A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
14 August 2026
5 min read
Cybersecurity
Business Email Compromise
Scams
Accounting
Perth Business

This is a representative scenario, not a specific client. It's a composite of the kind of business email compromise call we handle, written to show how we work the problem and why. Real incidents vary, and the details here are deliberately general.

An accounts clerk at a Perth accounting firm gets an email that looks completely normal: a supplier they pay every month, advising that their bank details have changed, with a polite request to use the new account for this month's invoice. Nothing about it feels off — the logo is right, the wording is right, the invoice is attached. This is business email compromise (BEC), and it's the single most expensive scam hitting Australian businesses. Here's how we respond when a client spots one (or nearly pays it), and the controls that stop it happening at all.

The moment it's noticed

Sometimes the clerk pauses because the bank account is interstate when the supplier is local. Sometimes the payment has already gone out and the real supplier chases the unpaid invoice a week later. Either way, the first call to us is usually: "I think we've been scammed — or nearly." Speed now matters enormously, because with a fraudulent transfer the money is often recoverable only in the first hours.

First: stop the money, then preserve the evidence

Two things happen in parallel the moment we're engaged:

  • Stop the payment. If the transfer hasn't cleared, the firm calls their bank immediately to attempt a recall, and we help them contact the receiving bank's fraud team. Time is everything here — a same-day flag can claw funds back that a next-day one can't.
  • Preserve, don't delete. The instinct is to delete the dodgy email. We keep it — headers and all — because it tells us whether the attacker simply spoofed the supplier from outside, or is actually inside a mailbox reading real conversations. That distinction changes everything about what we do next.

How we work out what actually happened

BEC comes in two flavours, and we confirm which one we're dealing with:

  • External spoofing — the attacker never got into any account; they forged a lookalike address (a swapped letter, a .co instead of .com.au) and guessed the payment cycle. Bad, but contained.
  • A compromised mailbox — the attacker has phished a real Microsoft 365 login and is sitting inside the firm's (or the supplier's) email, reading threads and striking at exactly the right moment. This is the dangerous one, and the tell-tale sign is a hidden inbox rule silently moving the supplier's real emails to a folder so nobody notices the conversation being hijacked.

We check the Microsoft 365 audit log for suspicious sign-ins, review every mailbox rule, and confirm whether multi-factor authentication actually held. If an account was compromised, we treat it as a full account takeover — reset credentials, revoke active sessions, and hunt for anything else the attacker touched.

Closing the hole — the real fix

Recovering the payment is the emergency; making it impossible next time is the job. What we put in place:

  • Payment-change verification as policy, not judgement. Any change to a supplier's bank details must be confirmed by phone on a known number (never the number on the new invoice) before a cent moves. This one habit stops most BEC losses outright.
  • Email protection** that flags impersonation** — external-sender warnings, lookalike-domain detection, and SPF/DKIM/DMARC configured so spoofed mail is rejected rather than delivered.
  • MFA everywhere, phishing-resistant where it counts, so a stolen password alone can't open the mailbox.
  • Staff awareness aimed squarely at finance roles, because they're the target — we walk teams through exactly what these emails look like (our guide on spotting business email compromise is a good primer).

Why this was preventable

Notice what BEC relies on: not a clever hack, but a trusted process with no verification step. The attacker doesn't need to break your systems if they can convince one busy person to change a bank account. That's why the fix is mostly procedural, backed by the right email controls — and why an accounting firm, which moves money on behalf of clients, has more to protect than almost anyone. It's the reason we take a dedicated approach to IT for Perth accounting practices, where confidentiality and trust-account discipline are the whole business.

How we help

For our managed IT clients, the anti-BEC controls above are standard: hardened email, MFA, audit logging that surfaces a suspicious sign-in early, and a documented payment-verification process. And if you're reading this because something has just landed in your inbox that doesn't feel right, don't pay it and don't delete it — call us on (08) 9325 1196 or get in touch and we'll help you check it safely. We've protected Perth businesses' money and data since 1997.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 25+ years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With more than 25 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
14 August 2026
5 min read
Cybersecurity
Business Email Compromise
Scams
Accounting
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

September Patch Broke Remote Desktop on Windows Server: What Perth Businesses Must Check

September's Patch Tuesday fixed a critical, unauthenticated Remote Desktop flaw — then the same update broke RDS on Windows Server, forcing hard reboots. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Passkeys Are Now Default in Microsoft 365: What Perth Businesses Must Check

Microsoft has switched Entra ID to passkeys by default and is retiring SMS and voice sign-in codes by February 2027. Here's what Perth businesses need to check now. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Two Chrome Zero-Days in a Week, Plus a Firewall Alert: What to Check Now

Google patched two actively exploited Chrome zero-days within a week, while CISA flagged actively exploited flaws in Cisco, Citrix and Fortinet security gear. Here's what Perth businesses should check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Payment Redirection Scams Are Costing Australian Businesses Millions: A Perth Guide
Scams
Cybersecurity

Payment Redirection Scams Are Costing Australian Businesses Millions: A Perth Guide

Payment redirection and invoice scams are the most common fraud reported by Australian small businesses, with losses in the hundreds of millions. Ahead of Scams Awareness Week 2026, here's how Perth businesses can stop them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/17/2026
Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore
Cybersecurity
AI

Deepfake Voice Scams: The AI Fraud Threat Perth Businesses Can't Ignore

AI can now clone a voice from seconds of audio, and businesses are losing millions to fake 'CEO' calls. Here's how deepfake scams work, why Perth SMBs are targets, and the simple process that stops them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
7/13/2026
SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts
Cybersecurity
Scams

SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts

Reports of SIM-swap and phone port-out fraud are climbing in Australia, and the target is usually the SMS codes protecting your business banking and email. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/9/2026
Call us