Business email compromise (BEC) is one of the most financially devastating cybercrimes targeting Australian businesses today. Unlike ransomware or malware attacks that rely on technical exploitation, BEC attacks exploit human psychology — and no antivirus software will save you. The Australian Cyber Security Centre estimates that BEC causes more than $80 million in losses to Australian organisations every year, and that figure understates the true cost because many incidents go unreported.
How Business Email Compromise Works
BEC attacks take several forms, but the most financially damaging ones in Australia typically follow one of two patterns:
- Invoice fraud / payment redirection — attackers intercept legitimate email communications between a business and its suppliers, or compromise one party’s email account, and substitute their own bank account details on invoices or payment instructions. The victim transfers funds to the attacker’s account believing it’s a legitimate payment.
- CEO fraud / executive impersonation — attackers impersonate a senior executive (CEO, CFO) and send urgent, authoritative-sounding requests to finance staff or employees requesting fund transfers, gift card purchases, or changes to payroll bank details.
Why BEC Is So Effective
BEC attacks succeed because they look completely legitimate. There’s no malware attachment to trigger antivirus alerts. The emails come from real-looking addresses (or sometimes actual compromised accounts). The attackers study their targets — reading months of email history to understand writing styles, business relationships, and pending transactions before striking.
The moment that makes BEC particularly devastating is that fund transfers are often irreversible by the time the fraud is discovered. International wire transfers are virtually impossible to recall. Even domestic transfers may have been moved multiple times before the theft is identified.
Who Is Most at Risk?
Any business that makes or receives significant payments is at risk, but some sectors are particularly targeted: law firms (trust account disbursements), accounting practices, real estate agencies (settlement funds), construction businesses (subcontractor and supplier payments), and importers/exporters.
How to Protect Your Business
- Implement MFA on all email accounts — the most common precursor to BEC is a compromised email account. MFA prevents attackers from accessing your email even if they have your password.
- Configure DKIM, SPF, and DMARC — these email authentication standards make it significantly harder for attackers to spoof your domain and send emails that appear to come from your business.
- Establish verbal verification procedures — for any payment instruction received by email, establish a policy of calling the requestor on a known number (not a number in the email) to confirm. This single control stops the vast majority of BEC attacks.
- Train staff to recognise red flags — urgency, secrecy, unusual requests, and last-minute bank account changes are all warning signs. Regular phishing simulation training keeps staff alert.
- Deploy advanced email security — email filtering solutions with impersonation detection can flag emails that appear to come from executives or known suppliers but fail authentication checks.
Kinsoft can implement all of these controls for your Sydney business as part of our cybersecurity services. Contact us to discuss your email security posture.