Australia’s scam losses hit $2.18 billion in 2025, up 7.8% on the prior year. The number of reports fell. The cost per incident rose.
Payment redirection alone cost Australians $166.8 million, and the ATO notes it remains the most reported scam type by small and micro businesses. Meanwhile, the average self-reported cost of cybercrime per small business rose 14% to $56,600.
Fewer incidents. Bigger hits. That’s the trend your AP function is now sitting in front of.
The uncomfortable truth
Most invoice fraud doesn’t need sophisticated malware. It needs ten seconds of inattention from someone in accounts payable.
The scams getting through today don’t look like scams. They look like Tuesday. A supplier email with updated bank details. A familiar invoice with one line changed. A request from the managing director marked urgent. The signals are indistinguishable from normal business.
The scammer’s playbook
Knowing how the con works is the first defence. These are the four moves draining SME bank accounts every week in Australia.
1. The intercepted invoice
Scammers compromise a supplier’s email account (or yours), wait for a legitimate invoice to be sent, then resend it with one detail changed: the bank account. The PDF looks identical, the amount matches, the sender address is real.
Your AP team pays it without blinking. Because everything about the request is correct except the destination of the money.
2. The “we’ve changed banks” email
A supplier you’ve paid for years emails updated remittance details, often citing a new bank, restructure, or audit requirement. The tone matches previous correspondence because the scammer has been reading the thread for weeks.
There is no new bank. Only a mule account that will be emptied within 24 hours.
3. CEO impersonation
A spoofed email from the managing director lands with a junior finance staffer late on a Friday: an urgent payment, confidential, no time to verify. Please process today.
The words “urgent,” “sign,” “review,” “invoice,” and “payment” are among the most common phishing trigger words. They’re also indistinguishable from legitimate payment requests. That’s why this works.
4. The fake new vendor
A fraudulent supplier is onboarded with forged paperwork, often piggybacking on a real subcontractor relationship. The first invoice is small and gets paid. The second is much larger.
By the time someone questions it, the money is gone and the vendor never existed.
The common thread
Every one of these attacks succeeds at a moment of change: new bank details, new vendor, new urgency.
That’s where your controls need to live. Not in the middle of normal processing. At the edges. At the points where something is different from last time.
What practical defence looks like
The finance teams that catch these aren’t running more sophisticated anti-fraud software. They’re running simpler processes with harder gates at the right moments:
| Moment of change | Control that stops it |
|---|---|
| Supplier bank details change | Verbal verification with known contact (not the email sender) |
| New vendor onboarding | Mandatory ABN/ACN check + second-person sign-off |
| Urgent payment request from leadership | 24-hour cooling period, no exceptions |
| Invoice amount or format differs from pattern | Auto-flag for manual review before payment |
The pattern is consistent: automate what’s predictable, force a human decision at the point of change, and remove the ability for a single person to action a large payment without verification.
Real-time visibility into payment flows gives finance teams the context to spot anomalies. If you can see every bill and every payment instruction the moment it enters the system, you have a chance to catch the one that doesn’t belong. If you only review payments after they’ve been made, you’re auditing losses, not preventing them.
Fraud is getting quieter because the playbook is getting better. Your controls need to get better at exactly the same rate.








