By Joshua Clouston, Head of Product, ezyshield

News 8 min read

$152 Million Lost as Australia's New Payment Fraud Law Arrives in 26 Days

BEC losses jumped 66% to $152.6M in 2024. Three charged in May. Australia's Scam Prevention Framework goes live 1 July. Here's what it fixes - and what it doesn't.

Three business professionals in an office lounge discussing a printed document together, with two laptops open on the table in front of them

A Tasmanian woman received an invoice. It looked exactly right - same layout, same logo, same line items she was expecting. The only thing different was a BSB and account number. She paid. She lost $120,000. By the time she reported it, the money was gone.

That single case is not unusual. It sits inside a $152.6 million pile of losses that Business Email Compromise (BEC) racked up across Australia in 2024 - a 66 per cent jump on the year before (AFP). And as three alleged money mules were charged in Sydney last month over a $600,000 BEC haul, a new law designed to push back against this tide is 26 days from going live.

The question worth asking now: will it be enough?

What Business Email Compromise Actually Is

BEC - sometimes called payment redirection fraud - is not a complicated scam. Criminals compromise or spoof a legitimate email account, monitor correspondence, and wait for a payment moment. Then they intercept or impersonate that email chain and swap in their own bank details. The business or individual pays, believing they are settling a real invoice with a real supplier.

What makes it effective is not technical sophistication - it is timing and familiarity. The invoice looks right because it often is right, down to the exact dollar amount and project reference. The only variable that changed is where the money goes.

According to the AFP, attackers use malware to capture login credentials and set up hidden email forwarding rules that filter for keywords like “invoice” and “payment.” The victim never sees the redirect. The fraudulent invoice arrives looking completely authentic.

The Numbers: 66 Per Cent Up and Still Climbing

In 2024, BEC cost Australian businesses $152.6 million - up from $91.6 million in 2023 (AFP media release). That is not a blip. It is a structural trend.

BEC now accounts for 13 per cent of all reports to ReportCyber, placing it among the top three self-reported cybercrimes for Australian businesses. And analysts tracking the 2026 landscape flag that AI is accelerating every part of the attack chain: drafting convincing emails, impersonating voices on calls designed to validate fake payment requests, and generating deepfake video for high-value targets.

Authorised Push Payment (APP) scam losses - of which BEC is a significant category - are projected to hit AUD $1.76 billion by 2028 if current trends hold, according to ACI Worldwide and GlobalData.

The trajectory is up. The tools attackers are using are getting cheaper and better. Three seconds of audio is now enough to clone a voice with roughly 85 per cent accuracy, available for as little as $60 a month (CNN, May 2026).

The Construction Sector Is Specifically in the Crosshairs

In late 2025, the AFP issued a targeted warning: organised cybercrime groups, including offshore syndicates, are specifically targeting Australia’s construction sector.

The reason is not hard to see. Construction runs on high-value transactions, complex subcontracting chains, frequent invoicing, and - especially among smaller operators - limited dedicated finance or cybersecurity resources. A project manager approving a $338,000 invoice from a trusted subcontractor is not going to check BSB and account number against a previous payment on every occasion. Criminals know this.

The AFP documented four cases across four states:

  • New South Wales: A construction company received a spoofed invoice from a supplier’s compromised email and transferred $41,800. The company independently verified with the supplier - using a phone number they already had, not one in the email. The AFP recovered the full amount.
  • South Australia: A conveyancing firm’s email was compromised, leading to a fraudulent $338,000 invoice. Operation Dolos intercepted the payment and recovered the full amount.
  • Tasmania: A woman received a perfect replica of a legitimate invoice with altered bank details and transferred $120,000. Reporting delay meant the funds were not recoverable.
  • Queensland: An organisation targeted with detailed knowledge of their business relationships lost more than $1 million, with offshore syndicate links identified.

AFP Assistant Commissioner Richard Chin was direct: “The construction sector, with its high-value transactions and complex subcontracting chains, has become an attractive target for organised cybercrime groups.”

The NSW case is instructive. The money was saved not by any system or platform - but by one employee who called a number they already trusted. That friction, built into a manual process, is what the technology should be automating.

