ACTL
All Respond topics

Business Scams (BEC, Invoice Fraud)

Small and medium businesses are targeted with fake invoices, intercepted email threads, fake supplier-change notices, and CEO impersonation. If customer or staff data is exposed, the Notifiable Data Breaches (NDB) scheme may also apply.

Common patterns

  • Fake invoices that look like a real supplier's
  • Business Email Compromise (BEC) — attacker takes over a mailbox and changes payment details
  • Payroll diversion — fake email from an 'employee' asking to update bank details
  • Ransomware demanding payment to decrypt files
  • Fake supplier change-of-bank notices
  • Director / executive impersonation requesting urgent transfers

Immediate actions

  1. Pause all outgoing payments to affected suppliers.
  2. Call the bank and ask them to recall and freeze the transfer.
  3. Reset passwords across email and finance systems; enable MFA.
  4. Preserve all evidence (emails, headers, payment records).
  5. Notify internally — owner, finance, IT.
  6. Assess whether customer or staff personal data may have been exposed.

Where to report (business)

SituationReport to
Cyber incidentReportCyber (cyber.gov.au/report)
Financial misconductASIC
General scamScamwatch (ACCC)
Fraud, blackmail, theftPolice
Personal data breachOAIC — Notifiable Data Breaches scheme

Notifiable Data Breaches (NDB) — the basics

If personal information is exposed and is likely to cause serious harm, you must notify both the affected individuals and the Office of the Australian Information Commissioner (OAIC). You have 30 days from awareness to assess and must notify promptly after that. The scheme applies to Australian Government agencies, businesses with turnover above $3M, and certain health, credit and TFN handlers.

Report and resources

Prevention checklist (top 5)

  • Train staff to recognise phishing and BEC patterns.
  • Enable MFA on all email, banking and finance systems.
  • Verify any change to invoice or supplier bank details by phone using a number you already have.
  • Run an annual cyber security review covering backups and access.
  • Tighten internal approval steps for any unusual payment.

Standard reporting contacts

WhereWhat forHow to contact
BankRecall or freeze a transferNumber on the back of your card
ScamwatchReport a scam, statisticsscamwatch.gov.au/report-a-scam
ReportCyberCyber crimecyber.gov.au/report
PoliceCriminal offences, threats000 (emergency) / 131 444 (non-urgent)
IDCAREFree identity theft support1800 595 160
TIS interpreterInterpreter when English is difficult131 450

All Respond topics