Someone Paid a Fake Invoice: What to Do in the First 48 Hours

Claymation illustration of a finance worker realising a fraudulent invoice was paid and reaching for the phone to call the bank

Call your bank first. Use the number printed on your card or on the bank's official website, not any number sitting in the email thread. The Australian Signals Directorate (ASD) is direct about why: the bank may be able to close the account or stop the transaction, and that chance shrinks the longer the money sits somewhere else. Everything else in this article matters. None of it recovers money the way that one call sometimes can.

Then take a breath, because the person who processed the payment needs one too. They were targeted by a criminal who does this professionally, using a technique ASD treats as its own category of attack. Business email compromise works because it abuses a process that is functioning normally: an invoice arrives, it looks like the others, the bank details have changed, and changed bank details are an ordinary event. Nobody failed an intelligence test.

The hour markings below are sequencing, not legal deadlines. The one genuine statutory clock in this situation belongs to privacy law, and it gets its own section further down.

TL;DR: What to remember

  • ✅ Hour one: the bank, on a number you looked up yourself. Say "payment fraud" and ask them to recall the payment.
  • ✅ Hours one to four: secure the mailbox. The payment is the symptom; the access is the problem.
  • ✅ Day one: report through ReportCyber and Scamwatch, keep the reference number, and tell your suppliers and customers before a second invoice lands.
  • ✅ Day one to two: work out whether personal information was exposed. That question carries a separate legal clock that has nothing to do with the money.

Contents

Hour one: the money

ASD's guidance is blunt: contact your bank or credit union immediately if you have transferred funds to fraudulent account details or your account details are at risk, because they may be able to close the account or stop the transaction. It adds one instruction that people under stress routinely skip. Call using the bank's official phone number. A criminal who has been reading your mailbox may have helpfully supplied a contact number somewhere in the thread, and it will not connect you to your bank.

  • Call the bank. Say the words "payment fraud" and "recall the payment", and give them the transaction details.
  • If the payment went to another Australian bank, ask your bank to contact the receiving bank. Funds sometimes sit briefly before being moved on.
  • Stop any scheduled or repeat payments to the same account, and check whether other invoices from the same supplier are queued for payment.
  • Write down times as you go. Who noticed, when, who was called, what they said. You will need all of it for reporting, and it is far harder to reconstruct on Monday.

Hours one to four: the mailbox

The payment is the symptom. The real question is whether someone still has access, because a redirected invoice usually means somebody has been reading email, sometimes for weeks, learning how your business talks about money.

ASD's recovery guidance for business email compromise runs six steps: report the incident, check account security, notify contacts and relevant third parties, send a takedown request, contact the email provider, and protect against future attacks. Under pressure, the middle steps are the ones that get missed.

  • Reset the password on the affected account and revoke its active sessions, not just the password. A password change on its own does not always evict someone who is already signed in.
  • Check for mailbox rules. Attackers commonly create a rule that forwards, deletes or files messages from a supplier or a finance address, so the real conversation never reaches the person it should. ASD lists emails being deleted or moved to different folders as an indicator of compromise, and unlike the other indicators, this one you can go and look for directly.
  • Check the account recovery details: alternate email addresses, phone numbers, app passwords. A new password is worth nothing while the attacker still holds the reset path.
  • Look at sign-in activity on other accounts, not just the obvious one. If credentials were reused, the mailbox may not be the only thing open.
  • Tell your finance team that until the incident is closed, every bank detail change gets verified by phone, on a number they already had.

Day one: reporting, and who to tell

Report through ReportCyber, ASD's reporting portal, which routes the report to the relevant police jurisdiction. Keep the reference number, which begins with CIRS. Report separately to the National Anti-Scam Centre's Scamwatch. ASD also runs a 24/7 hotline on 1300 CYBER1 if you want a person on the phone.

Beyond those two, ASD names several parties worth contacting depending on the circumstances: the email provider if someone is impersonating you through their service, IDCARE if personal information is at risk, and the Australian Taxation Office (ATO) if a personal or business identity has been stolen, since tax-related security issues must be reported to them.

Tell your suppliers and customers, and do it early. If your mailbox was the compromised one, the same fake invoice may already be sitting in their inboxes with your name on it. That phone call is uncomfortable. The one that follows a second payment is worse.

If your business holds cyber insurance, notify in line with the policy's own requirements. Policies commonly set expectations about how quickly an incident is reported and about what steps are taken before engaging external help. Those are the policy's terms, not anything inSUPPORT determines, so read the policy or speak to whoever arranged it. Whether any particular incident is covered is a matter for the insurer's assessment.

The other clock: was personal information involved?

