Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Business Email Compromise: What It Looks Like in an Ordinary Inbox

Business email compromise doesn't look like a scam. It looks like an invoice from a supplier you already trust. Here's what to check before Scams Awareness Week.

An email arrives from a supplier you've dealt with for years. The tone is right, the invoice looks familiar, and the only thing that's changed is the bank account at the bottom. That's business email compromise, and it's one of the most common ways Australian businesses lose money, not because anyone clicked a suspicious link, but because everything looked exactly as it should.

Scams Awareness Week runs from 24 to 28 August. It's a good prompt to look at how prepared your business actually is, not how prepared you assume you are.

What Business Email Compromise Actually Is

Business email compromise happens when a scammer gains access to, or convincingly imitates, a real business email account. Instead of an obviously fake message full of spelling errors, the scammer studies how a supplier, a client, or even a colleague actually writes, then sends a request that fits naturally into an existing conversation. Most often it's a change of bank details, an urgent invoice, or a request from "the CEO" asking someone in finance to process a payment quickly and quietly.

It works because it doesn't rely on technical weaknesses. It relies on trust, routine, and the fact that most people are moving quickly through their inbox rather than checking each sender address character by character.

Why It Catches Ordinary Businesses Off Guard

Every sector has its own version of this risk. Hospitality venues juggle constant supplier and vendor communication across multiple sites, which gives a scammer plenty of legitimate-looking threads to imitate. Not-for-profits often run lean finance teams with less time to double-check every request, and donor and supporter data adds another layer worth protecting. Financial services businesses are held to a higher standard again, with clients expecting audit-ready records and proper identity and access controls at every step.

None of this means any of these businesses are doing something wrong. It means the people processing payments and approving requests are busy, and busy is exactly what business email compromise is designed to exploit.

What to Check This Week

  • Confirm any change of bank details by phone, using a number you already have on file rather than one supplied in the email.
  • Check the sender's actual email address, not just the display name, especially on anything involving money.
  • Slow down requests marked urgent or confidential. A genuine urgent request can withstand a two-minute verification call.
  • Set up a second approval step for payment changes, even in a small team, so no single person is the only check in the process.
  • Talk to your team about what this looks like in practice. Most people have never seen a real example.

How All IT Helps

We support the infrastructure and systems that sit behind email security, including identity and access controls, so the right people have the right access and changes get flagged rather than slipping through. A cybersecurity audit gives you a clear picture of where those gaps currently sit.

When something does look wrong, our team responds fast: under 3 minutes for chat and under 14 minutes for email. A suspicious request doesn't sit unanswered while someone decides what to do.

We work on monthly contracts with no lock-in, because trust should be earned continuously, not assumed because of a signed agreement.

Written by Tom Buckley, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors.


Frequently Asked Questions

Phishing usually casts a wide net and often has obvious tells. Business email compromise is targeted, well researched, and designed to look like a normal part of an existing business relationship, which makes it harder to spot.
Contact your bank immediately to attempt a recall, then report it to Scamwatch through the National Anti-Scam Centre. Acting within hours makes a real difference to the chance of recovering funds.
Not necessarily. A lot of protection comes down to process, like verification calls and second approvals, alongside properly configured identity and access controls. Start with the basics before adding tools on top.

Run Through This with Your Team Before 24 August

Scams Awareness Week is a good moment to check your email security posture before it becomes something you're dealing with after the fact. Monthly contracts, no lock-in.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →