The one rule that stops most of these scams
Verify out of band. That means confirming the details through a channel the attacker does not control — a phone number you already had, not the number in the email signature, not the number on the PDF.
Payment redirection works because the attacker controls the document and the reply address. The moment you step outside that channel, the scam collapses.
The verification checklist
Run this before the first payment to any supplier, and again any time details change.
- Call the supplier on a previously known number — from a past contract, your accounting system, or their listed business number.
- Read the BSB and account number back to them digit by digit, and have them confirm.
- Check the account name matches the legal entity name on the invoice.
- Look up the ABN on the ABN Lookup register and confirm it is active and GST registered if GST is charged.
- Check the BSB belongs to the bank the supplier says they use.
- Record the date, the name of the person you spoke to, and who at your end verified it.
Treat a bank change as a red alert, not admin
An existing supplier sending new bank details is the highest-risk event in accounts payable. Legitimate changes do happen, but they are rare, and the cost of not checking is the whole invoice.
Anything in this list should stop the payment until a phone call clears it:
- New details arriving by email with urgency attached.
- A slightly different sender domain — one swapped or added character.
- The account name no longer matching the business name.
- A change that arrives close to a large or final invoice.
- A reply-to address different from the sender address.
Make the check automatic
Manual checks fail on the busy weeks, which is exactly when attackers strike. RILLA Shield keeps a verified record of each supplier's payee details, alerts you the moment those details change, checks ABN and BSB details automatically, and can hold the payment until a human confirms it.