SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
No one's just a number: the finance-team blind spot behind Australia's rising payment scams

No one's just a number: the finance-team blind spot behind Australia's rising payment scams

Mon, 24th Aug 2026 (Today)
Phillip Vella
PHILLIP VELLA Director of Sales & Partnerships ProSpend

Every Scams Awareness Week the headline figure lands and we all wince. Australians reported $2.18 billion in scam losses in 2025, up 7.8% on the year before (National Anti-Scam Centre, Targeting Scams Report 2025). This year's theme, "No one's just a number," is a useful correction, because behind that figure are people , and a surprising number of them work in finance teams.

The scam that should worry finance teams most rarely makes the news. It is payment redirection, sometimes called business email compromise. It cost Australians $166.8 million in 2025, up 9.3%, at a time when most other scam categories were falling (National Anti-Scam Centre, 2025). It is one of the few still climbing.

What makes it so effective is that it doesn't break anything. A supplier's bank details appear to change - usually by email, sometimes on an invoice that looks entirely ordinary ; and a genuine payment for genuine goods goes out on time, to an account controlled by someone else. No system failed. No login was hacked. The only thing that failed was a verification step that never happened.

Fraudulent emails are getting harder to catch. Generative AI now writes them without the old mistakes that used to be obvious giveaways: no typos, no clumsy phrasing, often referencing a real project or a genuine earlier exchange. The Australian Signals Directorate found that roughly one in three business cybercrime reports starts with a compromised or spoofed email (ASD Annual Cyber Threat Report 2024-25), which is exactly how payment redirection gets in. Spotting a fake by eye is no longer a reliable defence, which is precisely why the defence has to move into a business process.

The problem gets harder as you grow

When a business is small, this risk is easier to manage, because only a couple of key people are across every payment that goes out. Ten years ago, when it was just our founder and I at ProSpend, we were both across every invoice that needed paying - there weren't that many, but that doesn't last. As a business grows, so does their invoice volume. Invoices arrive from suppliers no one on the finance team has met, for departments they don't sit in, approved by people they may never speak to. Somewhere in that flow, a bank account quietly changes.

We spend a lot of time with mid-sized finance teams, and the pattern is consistent. Many are onboarding dozens or hundreds of new suppliers a month. A striking number still confirm bank details verbally, or simply key in whatever appears on the invoice, because they have no reliable way to check. Their external auditors have begun flagging the absence of ABN and bank-account verification as a genuine control gap. And when we ask what actually keeps them up at night, it is rarely their own staff. It is a supplier changing bank details without telling them,  or a change request that was intercepted and altered before it reached them.

The risk doesn't end at approval, either. In many teams there is a gap of days between a payment being approved and the file actually leaving for the bank, and the traditional payment file is an editable text document. A bank account can change in that window, and the first anyone hears of it is weeks later, when the real supplier asks where their money is, and there's no audit history in that text file.

Where the control belongs

The reassuring part is that the most effective defenses are neither expensive nor new. They are processes.

The first is a rule: never act on a change of bank details from an email alone. Confirm it through a second channel - a phone call to a number you already hold, not the one on the message. The second is verification at onboarding and at payment: an ABN and trading-status check, and Confirmation of Payee, which matches the account name to the BSB and account number. It is the same check your own bank now runs when you pay someone new. The third is separation of duties, so the person who approves a payment isn't the person who releases it. And underpinning all of it, an audit trail, so every change is traceable.

The teams handling this well have stopped relying on eyes and memory. They have built the check into how a payment gets approved, so a changed bank account surfaces automatically - before the money moves, not after it bounces back.

Often the control is one a team already has and simply hasn't switched on. At ProSpend, one that can be turned on today compares the bank details on an incoming invoice against the supplier record already held, and flags any mismatch before the payment is approved. It won't stop every scam, and no honest provider should claim otherwise. What it does is force a pause at the one moment that matters - when the details don't line up.

That pause is where this year's theme earns its keep. "No one's just a number" is a reminder that the accounts payable officer who stops a suspicious payment isn't being difficult. They are protecting colleagues, suppliers and the business. The organisations getting this right are the ones that treat verification as everyone's job, and the system's job - not the private burden of one person having a good day.

Scams Awareness Week is a prompt worth acting on. If it moves your team to make one change, make it this: no payment, and no change of bank details, on an email alone. It costs nothing. And it closes the gap that payment redirection depends on.