Running your business

Keeping Your Trade Business Secure Online

The scam that costs trade businesses real money isn't sophisticated: someone intercepts an emailed invoice and changes the bank details. Here's how it works, the handful of habits that stop it, and what to do in the first hour if it happens.

Nobody's trying to hack your ute. What they're after is the money moving between you, your clients and your suppliers — and the easiest way in is an email account. A tradie sends an invoice, a scammer who's been reading the mailbox sends a follow-up with different bank details, and the client pays the wrong account. By the time anyone notices, the money is gone and two businesses that trusted each other are arguing about who wears it. This guide is the practical version: the scam that actually happens, the small number of things that stop it, and the first hour if it happens anyway.

The scam that actually hits trade businesses

It's called invoice redirection, or business email compromise, and it's the one worth understanding properly because it's aimed squarely at businesses that email invoices — which is all of us.

  1. Someone gets into a mailbox. Yours, your bookkeeper's, or your client's. Usually through a reused password that leaked in someone else's data breach, or a convincing fake login page.
  2. They read, and they wait. They don't do anything straight away. They learn how you write, who you invoice, what your jobs cost and when your invoices go out. Often they set a mail rule that quietly hides their own replies from you.
  3. They pick their moment. A real invoice goes out, for a real job, for the right amount. Shortly after, the client gets a polite follow-up: "Apologies — we've changed banks, here are our updated details." Same signature, same tone, same invoice number.
  4. The client pays the wrong account. Nothing looks wrong to them. The job was real, the amount was right, the email was in the same thread.
  5. You find out weeks later. You chase what you think is an unpaid invoice. They send you the receipt. The money left days ago, and it moved out of the receiving account within hours.

The same trick runs in the other direction, and it's the one that catches trade businesses hardest. A merchant you buy from every week emails a statement with "new" account details. You pay it. The supplier is still owed, so you pay twice — once to the scammer and once, properly, to them.

Who ends up bearing the loss depends on the circumstances, and it's not a question with a comfortable answer for either side. The argument itself will cost you the client relationship regardless of how it lands. Every habit below exists to make sure you never have it.

Lock the email account first

Your email is the master key. Almost every other account you own — banking, accounting, job software, your domain, the phone plan — resets its password through it. Secure that one thing and you've done most of the work.

  • Turn on two-factor authentication. It means a password on its own isn't enough — a second code from your phone is needed too. It's the single highest-value thing on this page and it takes about five minutes per account.
  • Use an authenticator app rather than SMS codes where you get the choice. Codes by text can be intercepted if someone convinces your telco to move your number to their SIM, which does happen.
  • Stop reusing passwords. Reused passwords are how nearly all of this starts: a password you set on some forum in 2014 leaks, and it's the same one guarding your invoices.
  • Get a password manager. It's the only realistic way to have a different long password everywhere. Any of the mainstream ones is fine, and one strong password to open it is all you have to remember.
  • Check your mail rules every few months. Look for forwarding rules or filters you didn't create — a rule quietly copying your mail elsewhere, or filing replies from a particular client into a folder you never open. It's the classic sign someone's already in.
  • Use business email on your own domain, not a personal free address shared across the business. It's easier to control, easier to shut down when someone leaves, and it looks like a business.

Verify bank details by voice, every time

This is the rule that would prevent nearly every case, and it's free. Bank details are never changed by email. Not by you, not by your suppliers, not by anyone you deal with — and any email that says otherwise gets a phone call before a cent moves.

  • Ring the number you already have, from your own records or the number on the wall of their trade counter. Never the number in the email asking for the change — that's part of the scam.
  • Confirm the first payment to any new supplier or subcontractor by phone, and send a token amount first if it's a large one.
  • Say it out loud to your clients. "Our bank details never change. If you ever get an email saying they have, ring me on this number before you pay it." It takes ten seconds at the end of a quote conversation.
  • Put the same line on the invoice itself. A short note under your account details — our bank details will never change; call us to verify any request that says otherwise — costs nothing and puts a doubt in the right place at the right moment.
  • Treat urgency as a warning sign. "Needs paying today or the order's cancelled" is a pressure tactic. Genuine suppliers will wait ten minutes for a phone call.
  • Have one person who approves payments and one process for it, so an unusual request can't slip through because it arrived while everyone assumed someone else had checked.

The same applies to anything asking you to log in. If an email wants you to sign into your bank, your accounting software or your job management account, don't use the link — open the app or type the address you already know. Fake login pages are convincing and the whole point of them is to harvest the password you typed.

