By Joshua Clouston, Head of Product, ezyshield
EOFY 2026: Why the Next 11 Days Are Australia's Highest-Risk Window for Payment Fraud
BEC losses hit $152.6M in 2024 - up 66%. With EOFY 11 days away and Stage 1 of Australia's Scams Prevention Framework now active, here is what finance teams need to know.
A South Australian conveyancing firm’s client transferred $338,000 to what looked like a legitimate invoice. The bank details were right - or so they thought. A criminal had silently compromised the firm’s email account, monitored communications for weeks, and swapped in a fraudulent BSB at the exact moment a property settlement came due. The AFP’s Operation Dolos intercepted the funds in time. Most victims are not that lucky.
With June 30 eleven days away, that attack is playing out in finance teams across the country right now.
EOFY Is a Scammer’s Best Environment
End of financial year concentrates payment risk like nothing else in the Australian business calendar. BAS statements need lodging. Payroll is being finalised. Supplier invoices are stacking up. Accounts teams are stretched, approval chains get compressed, and the pressure to clear the backlog before July 1 makes people move faster than they should.
That urgency is exactly what a payment redirection scammer depends on.
The attack is straightforward. A criminal compromises a supplier’s or client’s email account - through phishing, credential theft, or malware. They sit quietly, reading communications and waiting for a large payment to come due. When the moment arrives, they send a near-perfect lookalike email with one change: the bank account details. The victim pays. The money moves to a mule account and is offshore within hours.
The AFP calls it Business Email Compromise. Finance teams who have lived through it call it catastrophic.
The Numbers Behind the Warning
The Australian Federal Police tracked $152.6 million stolen via BEC in 2024 alone - a 66% jump from $91.6 million the year before (AFP, October 2025). BEC now ranks as the third most self-reported cybercrime among Australian businesses, accounting for 13% of all business cybercrimes reported to ReportCyber.
Payment redirection scams - the broader category that includes BEC-driven invoice fraud - cost Australians $166.8 million in 2025, up nearly 10% on 2024. Across all scam categories, Australians reported $2.18 billion in losses in 2025.
These are not niche crimes. They are systematic, high-volume, and growing every year.
Construction Is Ground Zero - But No Sector Is Safe
The AFP issued a specific warning targeting Australia’s construction sector. The industry is an ideal hunting ground: high-value transactions, complex subcontracting chains, frequent invoicing between parties who have often never met in person, and many operators - particularly smaller, family-run businesses - without dedicated finance or IT security teams.
Four real cases illustrate the pattern:
- NSW: A construction company defrauded of $41,800 through spoofed supplier emails. Funds fully recovered after a prompt ReportCyber report.
- South Australia: A conveyancing firm’s email account was compromised; its client lost $338,000 to a fraudulent invoice. Operation Dolos intercepted the payment and recovered the full amount.
- Tasmania: A woman lost $120,000 after scammers replicated a construction company’s legitimate communications. Delayed reporting meant the funds were unrecoverable.
- Queensland: An organisation suffered $1 million-plus in total losses linked to offshore syndicates. Partial recovery only.
The difference between the SA outcome (full recovery) and the Tasmanian outcome (nothing) was time. Once funds clear a mule account and hit international transfers, recovery drops sharply. The AFP’s advice: report to ReportCyber and your bank the same day you suspect fraud.
Construction is the current focus, but the attack pattern applies to any sector with regular high-value invoicing - professional services, property, manufacturing, healthcare procurement, government suppliers.
How the Attack Gets Past Your Defences
Understanding the mechanics matters, because the attack is designed to look like ordinary business.
The first stage is access. Criminals use phishing emails, credential-stuffing, or malware to get into a legitimate business email account. Once inside, they do not immediately steal anything. They set up hidden email rules to forward or delete payment-related messages, then monitor quietly.
When a large invoice comes up for payment, they send their fake from within the compromised account, or from a spoofed address that passes a quick visual check. The invoice looks real because it was built by copying a genuine one from inside the mailbox. One field is changed: the BSB and account number.
AFP Assistant Commissioner Richard Chin put it plainly: “Taking a moment to stop and verify can be the difference between protecting your hard-earned cash and becoming a victim. Always confirm payment instructions through a secondary communication channel, such as a trusted contact.”
The operative phrase is secondary communication channel - a phone number already held in your records, not anything in the email chain.
The Regulatory Clock Is Also Running
On 23 May 2026, Treasury designated Stage 1 of the Scams Prevention Framework, covering banks, telecommunications services, and digital platforms (Mondaq, June 2026). The consultation period closes on 25 June 2026. Full compliance obligations land by 31 March 2027.
The framework requires banks to implement six core obligations: governance, prevent, detect, disrupt, respond, and report. The prevent obligation specifically requires banks to take reasonable steps to stop scams before they occur - including deploying payee-name checking systems and targeted warnings on high-risk payments. Non-compliance carries civil penalties of up to $50 million per contravention.
The harder context: Australia currently reimburses fewer than 10% of authorised push payment fraud victims. The UK reimbursed 88% of equivalent losses in 2025. The SPF is the mechanism designed to close that gap over time - but the rules alone do not stop a payment from being sent in the first place.
For businesses making B2B payments, the bank’s payee-checking operates at the rail level. It can confirm that an account exists. It cannot tell you whether that account belongs to the business named on the invoice, or to a mule recruited by an offshore syndicate. That verification has to happen before the payment instruction is even created.
What Finance Teams Should Do Before June 30
The window is short. Here is what actually reduces risk in the next eleven days.
Re-verify supplier bank details out-of-band. For any large payment due this EOFY, call the supplier on a number you hold in your own records - not from any recent email or invoice - and confirm the BSB and account number verbally before processing.
Treat bank detail changes as an automatic red flag. Any supplier email requesting a change to payment details in the lead-up to June 30 should trigger an immediate phone call to verify. Do not act on it by email alone, regardless of how convincing it looks.
Resist compressed approval chains. The pressure to clear the EOFY queue is real, but rushing two-person approvals is where fraud gets through. Any payment above your threshold should still require independent verification, even if it takes an extra hour.
Report fast if you suspect fraud. The SA case recovered $338,000 because the victim acted immediately. The Tasmanian case lost $120,000 because they delayed. If a fraudulent payment has gone out, call your bank’s fraud line and file a ReportCyber report within hours.
Verify the payee before the payment leaves. Confirming that a business exists, that the ABN on the invoice matches the entity, and that the bank account is registered to that business are checks that stop payment redirection fraud at the source - before money ever moves.
ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more
Keep reading
$152 Million Lost as Australia's New Payment Fraud Law Arrives in 26 Days
BEC losses jumped 66% to $152.6M in 2024. Three charged in May. Australia's Scam Prevention Framework goes live 1 July. Here's what it fixes - and what it doesn't.
newsHow a Fake Email and a New BSB Cost an Australian Government Agency $3.5 Million
BEC fraud cost Australian businesses $152.6 million in 2024 - up 66%. A real AFP case shows exactly where account verification stops the attack.
newsAustralia's Scams Prevention Framework Is Now Law - and the September Clock Is Ticking
Australia's Scams Prevention Framework is now law. Banks, telcos and platforms face $50M fines per breach. Here's what changed on 1 July 2026 and what's coming 1 September.
Stop payment fraud before money moves
Verify the person, business, and bank account before any payment leaves your account.