By Joshua Clouston, Head of Product, ezyshield
How a Fake Email and a New BSB Cost an Australian Government Agency $3.5 Million
BEC fraud cost Australian businesses $152.6 million in 2024 - up 66%. A real AFP case shows exactly where account verification stops the attack.
A government agency transferred $3.58 million to what it believed was a familiar construction contractor. The contractor had not changed their bank details. Someone else had.
That someone - a 38-year-old Lurnea man charged by the AFP in July 2025 - had registered a business with a name closely resembling the legitimate contractor, opened a bank account in that name, crafted email addresses mimicking real employees, and sent a “vendor identification form” updating the payment details. The Northern Territory Government processed the invoice. The money left the rail. Only fast work by the bank recovered most of it - approximately $11,600 remains unaccounted for.
This is not an isolated case. It is the template.
BEC Losses Jumped 66% in One Year
The AFP’s October 2025 warning on Business Email Compromise (BEC) in the construction sector came with a figure that should have stopped every accounts payable team in the country: BEC losses across Australian organisations hit $152.6 million in 2024, up from $91.6 million in 2023. That is a 66% surge in a single year.
The construction sector is the primary hunting ground because of three features it cannot easily change: high-value contracts, frequent legitimate requests to update supplier bank details as subcontractors move banks or open project accounts, and lean AP teams stretched across multiple active jobs. But those same features appear in property, legal conveyancing, healthcare procurement, and government infrastructure spend. Wherever high-value invoices flow routinely between trusting parties, BEC has a foothold.
The AFP’s Operation Dolos - a multiagency taskforce launched in 2020 - has prevented more than $45 million in BEC losses. That number sits against $152.6 million lost in 2024 alone. Law enforcement is outpaced.
The Attack Needs No Hacking
The NT Government case is clarifying because the attacker needed no technical access to pull it off. No systems were breached. No credentials were stolen. The method was entirely social and administrative:
- Register a business name that looks like a real contractor at a glance
- Open a bank account in that name
- Build email addresses that mimic actual company employees
- Send a vendor update form with the new BSB and account number
From the agency’s perspective, the email looked legitimate. The business name appeared plausible. The form was routine. The only check that would have definitively broken the chain was verifying whether that BSB and account number was actually held by the business named on the form. It was not a difficult check. It just was not done.
AFP Detective Superintendent Marie Andersson put it plainly after the charges were laid: “Call the party you are engaged with to confirm the request is legitimate.”
That advice is right. Manual call-backs, at the scale and frequency of modern AP operations, are not.
Time Pressure Is the Attacker’s Best Tool
New research from Commonwealth Bank’s Behavioural Science Team, published in April 2026, adds an important layer. Surveying 1,126 Australian employees, managers and business owners, the team found that 76% of employees successfully identified a workplace scam attempt versus just 53% of managers.
The gap is not about intelligence or seniority. It is about time pressure and routine. Managers, moving faster through more decisions, are less likely to pause on something that looks familiar. BEC emails are engineered to look exactly like the kind of routine request a senior approver would wave through without a second read.
The research found that 73% of workplace scams arrive via email, and 61% of successful attacks went undetected because of subtle abnormalities missed under pressure. The scam does not need to fool everyone - it only needs to find one person on a busy afternoon.
Human verification catches some attacks. It misses others. And the ones it misses are the expensive ones.
Receiving Banks Are Now in the Frame
The regulatory environment around payment fraud shifted materially in March 2026. From 12 March, the Australian Financial Complaints Authority expanded its jurisdiction to allow complaints against receiving banks - the institutions that hold the accounts fraudulent funds land in - even where the complainant is not their customer.
AFCA can now join multiple banks to a single complaint and assess proportionate liability across the payment chain. Banks that open accounts for fraudsters, and fail to flag suspicious inflows, now carry regulatory exposure they previously did not.
The practical effect: liability no longer stops at the sending bank’s door. Every institution that touched the transaction - and every organisation that initiated one without verifying the payee - faces a cleaner line of accountability. Demonstrating that account details were verified before money moved becomes a material piece of a dispute response, not just good practice.
What Verification Actually Stops
The NT Government case is useful not just for how the fraud worked but for precisely where it could have been interrupted.
The attacker opened a bank account. That account had a BSB and number. When the vendor update form arrived, the agency had one moment to verify whether that BSB and account number was actually registered to the business named on the form.
Account name matching - checking that the account holder’s name matches who you expect to be paying - would have returned a mismatch. The payment would not have been processed. $3.58 million would not have moved.
Australia’s Confirmation of Payee system, live across the major banks from July 2025, adds this check at the payment initiation stage. A 2023 CBA pilot showed CoP warnings persuaded customers to abandon or amend 31% of suspect transfers - far higher than SMS alert interception rates. That is a meaningful line of defence. But it does not replace the upstream step: verifying the account before it enters your supplier database in the first place.
A supplier database full of unverified BSBs is an attack surface. Each unverified entry is a vendor update request waiting to happen.
The Pattern Will Not Change Unless the Process Does
BEC attacks work because they exploit a process gap, not a technology gap. Businesses and government agencies update supplier bank details via email because that is how their suppliers communicate. Attackers send emails that look like supplier communications because that is what gets processed.
The AFP can charge the individuals who run these schemes. The banks can claw back funds when they move fast enough. AFCA can allocate liability after the fact. None of that changes the underlying gap: accounts are not verified before money is sent to them.
The $152.6 million lost to BEC in 2024 is the cost of that gap. The 66% year-on-year growth suggests it is widening.
ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more
Keep reading
Your Finance Team Spots the Scam. Then the Manager Signs Off Anyway.
CommBank data shows 53% of managers miss BEC scams vs 76% of employees. Why human vigilance alone won't stop payment redirection fraud - and what does.
news$152 Million Lost as Australia's New Payment Fraud Law Arrives in 26 Days
BEC losses jumped 66% to $152.6M in 2024. Three charged in May. Australia's Scam Prevention Framework goes live 1 July. Here's what it fixes - and what it doesn't.
newsYour Next Invoice Could Be a Deepfake: AI Fraud Targets Australian Businesses
AI deepfakes and voice cloning are behind a new wave of payment fraud hitting Australian businesses in 2026. Here's what changed, what it costs, and how to stop it.
Stop payment fraud before money moves
Verify the person, business, and bank account before any payment leaves your account.