Business Email Compromise in Australia: How to Spot, Prevent and Respond to BEC
August 19, 2026by Levit8 IT Solutions
Business Email Compromise (BEC) is a targeted scam that turns trusted business communication into an opportunity for fraud. Instead of relying on malware or obvious technical attacks, BEC often uses impersonation or compromised email accounts to redirect payments, change bank details or obtain sensitive information.
For Australian businesses, the risk is particularly relevant wherever supplier payments, invoices and financial approvals are handled through email. This guide explains how BEC attacks work, the warning signs to watch for, and the practical controls that can help prevent a convincing email from becoming a financial loss.
LEVIT8’S PERSPECTIVE
BEC is as much a business-process risk as it is a technical security problem. You can have strong email security in place and still lose money if a convincing payment request bypasses the way your team normally verifies changes.
That’s why we look at BEC protection across three areas: securing accounts, recognising suspicious activity, and making sure sensitive requests are independently verified before anyone acts on them. These controls also form part of the broader cyber security foundations small businesses should have in place.
What Is Business Email Compromise (BEC)?
Business Email Compromise (BEC) is a targeted scam where an attacker uses a real or convincingly faked business email identity to manipulate someone into making a fraudulent payment, changing payment details or disclosing sensitive information.
Unlike broad phishing campaigns, BEC is targeted. Attackers research a business, its suppliers and its staff, then craft a request that looks like it belongs inside a normal business process.
There are two main ways attackers pull this off. The first is impersonation, where they spoof a display name or use a lookalike domain to appear as a trusted contact. The second, and more dangerous, is account compromise, where the attacker gains actual access to a real mailbox.
When a real mailbox is compromised, the emails come from a genuine, previously trusted address. There’s no spoofed domain to spot and no obvious red flag in the sender field, which is why BEC can be so difficult to catch through observation alone.
Business Email Compromise vs Phishing
Phishing often tries to trick people into clicking a malicious link, entering credentials on a fake page or opening a harmful attachment. Some phishing campaigns are broad, while others are highly targeted.
BEC is typically more focused on impersonating a trusted business contact or using a compromised account to manipulate a legitimate process, such as a supplier payment or bank-detail change. Phishing can also be the entry point to BEC if stolen credentials give an attacker access to a real mailbox.
How Business Email Compromise Happens
Business email compromise attacks can take different forms, but they usually exploit the same thing: trust in an existing business relationship or process. An attacker may research the organisation, impersonate a trusted contact or gain access to a real mailbox, then wait for the right opportunity to intervene.
Here are three common ways that can play out in practice.
Supplier and Invoice Fraud
A business has an established, ongoing relationship with a supplier and pays them regularly. The attacker either compromises the supplier’s mailbox or impersonates their domain closely enough to pass a quick glance.
An email arrives advising that the supplier’s bank details have changed. It looks routine, references a real invoice, and comes at a plausible time. The accounts team updates the details and pays the next invoice straight into the attacker’s account.
CEO or Executive Impersonation
The attacker impersonates a senior figure in the business, often the CEO or a finance director. The message requests an urgent payment or sensitive information, and frames it as confidential or time-critical.
The tone is designed to discourage questions and make the request feel too urgent or sensitive to challenge. An employee may feel pressured to act quickly and bypass the usual approval process because the instruction appears to come from someone with authority.
Compromised Email Accounts
In this scenario, the attacker has already gained access to a real business mailbox, often through a prior phishing attack or credential leak. Rather than acting immediately, they sit quietly and read the conversation history.
They watch for an upcoming invoice, contract or payment, then intervene at exactly the right moment, either replying within the existing email thread or sending a follow-up that fits seamlessly with what’s already been discussed.
Warning Signs of a BEC Scam
BEC can be difficult to spot because the request is often designed to fit into normal business communication. Warning signs can include:
- An unexpected change to a supplier’s bank or payment details
- Payment instructions that differ from the business’s usual process
- Requests to keep a transaction confidential or act urgently
- Pressure to bypass normal approval steps
- Subtle changes to a sender’s domain or display name
- Unexpected new instructions appearing inside an existing email thread
- Unusual login activity or account alerts on a mailbox
A BEC email doesn’t have to look suspicious. If a real mailbox has been compromised, the message can come from a legitimate address and appear naturally within a conversation your team is already having.
That’s why checking whether an email “looks dodgy” isn’t enough. Unusual payment or account requests should be verified through a trusted process, while unexpected sign-ins or account activity should be investigated through your Microsoft 365 security alerts rather than ignored.
How to Prevent Business Email Compromise
Preventing business email compromise takes more than one security tool. The strongest approach combines secure accounts and email systems with staff awareness and clear processes for verifying sensitive requests.
Secure Email Accounts and Microsoft 365
Securing Microsoft 365 accounts makes one common path into BEC harder to exploit. Multi-factor authentication (MFA), suspicious sign-in monitoring and anti-phishing controls can all reduce the chance that stolen credentials turn into ongoing mailbox access.
MFA can significantly reduce the risk of account takeover, but it doesn’t prevent every BEC attack. Impersonation, spoofing and other social-engineering tactics can still target staff without compromising their login credentials, so MFA should be treated as one layer of protection rather than the whole solution.
For practical guidance on strengthening account access, see our guide to multi-factor authentication.
Verify Payment and Bank Detail Changes
Independent payment verification is one of the most practical ways to stop a convincing BEC attempt from becoming a financial loss. If a supplier, client or colleague emails to say their bank details have changed, don’t confirm the request by replying to the same email or calling a number provided in the message.
If the mailbox has been compromised, replying simply sends your question straight to the attacker, who will happily confirm their own fraudulent request. Instead, contact the supplier using a phone number or contact method your business already has on file, independent of anything in that email. This aligns with Australian Government guidance for protecting businesses against BEC.
For anything involving a meaningful sum, add a second layer: require a colleague to independently confirm the change before payment goes ahead. Any request that pushes you to skip this step, especially under time pressure, deserves extra scrutiny rather than less.
Train Staff Around Real BEC Scenarios
General security awareness training is more useful when it reflects the situations staff may actually encounter. Finance, accounts payable, executive support and supplier-facing teams should know how to handle changed bank details, unusual payment requests and instructions that appear to come from senior staff.
Walking through realistic BEC scenarios gives employees a clear process to follow instead of relying on a generic “watch out for scams” reminder.
What to Do If You Suspect Business Email Compromise
If you suspect a BEC attack is underway or a fraudulent payment has already been made, acting quickly can limit further damage and improve the chance of recovering funds. The immediate priorities are:
- Stop or delay any pending payment connected to the suspicious request.
- Contact your bank immediately if a payment has already been made, since fast action improves the chance of recovery.
- Secure the affected mailbox, including resetting passwords and reviewing MFA settings.
- Preserve the relevant emails, logs and any other evidence rather than deleting them.
- Investigate whether the compromise extends to other accounts or systems.
- Notify anyone else affected, including the impersonated supplier or colleague.
- Report the incident through ReportCyber and follow any other reporting obligations that apply to your situation.
These steps focus on the immediate BEC-specific response. If a mailbox or other system has been compromised, broader containment, investigation and recovery may also be required. Our cyber security incident response guide explains that process in more detail.
Protecting Your Business Against BEC
Protecting against BEC means reducing both the technical opportunity for an attacker and the chance that a fraudulent request succeeds. That means securing identities and email accounts while giving staff clear processes for verifying payments, account changes and unusual requests.
For businesses without dedicated internal security resources, ongoing monitoring can also help identify suspicious account activity before it develops into a larger incident. Levit8’s cyber security services can help assess these risks, while managed cybersecurity services provide ongoing protection and monitoring across your environment.
If you’re unsure where the gaps are, Levit8 can help review your current email and identity security controls and identify practical areas to strengthen.
Talk to Our Cyber Security Team
Frequently Asked Questions
Does MFA prevent business email compromise?
MFA significantly reduces the risk of account takeover, which closes off one common path into a BEC attack. However, it can’t prevent every scenario because impersonation, spoofing and social engineering can still succeed without an attacker gaining access to an account.
Can a BEC email come from a legitimate email address?
Yes. If an attacker compromises a real mailbox, their messages can come from a genuine, previously trusted address and appear inside an existing conversation. That’s why unusual payment or account requests should be independently verified even when the email itself looks legitimate.
What should you do if a supplier changes their bank details?
Verify the change through a contact method your business already trusts rather than replying to the email or using new contact details provided in the request. For significant payments, consider requiring a second person to independently approve the change before funds are transferred.
Author
Levit8 IT Solutions
Levit8 is a leading Australian managed IT services provider, helping businesses across industries improve performance, boost security, and scale confidently through smart, reliable technology. With a passion for efficiency, security, and client success, our local team delivers expert support, enterprise-grade solutions, and a no-nonsense approach to IT. We empower small and mid-sized businesses with future-proof systems, robust cybersecurity, and seamless support—so technology becomes an asset, not a headache.

