Mark Zhong

Documented public case · Business email compromise

A genuine email workflow, an altered invoice, and more than $15,000 lost

When an attacker can read the conversation, spelling checks and familiar logos are weak defenses.

What happened

In a case published by the ACCC, an attacker accessed a business email account and created a rule that redirected messages containing words such as “payment” and “invoice.” The attacker intercepted an invoice, replaced the payment details and sent it to the client. The client paid more than AUD 15,000 to the fraudulent account.

The dangerous assumption

Buyers often ask whether an email is “really from the supplier.” That is only half the question. A message can come from a genuine compromised mailbox and still contain fraudulent payment instructions. It can also arrive from a look-alike domain that differs by one character.

Signals to treat as a separate verification event

Use a two-channel check

Verify any change using contact information obtained before the suspicious message. Then verify the legal relationship among the contracting entity, invoice issuer and beneficiary. Do not rely on a reply within the same email thread.

Why this belongs in China supplier due diligence

The cyberattack itself is not uniquely Chinese. The China-specific challenge is resolving the entities behind an English trade name, a Chinese business license, a mainland exporter and perhaps a Hong Kong collection company. A clear entity map makes an unexpected beneficiary easier to challenge.

Sources: ACCC, Targeting Scams 2020; FBI IC3, Business E-mail Compromise: The 3.1 Billion Dollar Scam. IC3 calls the foreign-supplier version the bogus invoice or supplier swindle scheme.

Long-tail searches this case answers

QueryIntent
Chinese supplier email hacked bank detailsActive incident
supplier invoice bank account changedPayment verification
business email compromise foreign supplierFraud education
how to verify invoice beneficiary ChinaDue diligence