An invoice arrives from a familiar supplier. The email looks genuine, the amount is correct and the bank details are clearly displayed. Your employee makes the payment, only to discover later that the money was transferred to a criminal.
The online banking system worked exactly as intended. There may have been no obvious virus, ransomware attack or technical failure. Instead, the criminal manipulated someone into authorising the payment.
This is social engineering, and it is one of the most difficult cyber security risks for businesses to manage because it targets people and business processes rather than technology alone.
According to the Australian Signals Directorate’s Annual Cyber Threat Report 2024–25, business email compromise resulting in financial loss accounted for 15 per cent of self-reported cybercrime threats affecting Australian businesses. The National Anti-Scam Centre also reported that Australians lost $166.8 million to payment redirection scams during 2025.
What Is Social Engineering In Cyber Security?
Social engineering is the use of deception, impersonation or psychological manipulation to persuade someone to reveal information, provide access or take an action that benefits a criminal.
Rather than trying to defeat your security software directly, a criminal may pretend to be:
- A supplier advising that their bank details have changed
- A senior manager requesting an urgent payment
- A customer asking for a refund to a different account
- A bank or payment provider requesting login details
- An IT support provider asking an employee to reset a password
- A colleague requesting confidential business information
These requests are often carefully designed to look legitimate. Criminals may use information from company websites, social media, previous emails or compromised accounts to make their communications more convincing.
How Do Social Engineering Payment Scams Work?
One of the most common examples is a payment redirection scam, sometimes known as invoice fraud or business email compromise.
A typical scam could unfold as follows:
- A criminal gains access to a supplier’s email account or creates an email address that looks very similar.
- They monitor conversations and learn when an invoice or large payment is expected.
- The criminal sends an altered invoice or advises that the supplier’s bank account details have changed.
- An employee processes the payment using the fraudulent details.
- The money is transferred out of the receiving account before the business realises what has happened.
The invoice, amount, supplier name and email conversation may all appear genuine. The only altered information could be the bank account details.
In other cases, criminals impersonate a director or senior manager and request an urgent transfer. They may pressure the employee to act quickly, keep the payment confidential or bypass the organisation’s usual approval process.
AI-generated emails, cloned voices and manipulated video can make impersonation attempts even more convincing. Businesses can no longer assume that a familiar writing style, voice or image is sufficient proof of identity.
Warning Signs Of A Social Engineering Scam
Social engineering attempts are not always obvious, but common warning signs include:
- A supplier unexpectedly changing their bank account details
- An urgent or unusual payment request
- Pressure to avoid normal approval procedures
- A request for secrecy or confidentiality
- An email address with a small spelling or domain variation
- An invoice containing unfamiliar payment information
- A senior employee making a request that is outside their normal process
- A request to pay using cryptocurrency, gift cards or an unfamiliar platform
- Unusual wording, formatting or contact details
- A caller discouraging you from verifying their identity independently
Businesses should be especially cautious when a request involves changed payment details, a new payee or a high-value transaction.
How Can Businesses Protect Online Payments?
Technology remains important, but preventing social engineering also requires clear payment procedures and well-trained employees.
Independently verify changed bank details
Never rely solely on an email advising that payment details have changed. Call the supplier using a phone number already held in your records or published on their official website.
Do not use the phone number provided in the email containing the payment request, as this may connect you directly to the criminal.
The Australian Cyber Security Centre recommends verbally confirming requests to change payment details or make large transfers using a known and verified phone number.
Introduce dual approval for payments
Require two authorised people to approve large payments, new payees and changes to supplier bank details. Approval responsibilities should be clearly documented, including what happens when the usual approver is unavailable.
Set payment limits
Appropriate transaction and daily payment limits can reduce the amount that can be transferred before suspicious activity is detected. Higher-value payments may require an additional approval step.
Use multi-factor authentication
Enable multi-factor authentication for email, banking, accounting software and other important business systems. This makes it significantly harder for criminals to access an account using stolen login credentials alone.
Train employees to question unusual requests
Cyber security awareness training should extend beyond suspicious links and attachments. Employees involved in purchasing, payroll, accounts payable and banking should know how to identify and verify unusual payment requests.
They should also feel comfortable delaying a payment or questioning a senior employee when the request does not follow established procedures.
Protect your email systems
Businesses should use strong, unique passphrases and multi-factor authentication. Email security measures such as SPF, DKIM and DMARC can also help reduce the risk of criminals impersonating your business domain.
Your IT provider can advise whether these protections have been configured correctly.
Review supplier payment procedures
Tell suppliers and customers how your business will communicate changes to bank details. For example, you might confirm that payment changes will never be advised by email alone and will always be verified by telephone.
What Should You Do If A Fraudulent Payment Has Been Made?
Speed is critical. If you suspect that a payment has been redirected:
- Contact your bank immediately. Ask whether the transfer can be stopped, recalled or frozen.
- Notify your insurance broker or insurer. Follow any incident notification requirements under your policy.
- Stop further payments. Check whether other invoices or payment requests may also have been altered.
- Secure affected accounts. Change compromised passwords, enable multi-factor authentication, check login activity and review email forwarding rules.
- Preserve evidence. Retain emails, invoices, payment confirmations, phone numbers and other relevant records.
- Notify affected suppliers or customers. Warn them if your email account or business identity may have been used to send fraudulent requests.
- Report the incident. Cyber incidents can be reported through ReportCyber and scams can be reported to Scamwatch.
Avoid deleting suspicious emails until your insurer, bank or cyber incident response provider has advised what evidence may be required.
Does Cyber Insurance Cover Social Engineering Scams?
Businesses should not assume that every Cyber Insurance policy automatically covers money transferred as a result of social engineering.
Some policies distinguish between a criminal directly accessing a system to steal money and an employee voluntarily authorising a transfer after being deceived. Social engineering fraud, invoice manipulation and payment redirection may be excluded, subject to a separate limit or available only through an optional extension. In some circumstances, a separate crime or fidelity policy may also need to be considered.
When reviewing your insurance, important questions include:
- Does the policy expressly cover social engineering or payment redirection fraud?
- Does cover apply if a supplier’s email account is compromised rather than your own?
- Are there separate limits or excesses for this type of claim?
- Must particular verification procedures be followed for cover to apply?
- Does the policy provide access to an incident response team?
- Are there gaps or overlaps between Cyber Insurance and crime insurance?
Policy definitions, conditions, exclusions and limits can vary considerably between insurers.
Protecting Your Business Requires More Than Technology
Firewalls, security software and multi-factor authentication are important, but they cannot prevent every employee from being deceived by a convincing request.
Protecting your business from social engineering requires a combination of secure technology, employee awareness, robust payment procedures and appropriate insurance.
AIB’s experienced business insurance brokers can help you review your current protection and understand whether your policy includes cover for social engineering, payment redirection and other cyber risks. Learn more about Cyber Insurance or contact AIB to discuss the risks affecting your business.
Important notice
This article is of a general nature only and does not take into account your specific objectives, financial situation or needs. It is also not financial advice, nor complete, so please discuss the full details with your Steadfast insurance broker as to whether these types of insurance are appropriate for you. Deductibles, exclusions and limits apply. You should consider any relevant Target Market Determination and Product Disclosure Statement in deciding whether to buy or renew these types of insurance. Various insurers issue these types of insurance and cover can differ between insurers.
Steadfast Group Ltd ACN 073 659 677
Important notice – Steadfast Group Limited ABN 98 073 659 677
This article provides information rather than financial product or other advice. The content of this article, including any information contained in it, has been prepared without taking into account your objectives, financial situation or needs. You should consider the appropriateness of the information, taking these matters into account, before you act on any information. In particular, you should review the product disclosure statement for any product that the information relates to it before acquiring the product.
Information is current as at the date the article is written as specified within it but is subject to change. Steadfast Group Ltd and Steadfast Network Brokers make no representation as to the accuracy or completeness of the information. Various third parties have contributed to the production of this content. All information is subject to copyright and may not be reproduced without the prior written consent of Steadfast Group Limited.