Who has access to what

In a small trade business, access tends to accumulate. The apprentice knows the office password because they needed to look something up two years ago. The bookkeeper you stopped using still has a login. Everybody shares one account because it was simpler at the time.

  • One login per person, never a shared one. Shared accounts mean nobody can be removed without changing it for everyone, and no record of who actually did what.
  • Give people the access their job needs. Your crew need job details, site notes and photos. They don't need banking, payroll or the ability to delete an invoice.
  • Remove access the day someone leaves, and put it on the offboarding list next to handing back the keys and the fuel card. This matters most when someone leaves badly.
  • Keep a short list of every account the business owns — email, banking, accounting, job software, domain, phone, socials, supplier portals — and who has access to each. Half a page, and it's the difference between a bad week and a very bad month.
  • Set up who takes over if you can't. If everything is in your head and your phone, a broken arm becomes a business continuity problem. Someone you trust should be able to get in.

Phones, devices and the data behind them

Your phone is the office. It gets dropped on sites, left on roofs and stolen out of utes, and it holds the mailbox that everything else resets through.

  • Passcode or biometrics on every device, including the crew's work phones and the office laptop.
  • Turn on find-my-device and remote wipe before you need them — that's a setting you can't enable after the phone is gone.
  • Keep the operating system and apps updated. Most updates are closing holes someone already knows about, and the ones you keep postponing are the ones being exploited.
  • Don't keep the only copy of anything on one device. Photos of completed jobs, signed variations and site notes are what you'd rely on in a dispute — and a laptop in a stolen ute takes them with it.
  • Prefer cloud systems that back themselves up over a folder on one machine. If your business records only exist in one physical place, that place is a single point of failure.

This is one of the quieter arguments for running jobs in proper software. In ServiceYak the quote, the variation the client agreed to, the site photos and the invoice all live on the job record rather than in a mailbox and a camera roll — so losing a phone costs you a phone, and your invoices carry your details rather than whatever was in the last email thread.

If it happens anyway

Speed is the only thing that helps here. Funds paid to a scam account are usually moved on within hours, so this is a same-hour response, not a tomorrow-morning one.

  1. Call your bank's fraud line immediately. If money left your account, they may be able to attempt a recall. If it was your client who paid, tell them to call their own bank straight away — the receiving bank can sometimes freeze what's left.
  2. Change the passwords, starting with email. Email first, then banking, accounting and anything sharing that password. Turn on two-factor authentication as you go, and sign out all other sessions.
  3. Check for mail rules and forwarding. Before you assume it's over. If a rule is still quietly copying your mail somewhere, changing the password buys you very little.
  4. Tell anyone who might get the next fake email. Clients, suppliers, your bookkeeper. Warn them plainly: an email may arrive from your address asking them to pay somewhere new, and they should ring you before acting on anything.
  5. Report it. Scamwatch and ReportCyber are the Australian reporting channels, and your local police for the record. It won't usually get the money back, but a report is often needed for insurance and it feeds the tracking of the accounts being used.
  6. Talk to your insurer and your accountant. Check whether you have cyber cover — some business policies include a limited amount and some don't include it at all. Worth knowing which one you are before you need to ask.

Then take an hour and fix the thing that let it happen: two-factor on every account, unique passwords, a written rule that bank details are only ever changed after a phone call. It's a cheap hour compared with the one you just had.

Frequently asked questions

What is invoice redirection fraud?

A scammer gets access to an email account — yours, your bookkeeper's or your client's — watches the invoices go back and forth, then sends a follow-up on a genuine invoice saying the bank details have changed. The client pays the scammer's account. It works because everything about it is real except the account number, and it's usually discovered weeks later when you chase a payment that's already been made.

What's the single most useful thing to do?

Turn on two-factor authentication on your email, because everything else resets through it. Then adopt one rule and tell your clients about it: bank details are never changed by email, and any request that says otherwise gets a phone call to a number you already had before anyone pays anything.

Are text message codes good enough for two-factor?

They're far better than nothing, and if that's the only option an account offers, use it. Where you get a choice, an authenticator app is stronger — codes sent by SMS can be intercepted if someone persuades your phone provider to transfer your number to a new SIM. Set that up on your email and banking first.

Who pays when a client sends money to a scammer's account?

It depends on the circumstances and it's genuinely contested — both sides usually believe the other should have caught it. The banks may be able to recover something if it's reported within hours, but often the money is gone. That uncertainty is exactly why the phone-call rule is worth building into how you and your clients work: it costs nothing and it removes the argument entirely.