Three Charged in Sydney - But the Money Was Already Moving

On 14 May 2026, NSW Police Cybercrime Squad detectives - working alongside the AFP-led Joint Policing Cybercrime Coordination Centre (JPC3) - charged three people following an investigation into a $600,000 BEC operation.

The evidence trail led police to a 20-year-old woman who allegedly purchased $100,000 worth of gold bullion on five separate occasions over a two-week period. She was arrested at a Sydney CBD gold dealership. Two men aged 29 and 36 were also charged, facing counts including dealing with proceeds of crime, dealing with identity information, and participating in a criminal group. All three were refused bail and appeared at Downing Centre Local Court on 28 May (Cyber Daily).

Of the $600,000 total, $300,000 has been recovered. The rest is gone.

AFP Superintendent Marie Andersson noted what made the investigation possible: “Timely information from the National Australia Bank was crucial in helping police identify this alleged criminal activity and act quickly.”

Gold bullion is a telling choice for a money mule. It is high-value, portable, and converts cleanly to cash without the same traceability trail as a bank transfer. The three people charged are likely the cash-out layer of a larger operation - not its architects. The arrest is good news. The $300,000 gap is the realistic recovery outcome when the money has already moved.

What Changes on 1 July 2026

Australia’s Scam Prevention Framework (SPF) takes effect on 1 July 2026 - 26 days away. Banks, digital platforms, and telecommunications providers are the first sectors captured.

Core obligations for banks include (Outseer, Ashurst):

  • A fully operational scam reporting and Internal Dispute Resolution (IDR) mechanism by 30 June 2026
  • Scam reports accepted 24/7, acknowledged within 24 hours
  • A written compliance statement to scam victims within 30 days of an IDR complaint
  • Automatic reimbursement for verified losses under $3,000, expected in Ministerial Guidance
  • AFCA membership for external dispute resolution, required by 1 September 2026

Businesses that fail to meet obligations face fines of up to $50 million. The ACCC will monitor compliance and can take enforcement action.

This is a genuine step forward. The UK’s equivalent mandatory reimbursement regime - in force since October 2024 - has already changed how banks think about fraud prevention, because the cost of not catching fraud upstream now lands on the institution’s balance sheet. Australia’s framework creates a similar incentive structure.

What the Framework Doesn’t Do

The SPF is, at its core, a remediation framework. It defines what happens after a scam. IDR, reimbursement, dispute resolution - these are all responses to money that has already moved.

The $3,000 automatic reimbursement threshold matters for consumer scams. It does not touch the $338,000 construction invoice or the $1 million Queensland loss. For business-to-business payment fraud, the reimbursement provisions offer limited relief, and the burden of verification before payment remains on the business making it.

Nothing in the SPF mandates that, at the moment of payment, the BSB and account number a business is about to pay is checked against the identity of who is actually meant to receive it. That verification does not happen automatically. It has to be built in.

Confirmation of Payee (CoP) - Australia’s name-matching service - provides a traffic-light result when paying to a BSB and account number. It is a meaningful fraud brake. But CoP checks the account name. It does not verify that the business is legitimately registered, that the individual is who they say they are, or that the account details belong to a genuine counterparty.

Verifying the person, the business, and the bank account together - before the payment instruction is sent - is the gap that the SPF alone will not close.

The Fix That Exists Right Now

The NSW construction case shows what pre-payment verification looks like in practice: a human picked up a phone and called an independent number. That one step saved $41,800.

The Tasmanian case shows what happens when that step is skipped: $120,000 transferred, not recoverable.

The phone call model does not scale. Businesses process dozens or hundreds of payments. They cannot independently verify every payee by calling around. What scales is a system that automatically checks, before a payment leaves the rails, that the bank account, business registration, and recipient identity all line up with who the payment is actually meant to reach.

When the AFP advises businesses to “always verify payment requests via an independent and trusted channel” - that is the principle. Building that verification into the payment workflow, so it runs on every transaction without relying on a human remembering to check, is how the principle becomes practice.

The SPF will make the aftermath of a scam more manageable. But the 26 days until it goes live, and the $152.6 million in losses from 2024 still being processed through IDR and dispute resolution, show what happens when the framework starts at remediation rather than prevention.

Verifying the payee before the money moves is not a compliance checkbox. It is what stops the loss in the first place.


ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more

Stop payment fraud before money moves

Verify the person, business, and bank account before any payment leaves your account.