Business Email Compromise: What It Looks Like in an Ordinary Inbox
Business email compromise doesn't look like a scam. It looks like an invoice from a supplier you already trust. Here's what to check before Scams Awareness Week.
An email arrives from a supplier you've dealt with for years. The tone is right, the invoice looks familiar, and the only thing that's changed is the bank account at the bottom. That's business email compromise, and it's one of the most common ways Australian businesses lose money, not because anyone clicked a suspicious link, but because everything looked exactly as it should.
What Business Email Compromise Actually Is
Business email compromise happens when a scammer gains access to, or convincingly imitates, a real business email account. Instead of an obviously fake message full of spelling errors, the scammer studies how a supplier, a client, or even a colleague actually writes, then sends a request that fits naturally into an existing conversation. Most often it's a change of bank details, an urgent invoice, or a request from "the CEO" asking someone in finance to process a payment quickly and quietly.
It works because it doesn't rely on technical weaknesses. It relies on trust, routine, and the fact that most people are moving quickly through their inbox rather than checking each sender address character by character.
Why It Catches Ordinary Businesses Off Guard
Every sector has its own version of this risk. Hospitality venues juggle constant supplier and vendor communication across multiple sites, which gives a scammer plenty of legitimate-looking threads to imitate. Not-for-profits often run lean finance teams with less time to double-check every request, and donor and supporter data adds another layer worth protecting. Financial services businesses are held to a higher standard again, with clients expecting audit-ready records and proper identity and access controls at every step.
None of this means any of these businesses are doing something wrong. It means the people processing payments and approving requests are busy, and busy is exactly what business email compromise is designed to exploit.
What to Check This Week
- Confirm any change of bank details by phone, using a number you already have on file rather than one supplied in the email.
- Check the sender's actual email address, not just the display name, especially on anything involving money.
- Slow down requests marked urgent or confidential. A genuine urgent request can withstand a two-minute verification call.
- Set up a second approval step for payment changes, even in a small team, so no single person is the only check in the process.
- Talk to your team about what this looks like in practice. Most people have never seen a real example.
How All IT Helps
We support the infrastructure and systems that sit behind email security, including identity and access controls, so the right people have the right access and changes get flagged rather than slipping through. A cybersecurity audit gives you a clear picture of where those gaps currently sit.
We work on monthly contracts with no lock-in, because trust should be earned continuously, not assumed because of a signed agreement.
Written by Tom Buckley, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors.
Frequently Asked Questions
Run Through This with Your Team Before 24 August
Scams Awareness Week is a good moment to check your email security posture before it becomes something you're dealing with after the fact. Monthly contracts, no lock-in.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
