Industry News

The Silent Threat Hiding in Your Inbox

Why Business Email Compromise Is Surging and What You Can Do About It

Email runs almost everything in modern business which is exactly why the most dangerous cyber threats are now lurking inside the tool we depend on the most.

In late 2025, the AFP reported a “concerning rise” in Business Email Compromise (BEC) scams. BEC scams involve malicious actors impersonating a business or its employees via email to redirect vendor payments to fraudulent accounts.

The National Anti-Scam Centre received close to 85,000 reports of email-based scams in 2025, with false-billing scams accounting for almost 15% of total email-based scams.  Payment redirection scams generated over $166 million in losses, an increase of more than $14 million from the year before.

While construction remains the hardest‑hit sector thanks to its high‑value invoices and complex subcontracting chains, BEC attacks are popping up in every industry. BEC now makes up 13% of all self-reported cybercrime cases in Australia, and it continues to evolve faster than many businesses and their internal IT teams can keep up.

The threat landscape has changed, but so have the tools and partners available to help you stay ahead of it.

If your cybersecurity hasn’t had a health check in a while, or if your defences still depend on staff catching fake emails, Computer One can support you and ensure you don’t become the next case study.

What Exactly Is BEC, and Why Is It Working So Well?

BEC attacks have become disturbingly polished. Fake emails are being crafted to look exactly like the real thing, and tone, formatting, internal processes, and even references to past conversations are being mirrored with eerie accuracy.

Today’s attackers don’t rely on spelling mistakes or stories about a Nigerian prince. Instead, BEC campaigns use a sophisticated sequence of hacking and social engineering techniques to convincingly pose as a trusted, and possibly allowlisted, contact.

Techniques include:

Malware that quietly steals login credentials

Many BEC attacks begin with malware delivered via a malicious link or attachment. Infostealers quietly harvest email and banking credentials, session cookies, or OAuth tokens, allowing attackers to access real accounts without raising alarms. Attackers then create hidden inbox rules to forward or delete emails containing terms like invoice or payment, hiding warnings and payment confirmations.

Real‑time inbox surveillance

After gaining access, attackers often wait, but that doesn’t mean they’re not doing damage. They monitor email traffic to understand approval workflows, invoice timing, and communication styles. By reading full threads and observing patterns, they insert themselves at precisely the right moment to make fraudulent requests appear routine rather than suspicious.

Highly targeted social engineering

BEC succeeds by exploiting trust, not technology. Attackers impersonate executives, vendors, or legal counsel using accurate language, real project details, and familiar pressure points. These low‑volume, text‑only emails lack obvious red flags, leveraging authority and urgency to push recipients into acting without verification.

Why Traditional Defences Are No Longer Enough

While your people remain the best attack vector, cybersecurity training alone can’t compete with AI‑crafted emails. A multi‑layered approach is essential today.

Talking to SmarterMSP, Stanislav Kazanov, head of big data and software development at IT consulting firm Innowise, put it best: If your security plan depends on someone spotting a typo at 4:45pm on a Friday when they’re buried in work, you’re already in trouble.” BEC is a modern threat needs a modern defence, and a capable MSP can put those protections in place long before a criminal slips through your inbox.

Real‑World Case Studies: Proof This Isn’t “Someone Else’s Problem”

1. A Small Business Nearly Loses $940,000 in One Click

A small Australian business narrowly avoided a $938,600 loss after scammers compromised a construction company’s email account and sent a nearly identical invoice with updated bank details.

Quick action allowed their bank to recover most of it. It’s a reminder that even real email accounts can be weaponised.

2. Community Club Lose $120,000 After Hackers Replace a Legit Invoice

The Upwey‑Tecoma Bowls Club in Victoria, unknowingly paid a fraudulent invoice after hackers monitored their email system, deleted the legitimate invoice, and replaced it with one containing new banking details.

The club only realised weeks later when the contractor asked where the money was. Even not‑for‑profits aren’t safe from these attacks.

3. When a Vendor Email Compromise Ends in Court

While BEC often targets employee accounts inside an organisation (like executives or finance staff), a vendor email compromise (VEC) specifically targets vendor or supplier accounts, manipulating invoices and payment details within ongoing business relationships.

Inoteq was caught in a VEC scam after attackers impersonated their contractor, Mobius Group, and supplied fake updated bank details. When Inoteq attempted to verify the change, but experienced telephone connection issues, the scammer intercepted the follow‑up email and provided a forged confirmation.

Believing it was legitimate, Inoteq paid more than $235,000 into the attacker’s account, most of which was quickly moved overseas. Only a portion was recovered, and the court ultimately ruled that Inoteq hadn’t taken sufficient steps to protect itself and was responsible for the remaining loss.

It’s Time to Treat BEC as a Strategic Risk, Not Just an IT Problem

The cyber landscape has shifted, and inboxes have become one of the busiest battlegrounds in business. A few simple changes could prevent a devastating financial loss, reputational damage, or supply-chain disruption.

If your cybersecurity hasn’t been reviewed recently, or if your organisation still relies on old systems, generic training, or traditional MFA, this is the time to bring in expert help.

So How Do You Reduce BEC Risk?

The good news is that BEC risk can be significantly reduced with a few practical steps.

Strengthening authentication

Using phishing-resistant Multi‑Factor Authentication (like passkeys or hardware tokens) adds an extra barrier if credentials ever end up in the wrong hands.

Improving email security settings

Legacy systems only detect known threats. AI‑driven attacks don’t use suspicious attachments; they use convincing tailored text.

Modern email platforms offer behaviour‑based security features that catch unusual login locations, suspicious forwarding rules, or unexpected communication patterns.

Regulate communication verification

A simple phone call to a known, trusted contact (not the number listed in an email or invoice) can stop a fraudulent transfer before it happens. Beware of easily spoofed publicly available information, such as company websites and email addresses.

Preapproved, secure channels for payment changes, vendor updates, and financial approvals remove the guesswork from “Is this real?”

Reviewing who has access to what

Ensuring that only the people who genuinely need certain permissions have them reduces the chances of attackers abusing an overlooked account.

Building a culture of slow‑down‑and‑double‑check

Encouraging teams to pause before actioning financial requests, especially urgent ones, creates valuable friction against social engineering.

Building safety nets

Mistakes will be made and links will be clicked. Good systems ensure a click isn’t catastrophic.

DNS filtering, endpoint protection, and network segregation can contain the damage before it spreads.

Implementing security frameworks like Essential Eight

This creates a layered defence that significantly reduces the impact of both opportunistic and targeted attacks. Computer One offers a range of audits and assessments to determine which framework addresses your needs.

These steps can be implemented gradually, and even small improvements go a long way in reducing exposure. While each measure can be handled in‑house, many Australian businesses find that implementation and maintenance can be time‑consuming.

You don’t need to fight this battle alone. Managed Service Providers, such as Computer One, play a central role in helping businesses stay ahead of fast‑moving threats.

Contact our security specialists via the website or call 1300 667 871 and start strengthening your defences against business email compromises today.

Other News

The Computer One logo with blue background
6 time winner of the
Channel Futures MSP 501 Winner logo white | Computer One
Local Government Procurement Approved Contractor logo | Computer One
Q-Mark ISO 9001 certified logo | Computer OneQ-Mark ISO 27001 certified logo | Computer One
© 2026 Computer One Australia.
arrow-right linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram