The scam that made an Australian company pay twice
11/08/2026
In 2022, an electrical contractor completed works on a Rio Tinto project and invoiced the head contractor around $235,000. Before payment was made, a fraudster who had hacked the contractor's email sent through ‘updated’ bank details. The paying company was suspicious, it even tried to call to verify, but when the phone line was poor, it settled for an email confirmation, which the fraudster promptly answered with a forged letterhead. The money went overseas.
When the case reached the Western Australian District Court in Mobius Group v Inoteq, the paying company was ordered to pay the legitimate invoice all over again because it hadn't done enough to verify the change. It effectively paid twice for the same work, losing close to $200,000.
No firewall failed, it was just a convincing email and a verification process that stopped one step short.
Why this belongs on the Board agenda
Business Email Compromise (BEC), also called payment redirection or ‘CEO fraud’, occurs when a fraudster impersonates someone trusted to trick an employee into transferring funds or changing payment details. It looks legitimate, so it slips past controls that were never designed to catch a human being deceived.
In Australia, it's getting worse. The ACCC's National Anti-Scam Centre reported that payment redirection scams surged by 66.6% in 2024, with business losses exceeding $30 million, and that's only what's reported.
It's hitting the sectors our clients operate in
The Mobius v Inoteq case is a construction and infrastructure story, precisely the environment where large contractor payments change hands constantly, and where a single altered invoice can cost hundreds of thousands.
It's not confined to the private sector, either. In July 2025, the AFP charged a Sydney man over $3.5 million fraudulently obtained from the Northern Territory Government, after the agency received an email, appearing to be from a construction company contractor, with a completed vendor form and updated bank details. The agency paid more than $3.58m to the fraudulent account before the scam was uncovered.
And the sums can be devastating for smaller organisations. A flood-damaged Victorian bowls club lost $120,000 after hackers monitored its emails, deleted a genuine builder's invoice and replaced it with a near-identical one, changing only the BSB and account number.
The five scenarios we see most often
1. Supplier payment diversion
A supplier's email is compromised and ‘updated’ bank details are sent through, referencing a genuine project and real invoice, exactly what happened in Mobius v Inoteq.
2. CEO (or ‘fake president’) fraud
An urgent, confidential request appears to come from a senior executive, using urgency and secrecy to discourage verification.
3. Conversation hijacking
Fraudsters monitor a genuine email thread, then insert amended payment instructions at the critical moment, common in property and construction transactions.
4. Payroll redirection
Payroll receives a legitimate-looking request to change an employee's bank details, sending salary to a criminal account.
5. Adviser impersonation
Lawyers, consultants, or project managers are impersonated to lend credibility to a fraudulent request.
The warning signs your people can't afford to miss
- Urgent payment requests that bypass normal processes.
- Requests for secrecy or confidentiality.
- Changes to bank account details.
- Unusual instructions ‘from’ senior executives.
- Requests made outside business hours.
- Slight variations in email domains.
- Reluctance to take part in independent verification.
- Inconsistencies between invoices, contracts, and payment details.
- Pressure to override approvals.
The lesson from the courts: Verification is now a legal duty
The most confronting takeaway from Mobius v Inoteq is that a phone call attempt wasn't enough, the court expected the payer to actually complete independent verification before releasing funds.
As legal commentators noted, the decision means Australian businesses now carry a real duty of care to take reasonable steps against fraud, on both sides of a transaction. A follow-up ‘confirmation’ by email, to the very account that's been compromised, offers no protection at all.
Seven questions every Board and executive team should ask
- When did we last assess fraud risk across our payment processes?
- Do we independently verify every supplier banking change — by phone, to a known number?
- Can a single person both initiate and approve a payment?
- Have we tested our controls against a realistic BEC scenario?
- Are suppliers and contractors held to the same controls as employees?
- How quickly could we actually detect and respond to a fraudulent payment?
- Do our people know how to escalate a suspected attempt?
If you suspect an incident, you should move fast
The first few hours are critical. Immediately contact your financial institution, report to Scamwatch and ReportCyber, secure affected accounts, preserve evidence, launch a forensic investigation, assess whether other payments are at risk, and fix the control failures. In the Mobius matter, only around $43,000 of the stolen funds was ever recovered.
The bottom line
Business Email Compromise extends beyond an IT problem, creating governance, fraud, and operational risks that now carry legal consequences for the party that pays. The organisations that stay ahead of it combine strong payment controls, staff awareness, rigorous supplier verification, and a tested incident response plan.
How SW can help
SW's Fraud & Forensics team helps organisations prevent, detect, and respond to BEC and payment fraud through fraud risk assessments, payment process and control reviews, fraud control framework assessments, cyber and digital forensic investigations, incident response support, data analytics and transaction reviews, governance and control reviews, fraud awareness training, and supplier and third-party risk reviews.
For more information, you can also contact Anthony Hodgkinson directly. Anthony Hodgkinson has more than 30 years' experience in fraud and corruption risk management, forensic investigations, financial crime, cyber and digital forensics, governance reviews, and fraud control frameworks.
