Police keep $465 million out of criminal hands by targeting Business Email Compromise scams

Police have issued an urgent plea for vigilance against Business Email Compromise (BEC) as loss prevention and recovery figures under Operation Dolos head towards the half a billion-dollar mark.

Through Operation Dolos, the Joint Policing Cybercrime Coordination Centre (JPC3), state and territory police, and industry partners, work together to disrupt the growing threat of BEC and the criminal networks behind them.

The cybercrime operation, established in January 2020, has so far helped recover or prevent $465 million in losses from Australians and Australian businesses targeted by BEC activities.

According to the National Anti-Scam Centre’s Targeting Scams Report, payment redirection scams – also known as Business Email Compromise – resulted in $166.8 million in reported losses last year, making it the second most costly scam type in Australia after investment scams.

The size and scope of the problem has prompted a new ClickFit campaign from the JPC3 to boost awareness and education in the wider community.

BEC unfolds when a cybercriminal impersonates a trusted business, supplier, executive or colleague to deceive and pressure clients, customers or employees into redirecting legitimate payments into fraudulent accounts they control.

The scam typically begins when the offender gains unlawful access to a victim’s emails and monitors the inbox for weeks, or even months, so they can build intelligence and identify upcoming payments which could be disrupted or stolen.

Offenders use ‘typosquatting’ to send payment requests from email addresses which closely mimic legitimate businesses and may delete emails or alter inbox rules to hide their activity.

Scammers often target high-value transactions including property settlements, building projects and supplier invoices, with victims left unaware they have been deceived until the intended recipient makes contact or advises they have not received any payment.

Perpetrators will use high-pressure tactics to prevent victims from verifying payment requests, frequently targeting them before weekends or public holidays, and claiming urgent action is needed to avoid penalties, project delays or missed deadlines.

By then it’s usually too late to cancel the transaction to the criminal’s account or too late for the victim’s bank to recover the funds.

AFP Detective Superintendent Marie Andersson laid down a warning to cybercriminals.

“Cybercriminals rely on people being rushed, distracted or pressured into making snap decisions. Our message is simple: Australians are becoming more aware of your tactics. Every time someone stops to verify a payment request, it becomes increasingly harder for these criminals to succeed,” Detective Superintendent Andersson said.

The reminder for vigilance against BEC aligns with the beginning of Cyber Security Action Month, a government initiative to promote online safety, data protection and secure digital habits.

“Business email compromise can be effective because it exploits trust, business operations and our daily digital routines,” Detective Superintendent Andersson added.

“Cybercriminals carefully impersonate legitimate businesses and employees by copying branding and communication styles and create a sense of urgency to pressure their victim into acting quickly before they have time to realise it’s a scam.

“The sad reality is that because this type of compromise is a business for criminals, and they have sophisticated techniques deceptive enough to target anyone involved in processing or approving payments, from CEOs to Mum or Dad invoicing at home.”

This is why it’s so important for people to educate themselves and to take a moment to safeguard and recognise these common warnings signs of BEC:

  • Requests to change bank or payment details;
  • Minor changes to email addresses or domains;
  • Newly registered domains designed to resemble a legitimate business;
  • Emails which appear genuine because they originate from a compromised account;
  • Unsolicited follow-up calls confirming payment instructions;
  • Unprompted MFA or device logins;
  • Unfamiliar attachments or documents.

As part of the new ClickFit campaign focused on safety tips, Australians and Australian businesses are urged to follow six simple steps everyone can take before making a payment to help protect against cybercriminals.

Stop before you act

Pause before you action any invoice, email, payment request or bank detail changes. Criminals are counting on you to rush. Always double-check.

Check payment details carefully

Compare bank account details with previous invoices and be alert to changes in bank details, payment processes and email addresses.

Protect against impersonation

Watch for slight changes in email addresses or domains, unexpected emails, calls or shared documents, and unusual requests for payment.

Verify before making payment

/Public Release. View in full here.