Business email compromise Cyber.gov.au

Author: Australian Signal Directorate Publisher: cyber.gov.au

Business email compromise Cyber.gov.au

Business email compromise. First published: 23 Sep 2021, Last updated: 11 Feb 2023. ACSC


Technology & Innovation:

Summary: The Australian Cyber Security Centre (ACSC) highlights Business Email Compromise (BEC) as a major threat where criminals impersonate business contacts or use compromised accounts to defraud organisations of money, goods, or sensitive information. Indicators include suspicious payment requests, unusual login activity, or altered email folders. For SE QLD/Northern NSW family-owned businesses, a lack of dedicated IT and reliance on email for daily operations makes them prime targets for BEC scams, which can severely impact cash flow and incur personal director risk.
Implication: On Monday morning, owner-operators must immediately ensure Two-Factor Authentication (2FA) is enabled for all business email accounts. Institute a strict verbal verification process for any requests to change bank account details for payments, always using a pre-known contact number, not one provided in the email. Brief staff handling payments and sensitive information on BEC threats and these new verification protocols. 

Tags: acsc guidance, cyber security, email fraud, technology & innovation

View the original source →

  • Business Intelligence Newsletter

Category Tags

Author Tags

Scroll to Top