By Joshua Clouston, Head of Product, ezyshield

News 8 min read

Your Finance Team Spots the Scam. Then the Manager Signs Off Anyway.

CommBank data shows 53% of managers miss BEC scams vs 76% of employees. Why human vigilance alone won't stop payment redirection fraud - and what does.

Two people at an office desk reviewing paper documents, one signing a notebook page with a pen while the other holds a printed document

A payables officer at a Tasmanian construction firm raised her hand. The supplier invoice looked almost right - same letterhead, same contact name, same amount. But the BSB was different. She flagged it. Her manager, wrapping up a project deadline, scanned the email thread and approved the transfer. One hundred and twenty thousand dollars cleared to a fraud account. The real contractor never saw a cent.

That story comes from Australian Federal Police case files. And new research from Commonwealth Bank confirms it is not an edge case - it is the default failure mode for payment fraud in Australian workplaces.

Australia Is Losing $150 Million a Year to BEC, and It’s Accelerating

Business email compromise (BEC), known locally as payment redirection fraud, cost Australian businesses more than $152.6 million in 2024. The AFP, which tracks these figures through its Operation Dolos taskforce, noted a 66 per cent increase on the $91.6 million lost in 2023. BEC losses have nearly doubled in two financial years.

Seventy-three per cent of workplace scams targeting businesses arrive via email, according to Commonwealth Bank’s research. The attacks combine real-time surveillance - where criminals monitor genuine email threads between a company and its suppliers for weeks before striking - with precisely timed account substitution. When a real invoice is expected, a spoofed message appears with new payment details. By the time the genuine supplier follows up about a missed payment, the funds are long gone.

The AFP’s October 2025 warning singled out Australia’s construction sector as a priority target. High-value invoices, complex subcontracting chains, deadline pressure - all of it creates conditions where an unusual payment instruction can look routine. Organised criminal groups operating both domestically and offshore have taken note.

CommBank’s Research Surfaces an Uncomfortable Finding

In April 2026, Commonwealth Bank’s Behavioural Science Centre of Excellence released a national survey and behavioural experiment involving 1,126 Australian employees, managers, and business owners. The headline result: 76 per cent of employees identified a workplace scam attempt. Only 53 per cent of managers did.

That 23-percentage-point gap has a specific implication for payment fraud. In most Australian businesses, the person who processes invoices and notices something is off with a bank account number is not the person who approves the payment. The processor sees the detail; the approver has the authority. The scam is designed to reach the approver - and the approver is the one more likely to miss it.

CommBank’s researchers found that in 61 per cent of successful workplace scams, “subtle abnormalities were not identified.” When the fraud worked, the signals were present. The person who could have blocked the payment did not catch them.

Front-line finance staff handle invoices day in, day out. They build pattern recognition about supplier account details, letterhead layouts, and normal payment amounts. Senior managers are the target of impersonation in BEC attacks precisely because they carry approval authority - but they do not spend their days cross-checking BSBs against prior invoices. The social engineering is calibrated for the person who approves, not the person who processes.

The CommBank research is being covered by SecurityBrief Australia and others as a management problem. It is also a payment architecture problem.

The Construction Sector Is Not the Exception

The AFP’s warning about the construction sector is worth sitting with, because the industry characteristics that make it a target exist across dozens of Australian sectors.

Any industry with multiple suppliers sending invoices for ongoing work, payment cycles operating under time pressure, and email as the primary accounts-payable communication channel is running the same risk profile.

The AFP documented a NSW construction company that lost $41,800 after criminals spoofed an email from a trusted supplier. A South Australian conveyancing firm had a client’s $338,000 property settlement intercepted and redirected - Operation Dolos recovered that amount, which is the exception. The Tasmanian homeowner who lost $120,000 during a home renovation was a private individual, not a corporate accounts team.

BEC is not a large-enterprise problem. It is an any-enterprise problem, and increasingly a consumer problem too.

