Payment Fraud Risk Check
Seven questions about how payments get approved in your business. Takes two minutes. No documents needed.
QUESTION 1 OF 7
A supplier emails to say their bank details have changed. What happens next?
Want to go through your results with us?
Book a free callThe scam this check is built around
Payment redirection fraud does not look like fraud. It looks like a supplier letting you know their bank details have changed, or an email from the boss asking for an urgent payment while they are travelling. The document is real or close to it, the sender name is right, and the request is the kind of thing that happens legitimately all the time. That is the whole trick. The scam borrows the shape of a routine task and relies on a busy person completing it routinely.
The Australian Federal Police have warned that criminals are targeting the construction sector specifically. Construction is attractive for the same reasons it is hard to run: large invoices, long chains of subcontractors, progress payments on deadlines, and small admin teams. Scamwatch put business losses to payment redirection at $152.6 million in 2024, up 66 per cent on the year before. Individual hits are commonly five or six figures, and because the money is moved on within hours, recovery is rare.
The check on this page scores the seven process points these scams travel through: how bank detail changes are confirmed, whether one person can add and pay a supplier alone, where your bank details come from, whether the pay run gets reviewed, what happens when an urgent instruction arrives from the boss, whether every mailbox has multi-factor authentication, and whether anything suspicious has already turned up. Each one is a door. The score tells you how many of yours are open.
The callback rule
The strongest single control is also the cheapest. When a supplier's bank details change, ring them on a number you already had on file, from before the change request arrived. Never confirm by replying to the email, because if the supplier's account is compromised, the scammer answers the reply. And never ring a number printed on the invoice or email that requested the change, because the scammer chose what to print there.
Why one person paying alone is the biggest door
Every version of this scam needs a payment to be created and released. When one person can add a new supplier and pay them without a second set of eyes, a single convincing email is enough. Splitting those duties, so the person who enters a supplier is never the person who approves the payment, means the scam has to fool two people instead of one, on the same transaction, at the same time.
What is payment redirection fraud?
Payment redirection fraud, also called business email compromise or BEC, is a scam where a criminal impersonates a supplier, an executive, or a business contact by email to redirect a legitimate payment into their own account. The two most common forms are a fake bank detail change on a real supplier relationship, and a spoofed email from the business owner instructing staff to pay a new supplier.
How much do Australian businesses lose to these scams?
Scamwatch reported $152.6 million lost to payment redirection scams by Australian businesses in 2024, up 66 per cent on the $91.6 million reported in 2023. These figures only capture what gets reported.
What is the single best protection?
Two free controls do most of the work: the callback rule for bank detail changes, and multi-factor authentication on every email account in the business, not just the owner's. MFA blocks most of the account break-ins these scams start from. Neither costs anything, and both can be in place within a week.
See how Pulsify checks every invoice automatically →One call, and you'll know what to fix first
We'll walk through what you scored, what to change first, and which parts Pulsify can take off your hands. Some of it you'll want to fix yourself and we'll tell you which.