How the attack unfolds
Step 1 — Get in. A phishing email leads a staff member to a fake Microsoft login page; they enter their password; the attacker now has it. No MFA means they're in. Step 2 — Watch and wait. The attacker sets up a hidden forwarding rule so they receive a copy of everything, then reads. For weeks, sometimes months. They learn who your suppliers are, who approves payments, how invoices look, when the bookkeeper pays. Step 3 — Strike. At the right moment, they send an email — from the real account, or a lookalike domain — with 'updated bank details' on a genuine-looking invoice. The bookkeeper pays it. The money is gone within hours.
Why small businesses are targeted
Small businesses have money moving, trusting relationships with suppliers, simpler approval processes, and weaker email security than corporates. The attacker's effort is the same; the odds are better.
The variations
Supplier impersonation: your supplier's account is compromised and you receive 'new bank details' from their real email. CEO fraud: an urgent email from 'the boss' asking a staff member to pay an invoice or buy gift cards. Conveyancing fraud: in real estate, the settlement deposit redirected via a compromised agent or solicitor account. Payroll diversion: a 'staff member' emails HR to change their bank details.
The warning signs
A hidden inbox rule you didn't create. Sent items you don't recognise. Colleagues receiving odd emails from you. Sign-in notifications from unexpected locations. A supplier asking why you haven't paid an invoice you thought you'd paid. Any request to change bank details, urgently, by email only.
The controls that stop it
Multi-factor authentication, enforced. Stops step 1 in most cases — a stolen password is useless without the second factor. Block external auto-forwarding. Stops step 2 — the attacker can't silently receive your mail. Conditional Access. Blocks sign-ins from countries you don't operate in. Email security with impersonation protection. Flags lookalike domains and display-name spoofing. Audit logging and alerting. So you find out about a new inbox rule or a foreign sign-in when it happens, not months later. A payment verification process. Any change to bank details is confirmed by phone, to a known number, before a cent moves. This is a business process, not a technology — and it's the last line of defence.
If it's already happened
Contact your bank immediately — recalls are sometimes possible within hours. Report to ReportCyber (cyber.gov.au) and the ACCC's Scamwatch. Change the compromised password and revoke all active sessions. Check for and delete forwarding rules. Look for what else the attacker accessed. Notify anyone whose details may have been exposed. Then get someone to close the gaps that let it happen.
TechFix Pro Managed
Find out where your business actually stands.
Free 15-minute IT health check for Sydney businesses. One workstation, your Microsoft 365 tenant, a plain-English report. No obligation.
Frequently asked questions
Is BEC covered by cyber insurance?
Often, but with conditions. Many policies require MFA and a payment verification process to be in place, and will decline claims where they weren't. Check your policy — and check that the controls it assumes are actually enforced.
We use Gmail — is this only a Microsoft problem?
No. The attack works identically against Google Workspace or any other email platform. The controls are equivalent: enforce 2-step verification, block external forwarding, alert on rule changes.
How common is this really?
It's the most reported cyber crime category by financial loss in Australia, and the ACSC has reported average losses per incident to small business well into five figures. Most small businesses know someone it's happened to.
Related articles