The AI Layer Is Making Social Engineering Harder to Spot

ASIC flagged this directly in its April 2026 media release (26-063MR): AI is supercharging scam activity across the board. ASIC removed a record 11,964 scam websites in 2025 - a 90 per cent increase on the prior year - and noted that scammers are now using AI to generate polished fake content that looks indistinguishable from legitimate financial communication.

For BEC specifically, AI is eliminating the tells that used to help recipients identify fraudulent emails. Large language models handle the grammar, tone, and format. Voice cloning tools replicate the sound of a known executive or supplier contact. In early 2026, Australian cybersecurity analysts documented cases where AI-generated voice calls were used to impersonate HR managers and authorise payroll detail changes - a variant of BEC that targets the employee bank account on file rather than a supplier payment.

The AFP described BEC attacks that “mimic tone, formatting and internal processes with alarming precision.” When the fraudulent email looks identical to a genuine one, awareness training faces hard limits.

Payroll Diversion: BEC Through the HR Door

Payroll diversion sits in the same threat category as supplier payment redirection, but it comes through a different channel. A spoofed HR email, or an AI-cloned voice call claiming to be an employee, requests a bank account update before the next pay cycle. The instruction looks legitimate. The approval comes through. The payroll run sends funds to a mule account.

One-in-three Australian employers reported in 2026 that they are not fully confident they are paying employees correctly, according to analysis published by InsIconCyber. That uncertainty creates an opening: discrepancies in account details are more likely to be attributed to an internal admin error than to fraud.

The risk is not confined to large payroll runs. A single employee’s pay being redirected for one cycle can clear thousands of dollars before anyone notices. Multiply that across a small business with fifteen staff and the exposure adds up fast. The attack does not scale with business size; it scales with the frequency of bank account updates.

Why Two-Person Approval Is Not the Answer

The instinct when confronted with CommBank’s research is to add another approver. If one manager misses 47 per cent of scams, surely two will do better.

The problem is that both approvers are reviewing the same email thread. If that thread is fraudulent - if the supplier’s email account has been compromised, or the domain spoofed convincingly - then both approvers are working from bad information. A second human check on the same fraudulent source does not add independent verification; it adds another person who can be fooled by the same material.

Callback procedures to a known phone number help at the margin - but sophisticated BEC campaigns substitute the phone number in the email thread too. The AFP has documented cases where callbacks to the number listed in the email reached the fraudsters directly, who then confirmed the fraudulent payment details. A callback to a number from the email you already suspect is fraudulent tests nothing.

The control that actually breaks the attack is one that operates outside the email thread entirely: independent verification that the BSB and account number belong to the business or person being paid, checked against a trusted data source, before the payment instruction is authorised to go out.

What Verification at the Payment Layer Actually Stops

Consider the Tasmanian renovation case. The email looked right. The manager approved it. No additional sign-off or callback from the same email chain would have changed the outcome, because both would have been grounded in the fraudulent email thread.

But if the payer - or their financial institution - had checked whether that specific BSB and account number were registered to the contractor’s ABN or identity before the EFT cleared, the fraud would have ended there. The account did not belong to the contractor. An independent data check would have surfaced that mismatch before the transfer was authorised.

This is the logic behind Australia’s Confirmation of Payee service, progressively rolled out by Australian Payments Plus. CoP flashes a traffic-light match result when a payment is initiated to a BSB and account number - green, amber, or red. For B2B payments, supplier onboarding, and payroll updates, the same verification principle applies beyond the consumer context: verify the person, verify the business, verify the account - using data that sits outside the email chain that may already be compromised.

CommBank’s data shows the awareness gap between front-line staff and managers will not close on its own. The AFP data shows BEC losses are accelerating. The answer is not to train the approver harder - it is to move the account-number verification step outside the approval process entirely, so money only moves when the destination has been independently confirmed.


ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more

Stop payment fraud before money moves

Verify the person, business, and bank account before any payment leaves your account.