Helpful Guide

Business Email Compromise

How small businesses get tricked through email and payment changes.

Email fraudInvoice scamsMFASmall business security
OCT
Local Melbourne TechnicianTrusted • Clear pricing • On-site support

What business email compromise means

Business email compromise happens when criminals use email to trick a business into sending money, changing bank details, sharing information or giving access. The attacker may compromise a real mailbox or impersonate a supplier, customer, manager or staff member.

The Australian Cyber Security Centre explains that protective measures can help prevent email accounts from being compromised, make impersonation harder and reduce the risk of email fraud. For small businesses, simple controls can make a major difference.

Common warning signs

  • A supplier suddenly changes bank account details by email.
  • An urgent payment request arrives from a manager or owner.
  • Email wording feels slightly unusual but the address looks familiar.
  • Invoices arrive with changed payment details.
  • A staff mailbox sends messages the user did not send.
  • Login alerts or MFA prompts appear unexpectedly.
  • Email forwarding rules appear without explanation.

Practical prevention steps

  • Use multi-factor authentication on business email accounts.
  • Confirm bank detail changes by phone using a known trusted number, not the number in the email.
  • Limit admin access to only people who need it.
  • Review mailbox forwarding rules and sign-in activity when suspicious.
  • Train staff to slow down on urgent payment requests.
  • Use strong unique passwords and password managers where suitable.
  • Keep recovery details current for Microsoft 365 and email accounts.

What to do if you suspect compromise

Act quickly. Stop payment if possible, contact the bank, change passwords from a clean device, revoke suspicious sessions if available, check forwarding rules, warn affected contacts and report the scam. If a computer may also be infected, it should be checked before passwords are reused.

How OCT can help

OCT can help small businesses check computers, Outlook, mailbox symptoms, suspicious rules, MFA basics and practical security settings. For financial fraud, bank contact and official reporting should happen immediately.

Related Help

If this problem needs diagnosis, OCT can help with small business IT support. You can call 0406 813 593 or use WhatsApp to ask about the next step.

How Our Pricing Works

The diagnosis fee applies whether or not you proceed with the repair because it covers travel, fault finding and troubleshooting. Time-consuming jobs may be completed off site, with pickup and drop-off included when needed for the same device.

1

$50 Diagnosis Fee

We visit, inspect the device, fault-find and explain the likely repair options.

2

Options Explained

You receive clear recommendations and fixed-price repair options where possible.

3

Your Approval

No additional work or charges proceed without your approval first.

4

Repair Completed

We complete the approved work, test the device and return it after repair or diagnosis when off-site work is needed.

Additional services such as large backups, data migration, data recovery, parts replacement and complex business work may incur extra charges. You will be informed first. If a job needs time-consuming off-site work, pickup and drop-off for the same device are included within the same service, with no extra attendance charge.

Common Questions

Is business email compromise only a big company problem?

No. Small businesses are often targeted because payment processes may be informal.

Should bank detail changes be trusted by email?

No. Confirm using a known phone number or separate trusted method.

Does MFA help?

Yes. MFA makes account takeover harder, although users must not approve unexpected prompts.

Can you help after a suspected compromise?

Yes. OCT can help check devices and email symptoms, but banks and official reporting should be contacted quickly for payment fraud.

Need computer help?

Call or WhatsApp. We come to you across Melbourne and explain costs before extra work.