What business email compromise looks like
Business email compromise, often called BEC, can involve a real mailbox being accessed by an attacker, a look-alike domain, a fake supplier identity, an altered invoice or a hidden rule that forwards sensitive emails. It is especially dangerous because it often looks normal until money has moved.
Warning signs
- A supplier suddenly changes bank account details.
- Customers receive strange payment instructions from your address.
- Sent items are missing or emails appear as read unexpectedly.
- Mailbox rules forward, delete or hide messages.
- Login alerts show unfamiliar countries, devices or applications.
- A property, legal, building or professional services payment was redirected.
Evidence to collect quickly
Preserve the original emails, invoice versions, bank details, timestamps, phone call notes, mailbox audit logs, sign-in records, forwarding rules and any communications with the bank. If a payment has just occurred, contact the bank urgently through official channels.
What a specialist may help determine
A forensic review may identify whether the mailbox was actually compromised, whether a fake domain was used, whether more accounts are affected, what data was exposed and whether the incident created privacy, insurance or reporting obligations.
Payment redirection incidents are time sensitive. Banks may have a narrow window to attempt recall or trace actions.
Related help
Evidence checklist
A practical list of what to preserve before logs, screenshots or account records disappear.
Request specialist consultation
Send the facts you have and we will help organise the next steps.
Australian cyber resources
Helpful public resources for cyber, privacy, scams and online safety.