HomeBlog › Cybersecurity

Business Email Compromise Perth -- Perth IT Care

22 June 2026·7 min min read· Cybersecurity

Business email compromise doesn't arrive with a skull and crossbones. It arrives looking exactly like an email from your materials supplier, written in a professional tone, using their correct company name, referencing a real upcoming payment. The only thing wrong is that it isn't from them.

That distinction — legitimate-looking versus legitimate — is why BEC is the most expensive email threat category in Australia, and why your spam filter isn't going to save you.

What Actually Happened to That Perth Construction Business

A construction company in Perth received an email from what appeared to be their long-term materials supplier. Same display name. Same professional sign-off. The domain was one letter off — the kind of difference you'd miss at a glance when you're processing invoices before a site meeting.

The email requested a bank account update before the next scheduled payment. Routine-sounding. Plausible. $47,000 went out.

The real supplier called a fortnight later chasing the overdue invoice. The money was gone.

This is business email compromise. No malware. No suspicious link. No attachment that triggers a filter. Just a convincing human request that exploited trust, a gap in process, and the time pressure that comes with running a busy operation.

Why Business Email Compromise Perth Businesses Face Is Different from Phishing

Most people have a mental model of phishing: a dodgy email with a "Click here to verify your account" link, bad spelling, a sense of urgency. Your email filter catches most of those. Your staff have probably seen enough of them to be wary.

BEC doesn't work that way. There's no malicious link for a filter to flag. No attachment to scan. Often no obvious red flag at all. It's a socially engineered request that rides on existing trust — your supplier relationship, your boss's authority, your HR process.

Three variants account for most of what Australian businesses encounter:

CEO Fraud

An urgent request arrives, apparently from the business owner or director, asking for a wire transfer or gift card purchase before end of day. The urgency is deliberate. The request bypasses normal approval because it's "from the boss."

Supplier Invoice Fraud

A vendor you actually deal with — or a convincing lookalike — notifies you their banking details have changed. Payments get redirected. By the time the real invoice arrives, the money has moved.

Payroll Diversion

Someone posing as an employee contacts HR or payroll requesting a bank account update for their direct deposit. One employee's salary gets diverted to a criminal's account. Sometimes several.

Perth businesses in construction, professional services, and trades are particularly targeted. You operate on trust-based supplier relationships. Finance and ownership often sit with one or two people. When someone senior asks for something urgently, there isn't always a separate approvals layer to slow it down.

Why Your Spam Filter Doesn't Catch This

Here's where a lot of businesses are lulled into a false sense of security. You're on Microsoft 365. You have a spam filter. You might even have SPF and DKIM records set up on your domain. Surely that's enough?

Not for BEC.

SPF and DKIM verify that an email came from an authorised sending server for a given domain. They do their job. But BEC attacks often originate from one of two places that pass those checks entirely:

Legitimately compromised accounts. If an attacker has stolen login credentials for your supplier's actual Microsoft 365 account, they're sending from that domain with valid authentication. Every technical check passes. The email is real in every technical sense — it's just being sent by a criminal.

Lookalike domains. The attacker registers suppliername-au.com or supp1iername.com.au and sets up SPF and DKIM correctly for that domain. Your filter sees a technically authenticated email from an unfamiliar domain and has to make a judgement call. Without DMARC strict policy and impersonation-aware tooling, it often lets it through.

SPF and DKIM alone are not enough — DMARC strict policy is the layer that closes the gap. DMARC tells receiving mail servers what to do when an email fails alignment checks. Without a strict p=reject policy, a spoofed version of your domain could still land in inboxes.

The Defence Stack That Actually Works

Stopping BEC requires a combination of technical controls and one non-negotiable human process. Neither is sufficient on its own.

DMARC Strict Policy on Your Domain

Set your DMARC policy to p=reject. This means any email that claims to be from your domain but fails alignment checks gets rejected outright — not quarantined, rejected. This protects your domain from being spoofed when attackers target your suppliers, partners, or clients.

A proper email security setup covers SPF, DKIM, and DMARC together — if you haven't had all three reviewed recently, that's worth fixing before something expensive happens.

Microsoft Defender for Office 365 Impersonation Protection

If you're on Microsoft 365, impersonation protection in Microsoft Defender for Office 365 can flag emails that impersonate specific people or domains — even when the domain is a lookalike rather than an exact match. You define the key users and domains — your senior staff, your main suppliers — and the filter watches for attempts to spoof them.

This is available in Microsoft 365 Business Premium. If you're on a lower plan, it's one of the reasons an upgrade conversation is worth having.

Conditional Access to Block Account Takeover at Source

Some BEC attacks originate from a legitimately compromised account. The attacker gets hold of credentials — through a phishing email, a credential breach, or reused passwords — and logs in as a real user. Conditional Access policies in Microsoft 365 can block sign-ins from unexpected locations or devices, and require multi-factor authentication before access is granted. An attacker with a stolen password but no MFA token doesn't get in.

The One Human Process That Doesn't Cost a Cent

Verify bank account changes by phone before processing any payment. Not by replying to the email. Not by clicking a number in the email. Call the supplier on a number you already have on file — from a previous invoice, your accounts system, or their official website.

This single step would have stopped the $47,000 transfer described above. It costs nothing. It takes two minutes. And it's the control that catches the attacks that slip past every technical layer.

Train anyone in your business who processes payments or handles payroll changes to treat any banking detail update as requiring a separate phone verification. Write it into your accounts process. Make it the rule, not the exception.

What to Do If You Think You've Been Hit

If a payment has already gone to a fraudulent account, move fast:

  1. Call your bank immediately and ask them to recall the transfer. Speed matters — international transfers can be stopped if caught early enough.
  2. Report it to ACSC via ReportCyber and to the Australian Federal Police if the amount is significant.
  3. Notify your real supplier so they're aware their identity was impersonated.
  4. Check whether any of your own email accounts were compromised — if an attacker was operating from inside your Microsoft 365 tenancy, there may be forwarding rules or other persistence mechanisms to remove.

If you're not sure whether your accounts have been accessed, that's something we can check. Perth-based, same business hours as your team — when you need someone to look at this during your working day, there's no overnight wait on a ticket sitting in an offshore queue.

The Honest Summary

BEC works because it's designed to look like normal business communication. The attacks are targeted, researched, and timed to land when your guard is down. Technical controls raise the barrier significantly — DMARC, impersonation protection, MFA, Conditional Access — but no filter is perfect when the threat is a well-crafted human request.

The combination that actually works: solid technical foundations in Microsoft 365, and a verified-by-phone rule for any payment or banking change. That's not complex. It's just consistent.

If you want us to review your current Microsoft 365 security configuration and check whether your email authentication is set up correctly, get in touch. We work with Perth businesses across construction, professional services, and trades — we've seen what gets targeted and we know what to look for.

Need a hand with this?

Perth IT Care can sort it out for you. No jargon, no runaround.

Get in touch