info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo

    Preventing Invoice and Payment-Redirection Fraud in Construction

    Abstract illustration of a verification gate between a payment instruction and a payment, showing independent checks preventing redirected fraud.

    Construction is not incidentally exposed to invoice fraud. It is specifically targeted, and Australian law enforcement has warned about it. The combination of high invoice volume, many suppliers and subcontractors, and approval chains stretched across sites and offices makes construction businesses an attractive target for payment-redirection attacks.

    The Australian Federal Police has warned that construction businesses are targeted by business email compromise, and the Australian Signals Directorate has warned that cybercriminals target construction companies with email-based fraud. These are not generic threats — they are aimed at the way construction businesses pay and communicate.

    The risk is manageable, but only if both sides of it are addressed: the account being compromised in the first place, and the payment instruction being acted on without independent verification.

    The short answer

    Stop a fraudulent invoice being paid by closing two gaps at once: protect your email and identity accounts so correspondence cannot be watched or impersonated, and independently verify any new or changed payment detail using a phone number or channel your business already held before the request arrived. No single control is enough on its own, but together these two measures stop the overwhelming majority of payment-redirection attempts. The LOOKUP Business Modernisation Framework provides the staged method for putting both in place.

    Why construction is targeted

    Construction businesses process a high volume of invoices across many suppliers and subcontractors, some of whom are new to the business on every project. The amounts are large, the payment cycles are regular and learnable, and bank details legitimately do change when a supplier switches accounts or a subcontractor moves entities.

    Progress claims follow a predictable rhythm — claimed, assessed, approved, paid — and an attacker who can observe that rhythm can time a fraudulent instruction to arrive at exactly the moment a genuine payment is expected. The approval chain itself is a weakness: it stretches across site offices, head office, project managers and finance, and each handoff is a point where a substituted instruction can slip in.

    The Australian Federal Police has warned that construction businesses are specifically targeted by business email compromise. This is not a general cyber risk that happens to affect construction — it is aimed at the way construction businesses pay and communicate.

    How the fraud actually works

    The attack usually begins with visibility. An attacker gains access to a compromised mailbox — sometimes through phishing, sometimes through a reused password, sometimes through an account that was never properly secured — and then waits. They read the correspondence. They learn which suppliers are active, when progress claims are due, who approves payments and what the email patterns look like.

    When a genuine payment is approaching, the attacker sends a notification of changed bank details, or an invoice that fits the expected pattern, from an address that looks right. It might be a spoofed domain with one character different, or it might come from the actual compromised account. The request looks entirely normal because it is modelled on real correspondence the attacker has already seen.

    The payment is made to the new details. Nobody questions it because it arrived at the right time, in the right format, from what appears to be the right source. The fraud is usually discovered only when the genuine supplier follows up to ask why they have not been paid.

    Why it is often found late

    When a supplier chases an unpaid invoice, the first assumption is usually a payment dispute or an administrative delay. The accounts team checks whether the invoice was received, whether it was approved, whether it was paid. They may believe it was paid — because it was, just not to the supplier. The conversation becomes a back-and-forth about banking details, remittance advice and timing, and the possibility of fraud does not surface until someone compares the account number that was paid against the account number the supplier actually holds.

    That delay matters. The longer the gap between the fraudulent payment and its discovery, the less likely the funds are to be recovered. Construction businesses operate on tight cash flow and many simultaneous supplier relationships, so a single disputed payment can sit in a queue for weeks before it is examined closely enough to reveal the fraud.

    The pattern is consistent: the fraud is not found by a control that detected it. It is found by a supplier who was not paid. By the time that happens, the money has usually moved.

    The Framework

    How this maps to the LOOKUP Business Modernisation Framework™

    Preventing invoice and payment-redirection fraud follows the same eight-stage sequence: accounts are secured, supplier records are standardised, verification procedures are defined, and controls are implemented before the business can be confident that a fraudulent instruction will be caught.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    Discover

    Map every mailbox that handles supplier correspondence, identify which accounts can approve or action payments, and document where supplier bank details are currently stored and who can change them.

