Business Email Compromise in Australia: The Fraud Costing Companies Millions and the Governance Gaps Letting It Through
Australian regulator data shows business email compromise remains one of the costliest and most persistent fraud types facing finance and executive teams, and closing it requires structured governance controls rather than another awareness campaign.
Business email compromise (BEC) succeeds not because Australian staff are careless, but because most organisations have no verified process standing between a convincing email and a bank transfer. Regulator data consistently shows BEC as one of the costliest self-reported cybercrime types facing Australian businesses, with finance and executive teams the preferred target because they hold payment authority. Closing the gap requires governance controls that make fraud harder to execute, not another round of phishing awareness training.
The scale of the problem: what the numbers show
In FY2024–25, ASD's ACSC received over 84,700 cybercrime reports through ReportCyber; however, ASD's ACSC assesses that the vast majority of cybercrime continues to go unreported. Businesses reported an average loss of $80,850 per cybercrime, with large organisations averaging $202,691 per incident. Among self-reported cybercrime types, Business Email Compromise (BEC) fraud, resulting in financial loss made up 15% of the total cybercrime reports received, while a further share of email compromise attempts were caught before any money moved.
The trend is not new. It has been building for several reporting years, as the table below shows.
← Swipe to compare →
| Financial Year | ACSC-Reported BEC Losses | Average Loss / Reporting Detail |
|---|---|---|
| FY2021–22 | Financial losses due to BEC increased to over $98 million | An average loss of $64,000 per report |
| FY2022–23 | Total self-reported BEC losses to ReportCyber were almost $80 million | Over 2,000 reports of BEC that led to a financial loss |
| FY2024–25 | BEC fraud with financial loss made up 15% of total cybercrime reports | Average business cybercrime cost reached $80,850, with large organisations averaging $202,691 |
Data breach reporting under the Notifiable Data Breaches scheme tells a related story. Compromised credentials – through phishing, a brute-force attack or an unknown method – comprised 58% of all cyber incidents in one reporting period, and 12% of all breaches were caused by phishing, where an employee inadvertently clicked on malicious links or downloaded a compromised attachment in another. BEC and credential-based fraud sit on the same continuum: an attacker gains enough access or enough convincing detail to redirect a legitimate payment, and the loss is realised before anyone notices.
What regulators and frameworks expect
No single Australian regulator owns "BEC" as a category, but several frameworks converge on the same governance expectations.
ACSC
The Australian Cyber Security Centre publishes annual threat reporting and practical guidance for organisations, including on common threats such as phishing, malware and business email compromise and on protecting business operations and incident response planning. The ASD's ACSC recommends entities implement the Essential Eight cyber security strategies as a baseline defence against cyber threats. For BEC specifically, that baseline translates into multi-factor authentication on email and finance systems, application control, and restricted administrative privileges — controls that make account takeover and mailbox rule manipulation harder to achieve in the first place.
OAIC
Under the Notifiable Data Breaches scheme, entities holding personal information must assess and, where the threshold is met, report eligible data breaches. The OAIC's recurring finding is that it is important that entities enact measures that guard against common threats, such as malicious actors using compromised credentials, ransomware and phishing, and update these measures as threats arise and change. Since BEC frequently begins with a compromised mailbox or credential set, organisations captured by the scheme need documented controls they can point to, not just a policy statement.
APRA CPS 234
For APRA-regulated entities, CPS 234 Information Security is explicit and board-owned. An APRA-regulated entity must maintain an information security capability commensurate with the size and extent of threats to its information assets, and which enables the continued sound operation of the entity. Testing matters too: under CPS 234, an APRA-regulated entity must ensure that testing is conducted by appropriately skilled and functionally independent specialists. Notification obligations are similarly precise — an APRA-regulated entity must notify APRA as soon as possible and, in any case, no later than 10 business days, after it becomes aware of a material information security control weakness which the entity expects it will not be able to remediate in a timely manner. A BEC incident that exposes a gap in supplier verification or payment approval is exactly the kind of control weakness this obligation is designed to surface.
