Documented loss · Compromised supplier mailbox
The supplier email address was correct. The loss was $190,000.
The invoice, prior thread and sender address all looked familiar because the attacker apparently had access to the supplier’s real email environment.
Scamwatch published a victim story based on one or more reports received by Australia’s ACCC. A business received altered invoices and a request to change bank details. The scammers included prior correspondence and apparently hid the buyer’s replies from the real supplier. The buyer checked the sender address, found it correct, and transferred $190,000. The fraud was discovered when the supplier called about the missing payment.
Why replying to the email is not verification
If the mailbox or forwarding rules are compromised, the attacker can answer the reply, quote earlier messages and keep the real supplier out of the conversation. A matching From address only shows where the message appears to come from; it does not authenticate the payment change.
The safe verification path
- Do not reply to the change request.
- Call a previously known supplier number—not one shown in the new invoice.
- Ask a known person to confirm the beneficiary name, country and account ending.
- Compare the beneficiary with the contract and legal entity.
- Use a second approver before releasing the wire.
Where a corporate check helps
It can tell you whether the named company exists and whether another proposed payee has a documented corporate relationship. It cannot prove the email is secure or authenticate the account with a bank. Both the entity check and independent payment-change call are needed.
Long-tail searches this case answers
| Query | Intent |
|---|---|
| supplier email address correct but invoice scam | Compromised-mailbox concern |
| real supplier email hacked bank details changed | Payment redirection |
| previous email thread included in fake invoice | BEC detection |
| how to confirm supplier changed bank account | Verification procedure |
Mark Zhong