Like other forms of cybercrime there has been an increase in what is known as Invoice Hacking or Invoice Redirection. This is where cybercriminals are impersonating businesses and suppliers, accessing emails and intercepting invoices. They send emails, coupled with an invoice for payment, including changes to their bank account details, and ask you to pay to the new account. The trouble is this new account belongs to nefarious individuals and not your regular supplier.
The challenge with invoice hacking is that everything can appear totally legitimate in that there is no dodgy spelling, no obviously bogus email addresses, and no impersonal “My dearest friend” type greetings that we associate with email scams.
You may not even realise you’ve fallen victim to a scam until weeks later when the genuine supplier gets in touch asking you to pay your invoice. Unfortunately, by that time, your money and the scammer are both long gone leaving you out of pocket and potentially paying twice.
If you own or run a business, stay alert for invoice hacking and understand that scammers don’t just go after big companies, they go after businesses of all shapes and sizes and can impact any industry. They will tend to target new or junior level employees or volunteers as they’re most likely unfamiliar with payment processes. A compromise like this can have a severe impact on your business.
Reported stats on false billing for 2022 YTD (source: www.scamwatch.gov.au)
If you’re concerned, you may be a victim of invoice hacking:
The harsh reality is that if you have lost money to a scam, it is unlikely that you will get it back. We’ve put together a few tips to help prevent scams from happening:
For expert financial advice, contact us today.
www.scamwatch.gov.au
Scamwatch is run by the Australian Competition and Consumer Commission (ACCC). It provides information to consumers and small businesses about how to recognise, avoid and report scams.
www.cyber.gov.au
The Australian Cyber Security Centre (ACSC) leads the Australian Government’s efforts to improve cyber security.