Guide · Scams & security
How to check a supplier invoice before you pay it
Warning signs of payment redirection scams, a five-step check before paying, a bank-details policy to copy, and what to do straight away if you've paid.

The invoice looks right. It has the supplier’s logo, the usual line items, and it arrived in the same email thread you’ve used for months. The only difference is a short note saying the bank details have changed. Scamwatch calls this business email compromise, or payment redirection: “a scammer pretends to be a business or person you know via email and asks you to pay money to an account they control.”
The National Anti-Scam Centre’s Targeting Scams report, published in March 2026, puts combined reported losses to payment redirection scams at $166.8 million in 2025, up 9.3% from $152.6 million in 2024, and second only to investment scams. Among small businesses reporting to Scamwatch, false billing was the most reported scam type, and the report says false billing reports from business “generally relate to ‘payment redirections’ also known as ‘business email compromise’ scams”.
The warning signs
Scamwatch lists these signals:
- Changed bank details. A supplier’s payment details change without notice, or an invoice you were expecting arrives “with altered payee and contact details”.
- An address that is nearly right. Scammers “will sometimes add one extra letter or number to the email address”, or change the website slightly.
- Bills you didn’t expect. An invoice for goods or services nobody ordered.
- Urgency and secrecy. Scamwatch’s small business guidance says emails impersonating the boss to request a transfer create “a sense of urgency and secrecy”. A request to pay quickly and keep it quiet is a reason to slow down.
The hard part is that the email can come from a genuine, compromised address. In a case study Scamwatch has published, based on real reports, a business lost $190,000 after its supplier’s email was hacked; in the victim’s words, “the change in bank details was the only sign that this was a scam”. On our reading, that makes the change of bank details the trigger for a check, whoever appears to have sent it.
Five checks before you pay
- Call the supplier on a number you already hold. Use your accounts system, a past paid invoice or the supplier’s official website. Scamwatch says to contact the business “using a number you have sourced independently”. Westpac’s advice is to “call the payee and verify any account changes verbally.” Don’t reply to the email to confirm; if the account is compromised, the scammer answers.
- Look closely at the sender’s address. Compare it character by character with earlier emails. A clean address doesn’t clear the email; a lookalike one is a clear red flag.
- Match it to the paperwork. Scamwatch’s small business guidance says to check “goods or services were ordered and received and confirm banking details are correct prior to making payment.” Compare amount, ABN, numbering and bank details with the purchase order and the supplier’s past invoices.
- Get a second person to approve new or changed bank details. Scamwatch suggests considering “a multi-person approval process for transactions over a certain dollar threshold”. On our reading, the same check suits any change of bank details. Ask your bank whether your business banking can require two people to authorise a new payee or a payment.
- Read the Confirmation of Payee result. At participating banks, paying to a BSB and account number now triggers a name check before the money leaves (see below). A no match on a supplier you’ve paid for years is a reason to stop and call.
What Confirmation of Payee does and doesn’t do
Confirmation of Payee is an industry-wide name check run by Australian Payments Plus. The Australian Banking Association says it began rolling out in July 2025, starting with CommBank, NAB, ANZ, Westpac, HSBC and Macquarie. In July 2026 Australian Payments Plus said it was live with more than 100 financial institutions and had been used more than 150 million times.
What it does. When you enter a BSB, account number and payee name for the first time, or edit an existing payee, the receiving bank checks the name against its records and returns a result such as match, close match or no match. When the account you’re paying belongs to a business or government organisation, Australian Payments Plus says the account name is shown to you whether or not it matches.
What it doesn’t do. It “will never stop you from completing a payment”, in Australian Payments Plus’s words. The ABA calls it “an advisory checkpoint, not a hard block”, and says that if you proceed after a warning and the money goes to the wrong place, “authorising a transfer to the wrong account is usually at the customer’s risk”. It covers Australian payments to a BSB and account number, not international transfers. A legitimate supplier can also return a close match or no match if its account name differs from its trading name, a situation Australian Payments Plus specifically flags for businesses. On our reading, a mismatch means pick up the phone, not pay anyway. Check with your bank whether the check also runs on bulk or batch payment files uploaded from your accounting software.
A simple policy for your team
Write the rule down so nobody makes a judgement call under pressure. The paragraph below is an illustrative template; adapt it to your business.
