The Invoice Looks Real. The Bank Details Aren't
August 25, 2026

Australians reported 481,523 scams in 2025, with 274,577 reports involving financial losses totalling $2.18 billion.


Behind those numbers are scams that are becoming increasingly difficult to spot. For organisations, one of the most convincing can begin with something as routine as an invoice.

Invoice fraud is becoming increasingly sophisticated. The email may come from a supplier you know. The invoice may look exactly like previous ones. The amount is correct, the project is familiar, and the message may even sit inside a genuine email thread. 


The only thing that's changed is the bank account. 


That one change can redirect thousands of dollars into a cyber criminal's hands. 


How it happens


Invoice fraud, also known as payment redirection fraud, is a common form of Business Email Compromise (BEC). Criminals gain access to a real email account - through phishing, stolen credentials, malware or a data breach - then quietly monitor it. They learn who approves payments, how invoicing cycles work, and wait for the right moment to intercept a genuine transaction and simply change the bank details. 


Because nothing else changes, it's very hard to spot. 


Example of What a Scam Looks Like


A Real Scenario  


An organisation has worked with a trusted supplier for months. Invoices arrive regularly, and the next payment is due. 

A member of the finance team receives an email from the supplier: their banking details have changed. An updated invoice is attached. The supplier's name is right. The invoice number is right. The amount is right. It's part of an existing conversation. 

Nothing looks suspicious, but before processing the payment, the employee follows procedure and calls the supplier using the number already on file, not the one on the new invoice. 

The supplier's bank details haven't changed. Their email account had been compromised, and a criminal was waiting for exactly this moment to redirect the payment. 

One phone call prevented the loss. Without that simple check, a routine payment could have resulted in a substantial financial loss, with little to no chance, of recovering the funds.   


The Golden Rule  


If bank details change, verify independently before you pay - using a phone number you already have on file, never the number on the new invoice or in the email. 

Don't reply to the email to confirm the change either. If the account is compromised, you'd simply be asking the criminal to confirm their own fraud. 


Build this into your Payment Process


Individual vigilance helps, but it shouldn't be the only line of defence. Consider: 


  • Independent verification of any request to change supplier or employee bank details, using contact details you already trust 
  • Separation of duties — the person changing supplier details shouldn't be the same person approving the payment 
  • Extra approval for large or unusual payments 
  • Clear procedures for urgent requests, including anything appearing to come from senior leadership 
  • MFA/2FA on email, financial systems and admin accounts, so a stolen password alone can't grant access 
  • Regular staff training on BEC and payment redirection scams 

Don't Let Urgency Skip the Checks


Criminals rely on urgency to short-circuit good judgement — an overdue invoice, a supplier who "needs it today," a request that appears to come from the CEO. Treat pressure, secrecy, or a change in bank details as a reason to slow down, not speed up. Staff should always feel supported for pausing to verify, no matter who the request appears to come from. 

If You've Already Paid

 

  • Contact your bank immediately — speed matters 
  • Notify your IT/security team, in case an email account has been compromised 
  • Report it via ReportCyber and ScamWatch



Learn More About Staying Secure




We’re Here to Help


If you believe you’ve been a victim of a scam or are concerned about the security of your accounts, contact the CDF team today.  

Share this article:

Related articles

By Hillaria Juliana August 19, 2026
In 1956, a priest with a vision and a community with faith came together to solve a problem. Catholic schools across Melbourne were overflowing. Families were growing. Government funding for Catholic education was simply unavailable. And so Fr James Wall, later honoured with the title 'Father of the Funds', established what he called the Schools Provident Fund (SPF): a new way for the Catholic community to pool its resources, invest in its future, and care for one another. The very first school funded through that vision was Sacred Heart Parish Primary School in Preston, Victoria, which opened in 1957 and became an instant success, laying the framework for what would follow. The movement spread across Australia and New Zealand, growing from a solution for Catholic schools into a broader vehicle for funding parishes, hospitals, aged care and social services. Seventy years later, that vision is very much alive.
August 18, 2026
For the parishioners of Our Lady of Lourdes in Bayswater , the newly renovated Parish Hall is far more than a building. It is the fulfilment of a long-held dream; a place where a vibrant and growing Catholic community can finally come together, share life, and welcome others. Supported by a $1.85 million loan from CDF, the renovation has transformed what was once an ageing and inadequate space into a modern, welcoming hall that will serve the parish and wider Bayswater community for generations to come. A community that needed a home Our Lady of Lourdes Parish has been a cornerstone of Catholic life in Bayswater for more than 60 years, celebrating daily Mass throughout the week and welcoming between 450 and 600 parishioners and visitors across four weekend Masses. It is a community rich in faith, culture and connection, and one that had long outgrown its ability to gather together in a shared space. For Parish Priest Fr Sabu, taking on the renovation project was both a personal commitment and a responsibility to those who had built the parish before him.
August 6, 2026
More than twenty years after a bold vision first took shape, the Aikenhead Centre for Medical Discovery (ACMD) has officially opened its doors in Melbourne, marking a new era for Australian healthcare, medical research and innovation. A centre unlike any other
More

CDPF Limited, a company established by the Australian Catholic Bishops Conference, has indemnified the Catholic Development Fund ABN 15 274 943 760 (the Fund) against any liability arising out of a claim by investors in the Fund. In practice, this means your investment is backed by the assets of the Catholic Archdiocese of Melbourne. The Fund is required by law to make the following disclosure. Investment in the Fund is only intended to attract investors whose primary purpose for making their investment is to support the charitable purposes of the Fund. Investors’ funds will be used to generate a return to the Fund that will be applied to further the charitable works of the Archdiocese of Melbourne and the Dioceses of Sale and Bunbury. The Fund is not prudentially supervised by the Australian Prudential Regulation Authority nor has it been examined or approved by the Australian Securities and Investments Commission (ASIC). An investor in the Fund will not receive the benefit of the financial claims scheme or the depositor protection provisions in the Banking Act 1959 (Cth). The investments that the Fund offers are not subject to the usual protections for investors under the Corporations Act (Cth) or regulation by ASIC. Investors may be unable to get some or all of their money back when the investor expects or at all and investments in the Fund are not comparable to investments with banks, finance companies or fund managers. The Fund’s identification statement may be viewed here or by contacting the Fund. The Fund does not hold an Australian Financial Services Licence.