A District Court ruling in Western Australia recently ordered a business to pay over $190,000 to a supplier after falling for an invoice scam — even though the business itself was the victim of the fraud. The case is a useful, if expensive, lesson in where liability actually sits when a payment goes to the wrong account.
What happened
A supplier issued a legitimate invoice for contracting work. Somewhere between issue and payment, a criminal intercepted the email thread — likely through a compromised inbox — and sent revised banking details. The paying business followed up before releasing funds, but the confirmation came back through the same compromised channel. The payment went out, and the fraud wasn’t discovered for two weeks.
Why the court sided with the supplier
The court found that a single email confirmation wasn’t sufficient verification for a change of this size. Once a business receives new bank account details for an existing supplier, the expectation is a call to a previously verified number — not a reply to the same email that raised the change in the first place. Paying without that step was treated as a failure of reasonable care, not just bad luck.
The pattern behind the ruling
This isn’t an isolated case. Invoice scams reported to Australian regulators have grown several times over in just a few years, and the mechanics are almost always the same: a compromised or spoofed email, a plausible change to payment details, and a business that verifies through the same channel the fraud arrived on.
What this means for your controls
A few practical takeaways follow directly from the ruling:
- Verify bank detail changes out-of-band. A phone call to a number you already had on file, not one supplied in the email requesting the change.
- Treat every bank detail change as a re-onboarding event. The account was verified once; a change means it needs to be verified again.
- Don’t rely on email tone or familiarity as a signal. Compromised accounts send messages that look exactly like the real thing, because they are the real thing — just no longer under the right person’s control.
- Build the verification step into your process, not into individual judgment. The business in this case did attempt to verify — the gap was in how, not whether.
Courts are increasingly treating payment verification as a standard businesses are expected to meet, not a nice-to-have. The cheapest fix is still the simplest one: confirm account changes through a channel the fraudster doesn’t control.