Template: Supplier bank details change policy. We never change a supplier’s bank details, or pay to new bank details, on the strength of an email, letter, text or invoice alone. Any request to change bank details is verified by phone with a known contact at the supplier, using a number already in our records or on the supplier’s official website, never the number in the request. The person who verifies it records the date, who they spoke to and the number called. A second person [name/role] must approve the change in our accounting and banking systems before any payment is made to the new account. Any payment to new or changed details over $[amount] also needs [owner/manager] approval. Anyone pressured to skip these steps should tell [owner/manager]; nobody is criticised for delaying a payment to check it.
If you’ve already paid
Time matters. On our reading, work in this order:
- Call your bank now. Scamwatch says to contact your bank “immediately” to report it and stop transactions. Use the number on your bank’s website or card.
- Report it. Make a police report through ReportCyber at cyber.gov.au/report-and-recover/report, which Scamwatch links to for cybercrime victims, and report to Scamwatch at scamwatch.gov.au/report-a-scam to help warn others. The Australian Cyber Security Hotline is 1300 292 371.
- Tell the supplier. Use a number you trust. Their email may be compromised and other customers may be receiving the same invoice.
- Change your passwords for banking, email and other business accounts, as Scamwatch advises.
- Contact IDCARE on 1800 595 160 if personal or business details were exposed. IDCARE also runs the free Small Business Cyber Resilience Service for businesses with 19 or fewer full-time equivalent employees (not counting the owner), registered in Australia, actively trading and with a valid ABN.
Don’t be the business that gets impersonated
If your own mailbox is taken over, your customers get your invoices with someone else’s bank details. According to the Australian Signals Directorate, as reported by business.gov.au, email compromise was the most reported cybercrime for businesses in ASD’s Annual Cyber Threat Report 2023–24, and the vast majority of the email compromise incidents ASD responded to involved compromised accounts or credentials, often stolen by information stealer malware. Our recent alert on an ATO-themed scam email carrying malware is a current example of how attackers try to get onto business computers.
ASD’s advice to small businesses is to check your email settings, turn on multi-factor authentication, turn on email content filtering and train staff to recognise suspicious email. The government’s cyber security checklist adds unique passphrases, prompt software updates, antivirus and giving staff access only to the systems they need. ASD’s Australian Cyber Security Centre also publishes detailed guidance on preventing business email compromise.
Checklist
- Treat changed bank details as a stop sign. Don’t pay to new details until they’ve been checked, whoever appears to have sent the request.
- Call on a number you already hold. Never use the phone number, link or reply address in the email.
- Compare the invoice with the paperwork. Check it against the purchase order, delivery record and past invoices.
- Require two people for new or changed payee details. Ask your bank whether your business banking can enforce two-person authorisation.
- Read the Confirmation of Payee result. A close match or no match on a known supplier means call before you pay.
- Put the policy in writing. Write a bank-details rule (our guide includes a template) and tell every staff member who can make payments.
- Know the immediate steps. Bank first, then ReportCyber and Scamwatch, then the supplier, then passwords and IDCARE.
- Lock down your own email. Turn on multi-factor authentication for every mailbox and review email settings.
Tick items as you go. Your ticks stay in this browser.
Sources 16 sources
- National Anti-Scam Centre: Targeting scams – Report of the National Anti-Scam Centre on scams data and activity 2025 (March 2026)
- Scamwatch: Business email compromise scams
- Scamwatch: Protect your small business from scams
- Scamwatch: Small business scams guidance (PDF)
- Scamwatch: Business email compromise – our business lost $190 000 when our supplier's email was hacked
- Scamwatch: Protect your small business from invoice email scams (2016 alert)
- Scamwatch: Report a scam
- Australian Banking Association: Confirmation of Payee
- Australian Payments Plus: Confirmation of Payee
- Australian Payments Plus: Businesses come on board as Confirmation of Payee enters its second year (8 July 2026)
- CommBank: Strengthening scam protection – Introducing Confirmation of Payee
- Westpac: Protect your business
- business.gov.au: Email security is not set and forget
- business.gov.au: Cyber security checklist
- Cyber.gov.au: Report (ReportCyber)
- Cyber.gov.au: Preventing business email compromise