This is where a payment fraud quietly turns into a privacy matter, and it is the part most businesses do not see coming. If personal information was accessed, disclosed or lost, a separate legal obligation may apply, and it has nothing to do with the money.

Under the Notifiable Data Breach scheme, an eligible data breach occurs when three things line up: there is unauthorised access to, unauthorised disclosure of, or loss of personal information an organisation holds; this is likely to result in serious harm to one or more individuals; and the organisation has not been able to prevent that likely risk of serious harm through remedial action. Where all three are met, the organisation must notify the affected individuals and the Office of the Australian Information Commissioner (OAIC).

Whether the scheme applies to you at all is worth knowing before you need to. The obligations attach to Australian Government agencies and to private sector and not-for-profit organisations with an annual turnover of more than $3 million; small business operators are generally outside that definition. But size is not the whole test. Some businesses are covered whatever their turnover, including organisations that provide a health service and hold health information, businesses that trade in personal information, credit providers and credit reporting bodies. Entities whose Privacy Act security obligations cover particular information types only, such as small businesses required to secure tax file number information, do not need to notify about breaches of other information outside those obligations. A construction firm under the turnover threshold and a small medical practice can sit on opposite sides of this line.

Where the scheme does apply, an entity that suspects an eligible data breach must quickly assess the incident. OAIC's guidance sets an outer limit of 30 calendar days for that assessment, and makes clear the Commissioner expects it treated as a maximum, not a target. A compromised mailbox containing customer records is exactly the kind of scenario that can start this clock. And where it does, the clock runs from when you become aware of the grounds for suspicion, not from when you finish investigating.

After the 48 hours

Once the immediate work is done, the useful question is not who clicked. It is which control would have made this attack fail, and that is usually a short list: multi-factor authentication that actually resists a determined attempt, alerting on mailbox rules, and a payment process where a change of bank details is verified out of band as a matter of routine rather than judgement.

That last one is a process control, not a technical one, and it is the cheapest thing on the list. A standing rule that no bank detail change is actioned without a call to a previously known number takes the decision away from whoever happens to be under time pressure that day. The control does the remembering.

inSUPPORT builds incident response during onboarding rather than on the day it is needed, and maintains the controls behind it as part of the 6 Step Cyber Strength System. The reason is unglamorous: every step above is easier when somebody already has administrative access, knows the environment, and is not meeting it for the first time at 4pm on a Friday.

What owners ask after paying a fake invoice

Will we get the money back?
Sometimes, and speed is the main variable. Banks may be able to stop or recall a transaction if they are told quickly enough, which is why the first call matters more than anything else in this article. Nobody can promise recovery, and any provider who does is guessing with your money.

Do we have to tell anyone, legally?
It depends on whether personal information was involved and whether your organisation is covered by the Notifiable Data Breach scheme, which turns on the entity test above rather than on the size of the loss. Money moving is not by itself a notifiable breach. Customer records being reachable in a compromised mailbox may well be. Work out which situation you are in early, because the assessment clock does not wait for you to finish arguing about it.

Should we tell staff what happened?
Yes, and how you do it decides whether anyone reports the next one. If the person who processed the payment is treated as the cause, your team learns that noticing something odd is dangerous, and the next incident surfaces days later instead of minutes later. Describe the technique, not the person.

How do we stop it happening again?
Treat it as a process problem with a technical backstop, not a training problem. Out-of-band verification of bank detail changes, multi-factor authentication that survives a prepared attacker, alerting on mailbox forwarding rules, and a documented response plan cover most of it. Awareness training helps, and it is the layer that fails most often under deadline pressure, which is why it should never be the only one.

Have the environment checked properly

If you are in the first 48 hours right now, work the list above first. The conversation about what changes afterwards can wait a day. When that day comes, a Cyber Strength Audit documents what is actually in place and what it would take to close the gap that let this through. We run managed IT, security and compliance for Australian businesses of roughly 30 to 300 users, and we design incident response during onboarding, not during an incident. The point is to make the next attempt hit a wall, not just to write this one up.

Book a Cyber Strength Audit →

Citations

  • "Report and recover from business email compromise", Australian Signals Directorate. The six recovery steps used above, the instruction to contact your bank immediately on their official number, and the list of parties to notify including ReportCyber, Scamwatch, IDCARE and the ATO. cyber.gov.au
  • "When to report a data breach", Office of the Australian Information Commissioner. The three limbs of an eligible data breach and the obligation to notify affected individuals and the OAIC. oaic.gov.au
  • "Part 4: Notifiable Data Breach (NDB) Scheme", Office of the Australian Information Commissioner (updated February 2025). Which entities the scheme covers, including the $3 million turnover threshold and the categories covered regardless of size, and the assessment obligation for a suspected breach. oaic.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE