Scam-Safe Payment Practices: What Businesses Are Now Expected to Have in Place

21/08/2026 10:16 AM
Scam-Safe Payment Practices: What Businesses Are Now Expected to Have in Place

Scam-Safe Payment Practices: What Businesses Are Now Expected to Have in Place

Payment redirection scams — where a fraudster impersonates a legitimate supplier or intercepts an email chain to redirect a payment to their own bank account — remain one of the most financially damaging scams affecting Australian businesses. What's changed in recent years isn't just the scale of the problem, but the growing expectation that businesses have reasonable safeguards in place, both to protect themselves and to avoid inadvertently exposing their own customers to risk.

How These Scams Actually Work

The most common version involves a fraudster gaining access to (or closely mimicking) a genuine email exchange between a business and its supplier or customer, then sending a message — appearing to come from the legitimate party — advising that bank account details have changed. If the recipient updates their records and pays the new account without verifying the change through an independent channel, the funds go directly to the scammer, often with little chance of recovery once the transfer is complete.

Why This Increasingly Falls on Businesses to Prevent

Banks, regulators, and industry bodies have progressively increased expectations around businesses actively preventing these scams, rather than treating them purely as an unfortunate but unavoidable cost of doing business. This shows up in a few ways:

  • Increased scrutiny of whether a business had reasonable verification processes in place when a payment redirection scam occurs, which can affect commercial disputes over who bears the loss between the parties involved.
  • Growing expectation that businesses verify any change to payment details through a separate, independent communication channel — not simply by replying to the same email thread the change request arrived on.
  • Reputational risk, since a business whose email systems are compromised and used to defraud its own customers or suppliers faces damage to trust and relationships, beyond any direct financial loss.

What a Reasonable Verification Process Actually Looks Like

1. Never update payment details based solely on an email request. Any request to change bank account details — regardless of how legitimate the email appears — should be verified through a separate channel, ideally a phone call to a previously known, independently sourced contact number (not a number provided in the email itself, which could also be part of the fraud).

2. Establish a standard process for all payment detail changes. Rather than leaving verification to individual judgment on a case-by-case basis, have a documented internal process that requires verification before any change to a supplier's or customer's payment details is actioned.

3. Train staff specifically on recognising payment redirection attempts. Many of these scams succeed because they exploit normal business urgency (an invoice due soon, a request marked urgent) — staff trained specifically to slow down and verify in these situations are considerably less likely to fall for the scam.

4. Use multi-factor authentication and access controls on email systems. Since many of these scams begin with a compromised email account (either your own or a supplier's), securing email access reduces the risk of your systems being the point of compromise in the first place.

5. Communicate expectations to your own customers. If your business regularly invoices customers, consider explicitly communicating that you will never change payment details via email alone, and encouraging customers to verify any such request through a known phone number — this protects your customers and your business's reputation simultaneously.

What to Do If a Scam Occurs

  • Contact your bank immediately, since the chance of recovering funds is highest in the very short window immediately after a fraudulent transfer.
  • Report the incident to Scamwatch and, if relevant, the ACSC (Australian Cyber Security Centre), since these reports contribute to broader tracking and can sometimes assist in fund recovery efforts.
  • Notify the genuine supplier or customer involved, since their systems (or yours) may be compromised in a way that affects other transactions too.
  • Review whether the incident may also trigger notifiable data breach obligations, if personal or business information was accessed as part of the scam.
  • Prevention Is Considerably Cheaper Than Recovery

    Once a payment redirection scam succeeds, recovering the funds is difficult and often unsuccessful, particularly once time has passed. A documented, trained, and consistently applied verification process is a low-cost, high-value safeguard compared to the financial and reputational cost of a successful scam.

    RBizz can help review your payment verification processes and staff training to reduce your exposure to payment redirection scams — get in touch to check your current safeguards.

    Contact Us


    RBizz Team