear: payment controls need to assume that a convincing request can still be fraudulent.

How Business Payment Scams Work

Payment redirection scams often follow a straightforward pattern.

Step 1 — A legitimate payment is identified

A criminal identifies a genuine supplier, invoice, project or payment that is already in progress.

The target could be a construction supplier, professional services provider, landlord or other regular vendor.

Step 2 — The communication is manipulated

The criminal may compromise an email account or imitate a legitimate sender.

They then send a request that appears routine, often claiming that the supplier's bank account has changed.

The request may contain genuine project details or reference previous correspondence, making it harder to recognise as suspicious.

Step 3 — The bank details change

The invoice or payment request looks legitimate, but the BSB and account number point to an account controlled by the criminal.

This is where a strong verification process matters.

Step 4 — The payment is approved

If the change passes through the normal workflow without an independent check, the payment can be released.

By this point, the finance team may have followed every normal payment step — except the one that matters most: verifying the changed bank details.

What Finance Teams Should Be Checking

A strong defence does not rely on one control. It combines people, process and technology.

1. Treat Bank-Detail Changes as High Risk

A bank-account change should never be treated like an ordinary invoice update.

Your process should require an independent verification before the new details are used.

The simplest rule is also one of the most important:

Never change payment details based on an email alone.

Call the supplier using a phone number already held in your records. Do not use the number supplied in the bank-detail-change email.

2. Check Supplier Details

For new suppliers, verify more than the invoice.

Finance teams can check:

  • ABN and supplier details
  • Official contact information
  • Existing supplier records
  • Bank account information already held in the system
  • Whether the request is consistent with previous supplier activity

Supplier and ABN verification, including ABR cross-checks, are identified in ProSpend's existing fraud-control material as part of a broader control framework.

3. Separate Approval From Payment

The person who approves a payment should not automatically be the person who releases it.

Separation of duties creates another opportunity to identify an unusual request before money moves.

For higher-value payments, consider a second approval threshold.

4. Look for Duplicate or Unusual Invoices

Not every fraud attempt involves a changed bank account.

Finance teams should also look for:

  • Duplicate invoices
  • Unusual invoice values
  • Unexpected suppliers
  • Changes in supplier behaviour
  • Unusual payment timing
  • Invoice details that do not match established records

These controls help address broader fraud risks as well as external scams.

5. Keep a Complete Audit Trail

Every supplier change, approval and verification should be traceable.

A good audit trail helps your team understand:

  • Who requested the change
  • Who verified it
  • Who approved the payment
  • When the change occurred
  • What information was checked
  • Who released the payment

It also gives finance leaders a clearer view of where controls are working and where gaps remain.

Where Technology Can Strengthen Payment Controls

Technology should support good financial controls, not replace them.

For example, ProSpend's Bank Account Validation feature can check the bank details on an invoice against the bank details held in the system. This gives finance teams another validation point before payment and can help identify a mismatch that deserves further investigation.

That is particularly useful when the invoice itself looks legitimate.

The important distinction is that technology does not make a business fraud-proof. As the Scams Awareness Week content package notes, automation should be viewed as strengthening the controls that help teams identify suspicious invoices, unauthorised changes and processing errors before payment.

The strongest approach is layered:

People → know when to stop and question an unusual request
Process → require independent verification and appropriate approvals
Technology → validate information and flag exceptions before payment

A Practical Payment Scam Control Review

Use Scams Awareness Week as a reason to test your current controls.

Ask your finance team:

  • Do we verify every supplier bank-detail change independently?
  • Do we call a number already held in our records rather than one supplied in an email?
  • Is approval separated from payment release?
  • Do higher-value payments require additional approval?
  • Do we verify new suppliers and their ABN details?
  • Can our system identify duplicate invoices?
  • Can we identify unusual supplier or payment activity?
  • Do we maintain an audit trail for supplier and bank-detail changes?
  • Can our AP technology validate invoice bank details against existing records?
  • Do staff feel empowered to pause a payment when something does not look right?

If several answers are "no", the issue is not necessarily that your team needs more software. Start by defining the control you want, then look at where technology can make that control easier to apply consistently.

FAQs

What are the most common business payment scams in Australia?

Payment redirection, business email compromise and false billing are key risks for Australian businesses. The National Anti-Scam Centre reported $166.8 million in payment-redirection losses during 2025, up 9.3% on 2024.

How can finance teams prevent payment redirection scams?

The most important control is to independently verify any bank-detail change before making a payment. Use a contact number already held by your organisation, separate payment approval from payment release and maintain an audit trail.

Should finance teams trust supplier bank-detail-change emails?

No bank-detail change should be accepted on the basis of an email alone. Even when an email appears genuine, verify the change through a separate communication channel before updating supplier records.

What is Bank Account Validation?

Bank Account Validation is a control that checks bank details provided on an invoice against the bank details already held in the system. A mismatch gives the finance team an opportunity to investigate before payment is released.

Can AP automation prevent invoice fraud?

AP automation can strengthen financial controls, but it cannot guarantee that fraud will never occur. Controls such as supplier verification, duplicate detection, bank-detail validation, approval workflows and audit trails help finance teams identify risks before payment.

Is payment redirection the same as business email compromise?

They are closely related. Payment redirection involves tricking a business into sending money to a different account, while BEC commonly involves compromising or impersonating email communications to make that redirection appear legitimate.

What should a finance team do if it suspects a payment scam?

Pause the payment where possible and follow your organisation's incident-response process. Preserve relevant emails, payment records and audit information, and escalate the incident to the appropriate internal and external authorities.

How can finance leaders build a stronger anti-scam culture?

Make verification part of the process rather than relying on individual judgement. Staff should feel comfortable pausing an urgent payment, asking questions and escalating unusual requests without feeling that they are delaying the business.

Similar posts

Get notified on new insights

Be the first to know about new expense management solution insights to build or refine your processes with the tools and knowledge of today’s industry.