SOCI Act
For organisations captured by the Security of Critical Infrastructure Act, the same principle applies at board level: a documented, tested risk management programme is expected, not an ad hoc response drafted after a fraudulent payment has already cleared.
ISO 27001
None of the above frameworks mandate ISO 27001, but an ISO 27001-aligned information security management system gives an organisation the evidence trail — risk assessments, supplier due diligence records, incident logs, management review minutes — that regulators, auditors and insurers increasingly expect to see when a BEC incident is investigated after the fact.
Closing the governance gap: controls that work
The pattern behind almost every successful BEC case is the same: a plausible-looking email arrives at a point in the payment process where no independent check exists. The fix is procedural as much as technical.
← Swipe to compare →
| Governance Gap | What It Lets Through | Control That Closes It |
|---|---|---|
| No verified callback for bank detail or payment changes | Fraudulent invoice or account changes processed on email instruction alone | Documented supplier verification and callback procedure, recorded within an ISO 27001-aligned ISMS |
| No formal incident escalation path | Delayed detection once funds have already been transferred | Defined incident response and escalation procedure, tested and reviewed regularly |
| Weak technical controls against account takeover | Compromised mailbox or credentials used to intercept or redirect invoices | Essential Eight-informed controls: multi-factor authentication, application control, restricted admin privileges, patched systems |
| No assessment of supplier or third-party security | Fraud introduced through a compromised vendor account or shared mailbox | Third-party risk assessment built into the governance programme, consistent with CPS 234 expectations on related parties |
| Awareness training with no assurance behind it | Staff can describe the risk but the process still allows a bypass under pressure | Structured GRC programme with policy, control testing and audit evidence |
Practical steps a security lead can act on this quarter:
- Mandate a verified, out-of-band callback for any change to bank details or first-time payments above a defined threshold.
- Separate the person who approves a payment change from the person who executes it.
- Apply multi-factor authentication across email, finance systems and remote access, and restrict administrative privileges to those who need them.
- Build an incident escalation path that finance staff know how to trigger the moment something looks wrong — before, not after, funds move.
- Bring supplier and payment-process controls into a documented, tested information security management system rather than leaving them as informal habits.
Why an awareness email isn't a control
Phishing simulations and awareness emails have a place, but they test whether an individual can spot a suspicious message on a given day. They do not test whether the payment process itself has a gap that a convincing enough message can exploit. A structured GRC programme does something different: it maps where payment authority sits, tests whether verification steps are actually followed under pressure, records the evidence, and escalates weaknesses to the board — which is precisely what CPS 234 already expects of APRA-regulated entities and what a mature ISO 27001-aligned programme delivers for everyone else.
How Infracom helps
Infracom Consultancy Integration works with Australian finance and executive teams to build governance programmes that address BEC directly — supplier verification procedures, incident escalation design, ISO 27001-aligned information security management, and Essential Eight-informed technical control reviews, delivered by an all-Australian-focused, SME-accessible advisory team. Read more about our GRC advisory services.
Sources (15)
- Annual Cyber Threat Report 2024–2025
- ACSC Annual Cyber Threat Report, July 2021 to June 2022
- ASD Cyber Threat Report 2022-2023
- Annual Cyber Threat Report 2023-2024
- Threats
- For business and government
- Notifiable Data Breaches
- Notifiable Data Breaches Report: July to December 2023
- CPS 234 Information Security
- CPS 234 Information Security
- CPG 234 Information Security
- What the 2025 ACSC Annual Cyber Threat Report means for businesses
- ASD's Annual Cyber Threat Report reveals top cyber threats for Australian businesses
- Cyber Threats Are Rising: What You Need to Know from the 2024–25 ACSC Report
- The ACSC Just Dropped a Bombshell Report — Your Business Is in It
Get Infracom Insights by email
Practical cybersecurity governance and regulatory updates for Singapore and Australia. No more than a few emails a month; unsubscribe any time.
