What Happened?
The National Anti-Scam Centre's 2025 Targeting Scams report recorded $166.8 million in payment redirection losses across Australia in 2025, up 9.3% from $152.6 million in 2024 — one of the largest and fastest-growing scam categories it tracks.
Commentary published during Scams Awareness Week (eCommerceNews Australia, 24 August 2026) linked the rise directly to a finance-team blind spot: as businesses scale, more suppliers, invoices and payments pass through the same manual review process, and individual staff are relied on to catch a fraudulent bank-detail change on sight.
The typical attack doesn't involve a fabricated supplier or a fake invoice. Criminals impersonate a genuine, already-approved supplier — or compromise that supplier's email account outright — and present a real invoice with altered banking details. The goods or services may genuinely have been supplied and the invoice amount may be entirely correct; only the destination account has changed.
Where Was the Supplier Risk?
The risk sits at the point where supplier bank-account details are accepted or changed, not at supplier selection or invoice approval — a supplier verified properly at onboarding can still become the vector for a fraudulent payment if its banking details change afterward.
Businesses commonly hold trusted supplier records in their accounting or ERP system, but the value of that record depends entirely on the controls around how it gets updated — and a request to change bank details is frequently treated as routine account maintenance rather than a distinct risk event.
As supplier numbers and payment volumes grow, this becomes a structural gap rather than an occasional lapse: a finance employee may not personally know the supplier, know who originally engaged them, or have a reliable way to confirm that new banking information genuinely belongs to that supplier — a gap between knowing who the supplier is and knowing whether the account being paid actually belongs to them.
What Went Wrong?
The control weakness identified is reliance on email, or individual employee judgement, to validate changes to supplier payment information — a control that scales poorly as transaction volumes grow.
Modern impersonation emails can closely mirror legitimate supplier correspondence, and where a supplier's mailbox has been compromised outright, the fraudulent instruction can originate from the supplier's genuine account and appear inside an existing, ongoing email thread — removing most of the usual visual cues of fraud.
The failure isn't invoice approval — the invoice, amount and supplier can all be genuine. It's the absence of an effective, independent verification step at the one moment that actually matters: when the destination bank account changes.
What Should Businesses Do?
Treat every bank detail change as a supplier-risk event
Don't process a request to change supplier banking details as routine account maintenance — treat it as an elevated-risk event requiring re-verification before it takes effect, regardless of how legitimate the request looks.
Verify out-of-band, using details you already hold
Confirm any change using contact details independently on file — never a phone number or reply address supplied in the change request itself, which is exactly what a compromised or impersonated mailbox will provide.
Don't rely on individual judgement at scale
As supplier, invoice and payment volumes grow, informal recognition by finance staff stops being a reliable control. Build independent verification into the process as a mandatory, logged step, rather than leaving it to whoever opens the email.
Separate the request channel from the verification channel
If a change arrives by email, verify by phone; if it arrives by phone, verify through a channel the requester doesn't control. The point of verification is that the person asking for the change can't also confirm it.
The ArayaPRO Response
How ArayaPRO Helps
This is exactly the type of supplier risk ArayaPRO is built to control.
Further Reading
Sources
- National Anti-Scam Centre / Scamwatch, Targeting Scams: Report on Scams Data and Activity 2025 · Read original article →