    Secure

    Enforce multi-factor authentication on all mailboxes and finance systems, apply conditional access to block suspicious sign-ins, and enable mailbox rule detection to catch forwarding rules an attacker may have created.

    Modernise

    Move supplier records and payment-authorisation workflows into governed Microsoft 365 structures so that bank-detail changes require documented approval rather than a single email.

    Standardise

    Define a single verification procedure for any new or changed payment detail, using a phone number the business already held, and apply it identically across every project, office and finance team.

    Optimise

    Review mailbox forwarding rules, guest access and sign-in logs regularly, and tune conditional access policies so that anomalous activity is flagged before a payment is released.

    Prepare

    Train finance, project and site staff to recognise payment-change requests, understand that urgency is a warning sign, and know the verification procedure they must follow before acting.

    Implement

    Roll out email authentication, supplier-record separation and the verification procedure across every office, with a documented close-out step that removes access when a project or supplier relationship ends.

    Improve

    Run periodic reviews of payment processes, test the verification procedure with simulated change requests, and update controls based on what the review reveals about where instructions could still slip through.

    The two separate failures

    Payment-redirection fraud succeeds when two things go wrong, not one. The first is that an email account is compromised or impersonated, giving an attacker visibility into correspondence and the ability to send instructions that look genuine. The second is that a payment instruction — a new bank detail, a changed account, an additional invoice — is acted on without independent verification.

    Many businesses fix only one side. They add multi-factor authentication but never build a verification procedure, so a spoofed email still gets paid. Or they write a verification procedure but leave accounts unprotected, so an attacker can watch the correspondence and time the fraudulent request perfectly. Either gap is enough on its own.

    Both failures need answering. The account has to be protected so correspondence cannot be watched, and the payment instruction has to be verified so a fraudulent one cannot be acted on. Closing one gap and leaving the other open does not reduce the risk — it simply routes the attack through the gap that remains.

    Verifying a change of payment details

    Any new or changed bank detail — whether it arrives by email, by letter, or by phone — is verified by contacting the supplier on a number the business already held before the request arrived. The number in the email itself is never used, because a compromised account can include a compromised phone number just as easily as a compromised bank detail.

    This applies regardless of how urgent the request appears. Urgency is itself a warning sign. A supplier who has banked with the business for years and has never once asked for a same-day change to their account details is not suddenly going to start now. A request that pressures the recipient to act before there is time to verify is doing exactly what a fraudulent request does, and the verification procedure exists precisely for that moment.

    The verification is a business process, not a technology feature. Technology can make the right path easier — a governed supplier record, a documented approval workflow, a prompt that asks whether the change was verified — but the decision to pick up the phone and call a known number is a human one. The procedure has to be written down, owned, and enforced regardless of seniority or deadline pressure.

    Protecting the accounts themselves

    The first line of defence is making sure the accounts that handle supplier correspondence and payment approvals cannot be quietly taken over. Multi-factor authentication on every mailbox and finance system is the baseline — it stops a stolen password from being enough. Conditional access goes further, blocking sign-ins from unexpected locations or devices and requiring additional verification when something looks unusual.

    Email protection layers catch phishing and spoofing attempts before they reach the inbox, reducing the chance that an attacker gets credentials in the first place. But the control that is most often missing is detection of what happens after a compromise: mailbox forwarding rules that an attacker quietly creates to copy correspondence to an external address, and sign-ins from unusual locations at unusual hours. These are visible in the logs, but only if someone is looking.

    Access removal matters as much as access protection. When a project manager, a finance team member or a contractor leaves, their access to mailboxes, supplier records and payment systems should be removed promptly and documented. An account that lingers after its owner has gone is an open door that nobody is watching.

    The Australian Signals Directorate publishes the Essential Eight as a baseline set of mitigation strategies, and multi-factor authentication is one of them. These are not exotic controls — they are the minimum that a business handling large payments should have in place.

    What good looks like

    A verification step that nobody is permitted to skip, regardless of how senior the request comes from or how urgent it appears. The procedure is the same for a director as it is for a junior accounts clerk, and the answer to "can you just process this now?" is "as soon as the change is verified." That culture is what makes the control hold under pressure.

    Staff who are permitted to slow a payment down. If the verification procedure creates friction, that friction is the point — not a problem to be worked around. A team member who holds a payment because the bank details changed and the verification has not been completed is doing their job correctly, not obstructing the business.

    Separation between who can change a supplier record and who can approve a payment. The person who enters the new bank details is not the person who authorises the payment against those details, so a single compromised account cannot both create and approve a fraudulent instruction.

    And detection of a compromised account before the money has gone — through mailbox rule monitoring, sign-in alerts and conditional access — rather than discovery afterwards when a supplier calls to ask why they have not been paid. The difference between those two moments is the difference between a prevented attempt and a completed fraud.

    How LOOKUP helps

    LOOKUP works on the Microsoft 365 environment that surrounds your construction accounting and project systems — identity, Microsoft 365 configuration, multi-factor authentication, conditional access, email protection, monitoring and device management. The objective is to make sure the accounts that handle supplier correspondence and payment approvals cannot be quietly taken over, and that unusual activity is detected before a payment is released.

    We configure mailbox rule detection, sign-in alerts and conditional access policies so that a compromised account is flagged rather than discovered weeks later. We structure supplier records and approval workflows in governed Microsoft 365 environments so that a bank-detail change requires documented verification, not a single email. And we apply the Essential Eight baseline — multi-factor authentication, application control, restricted administrative privileges and daily patching — as the security floor underneath everything else.

    LOOKUP coordinates with construction accounting, estimating and project-management platforms rather than replacing them. The specialist systems remain the systems of record; LOOKUP secures and governs the environment they sit in. For construction businesses specifically, the approach is tailored to the way project teams, site offices and finance functions actually communicate and approve payments — see our broader construction and property development industry page for the full scope.

    The other outcomes in this series

    Improving project information and document control — is everyone on site building from the current drawing, and can the right version be found without a search?

    Securing external collaboration and project access — consultants, subcontractors and clients all need access, so how do you grant it properly and take it back when the project ends?

    Building a technology roadmap for a construction business — what order should you do this in, and what comes first?

    Frequently asked questions

    Frame the call as a standard procedure that applies to every supplier equally, not as a response to anything suspicious about them or their request specifically. A brief phone call to the number you already hold, confirming the change, takes under a minute and most suppliers accept it once they know it is policy. The key is making it universal — every change, every supplier, every time — so nobody feels singled out.

    Call-back verification adds a short step only when bank details change, not on every routine payment, so the impact on your normal cycle is minimal. The vast majority of invoices use unchanged details and process exactly as they always have. The verification step triggers only when something is new or different — which is precisely when slowing down is the right thing to do.

    Contact your bank immediately and request a recall on the transferred funds, then report the incident to the Australian Federal Police and your cyber insurance provider without delay. The faster you act, the greater the chance of recovery, though there is no guarantee. You should also engage your IT provider to secure the compromised account, preserve email logs as evidence, and check whether other payments may have been redirected.

    Coverage depends entirely on the specific terms of your policy, and some policies exclude social engineering or payment-redirection losses unless a dedicated extension was purchased. You should not assume you are covered. Review the policy wording with your broker, confirm whether business email compromise is included, and check whether the policy requires specific controls like multi-factor authentication and call-back verification as conditions of cover.

    The most common entry points are phishing emails that steal passwords, reused credentials from other breaches, and accounts that were never secured with multi-factor authentication. An attacker may also exploit a lingering account from a departed employee or contractor. Once inside, they often create a hidden forwarding rule so correspondence is copied externally, giving them ongoing visibility without needing to log in again.

    Multi-factor authentication prevents a stolen password from being sufficient to access an account, but it does not stop an attacker from spoofing an email address or impersonating a supplier from outside your environment. You need both account protection and an independent verification procedure for any new or changed payment detail. MFA closes one gap; verification closes the other.

    The person who enters a changed bank detail into the supplier record should never be the same person who approves the payment against that detail, and the number of people authorised to make changes should be deliberately small. Separation between data entry and payment approval means a single compromised account cannot both create and pay a fraudulent instruction. Document who has this access and review it regularly.

    Progress claims follow a predictable rhythm — claimed, assessed, approved, paid — and an attacker who has observed that rhythm can time a fraudulent instruction to arrive at exactly the moment a genuine payment is expected. The regularity that makes progress claims manageable also makes them learnable. The defence is verification on every change, regardless of whether the timing feels expected.

    The size of the invoice is not the right test — the right test is whether the payment details are new or changed, regardless of the amount involved. Attackers sometimes test with a small invoice before attempting a larger one, and a small fraudulent payment still represents a real loss and a compromised account. Apply the same verification procedure to every changed detail, large or small.

    Check for any forwarding rule that sends mail to an external address, any rule that moves messages to obscure folders, and any rule you did not create yourself. Attackers create these rules to maintain quiet access — correspondence is copied out without them needing to log in again. Review mailbox rules regularly across all accounts that handle supplier correspondence, and remove anything unexplained immediately.

    An attacker can spoof an email address that looks like your supplier's domain — with one character different or a similar display name — without ever accessing your account or theirs. This is why verifying on a number you already held matters even when your own accounts are fully secure. Account protection and payment verification address different attack paths, and both are necessary.

    The supplier contacts you with the new details, your team verifies the change by calling a number the business already held before the request arrived, and then updates the supplier record through the documented procedure. Legitimate changes happen regularly and the verification call is quick and routine. The supplier is not inconvenienced by a brief confirmation, and the business is protected if the request turns out to be fraudulent.

    Site staff should not be changing supplier records or approving payments, but they should be trained to recognise and report any payment-related request that arrives through an unusual channel. A site manager who receives a text about changed banking details and forwards it to finance without acting on it is part of the defence. The verification itself stays with finance, but awareness extends to site.

    Review access to supplier records whenever someone leaves the business, whenever a project ends, and on a regular schedule — at least quarterly for businesses with high supplier turnover. The review should confirm that only current, authorised staff can view or change bank details, and that access from completed projects has been removed. Document the review so the process is auditable.

    Independent verification of any new or changed payment detail on a channel the business already held is the single control that stops a fraudulent instruction from being paid, even when every other defence has failed. If the verification call uses a number from your existing records rather than one supplied in the email, the fraud cannot succeed. No technology replaces this step, and no urgency justifies skipping it.

    Sources & Further Reading

    The following primary and authoritative sources support the research, guidance and industry context discussed on this page:

    Australian Federal Police — Business Email Compromise

    Supports the claim that construction businesses are specifically targeted by business email compromise and payment-redirection fraud.

    View Source →

    Australian Cyber Security Centre (ASD) — Essential Eight Mitigation Strategies

    Supports the claim that the Essential Eight is a baseline set of mitigation strategies and that multi-factor authentication is one of them.

    View Source →

    Evidence Standard

    LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    Book a strategy session

    If your construction business processes a high volume of supplier and subcontractor payments, the right time to put verification and account-protection controls in place is before a fraudulent instruction arrives. Book a strategy session with LOOKUP to assess your current exposure and build a practical plan.

    Book a Strategy Session

    Peter Kantarelis

    Founder, LOOKUP — Business Technology Strategist

    Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.

    View More Insights →
    Avatar
    Hi there! Have a question? Chat with us here.