Skip to content
Spenda
  • Solutions
    • For franchise groups & buying networksStay ahead of the curve with future-proof digital solutions that grow with your network
    • For B2B marketplaces & platformsStreamline your payment processes and deliver a frictionless customer experience
    • For suppliers & wholesalersA powerful suite of integrated digital tools designed to grow with your business
    • For retailers & service providersIntegrated retail solutions designed to elevate your customer experience
    Servicing businesses along the entire supply chain
    Talk to us
  • Products
    • Software
      • Accounts receivableEnd late payments and quickly turn invoices into cash
      • Accounts payableMake invoice payments easier and faster
      • Full software suiteOur product ecosystem is designed to support every part of your business
      • Book a free demoSee Spenda in action with a free software demo
    • Payments
      • B2B payments & eInvoicingStreamline processes and boost cash flow
      • B2C paymentsAccept payments quickly and securely
      • Virtual credit facilityAccess an unsecured line of credit to pay business expenses
      • Payment methods & optionsOffer customers more ways to pay and get paid faster
    • Integrations
      • Integrations & partner appsEasily integrate Spenda into systems you already use
      • Developer portal & API documentationSmart integrations to support your business
    Solutions designed to
    grow with
    your business

    Book a demo
  • Company
    • About us
      • Our storyWe’re helping businesses work smarter and get paid faster
      • Work for usBe part of a fast-growing team of innovators
      • Partner programmeBecome a referral partner and expand your revenue stream
    • News & Media Centre
      • Spenda in the newsKeep up with the latest news and press releases
      • Media resourcesDownload our approved brand guidelines & logos
    • Investors
      • Investor centreThe official information portal for ASX:SPX news and resources
    Helping
    businesses
    sell better &
    get paid faster

    Contact us
  • Resources
    • Blogs & insightsAccess our articles, tips, and industry news to stay informed and inspired
    • Security & complianceAccept and make payments safely and know that your data is secure
    • Whitepapers & webinarsGain valuable insights and knowledge with our selection of resources
    • FAQsYour most asked questions, answered
    Resources
    to guide your
    business growth

    Get free whitepaper
  • Build your Spenda
Build your solutionLogin
Search
Insights

Email payment fraud: What is it and how to avoid it

Published: February, 12th 2021

As businesses have started using technology more, online payment fraud has become a common problem. Email payment fraud is one of the most common and costly online scams. According to the Australian Competition and Consumer Commission’s (ACCC) Targeting Scam Report, business email compromises cost Australian businesses over $132 million in 2019 — the highest losses amongst all scam types. Over time, this kind of fraud has become more sophisticated, resulting in more businesses falling prey to this costly scam. Spenda has crucial B2B payment security built in.

 In this article, we provide an overview of email payment fraud and steps to protect your business from business email compromise and other interception methods. You’ll also learn how Spenda is improving B2B payment security.*

What is email payment fraud?

Email payment fraud, also known as business email compromise (BEC), occurs when someone sends an email impersonating a senior employee or supplier. This email will typically request a one-off payment or ask for you to change the recipient for future payments. Cybercriminals are able to intercept people’s emails by finding gaps and glitches in your business systems and software. 

For example, a hacker may intercept an email thread between you and a supplier discussing fees and payment details. Once the hacker has intercepted the exchange, they can redirect the payment to a different account. This usually occurs by changing payment details or intercepting the payment by changing the payment details on an authorised invoice, which is also known as invoice redirection fraud.

Who is liable for invoice redirection fraud?

When someone falls victim to invoice redirection fraud, it obviously comes at a significant cost. As a relatively new area of risk, the legislation hasn’t caught up with a defined process to investigate and determine who is liable for the fraud. If it gets to the point that courts are involved, experts may be brought in to investigate all parties’ computers and systems involved in the transaction to determine where the breach occurred. The ACCC’s website provides a range of information and resources to small businesses about common scams and what to do if you suspect your business has been scammed.

How can you identify a fraudulent payment request?

Some online scams are quite sophisticated, and sometimes it can be difficult to determine if an email is fraudulent at first glance. There are a few warning signs you should look out for on any emails that seem suspicious:

  • Requests for urgent payment
  • Unusual language or formatting, including low-resolution imagery and logos
  • The sender’s email doesn’t match the ‘reply to’ email
  • The payment details in the email are different to the usual payment detail
  • The sender asks you to ignore the usual authorisation processes

How can you protect your business from paying fraudulent invoices?

To mitigate the risk of paying fraudulent invoices, you need to understand how to prevent online phishing attacks. First, if you’re unsure if an email or request for payment is legitimate, take steps to double-check the request. You should call the sender to confirm they sent the email. When you call the sender, make sure you use the number you have available, not contact information listed on the email. Further, never reply to an email until you’ve confirmed it is legitimate. If you determine the email is suspicious, escalate it with the appropriate people in your business and let the sender know they may have had a cybersecurity breach.

Secure B2B payments

It’s also important to remember that you may not be the only recipient of fraudulent email or request for payment. You should also educate your employees, so they know what to look out for in the event of email payment fraud. Other processes, such as implementing a multi-person approval process when paying new accounts, are also good ways to protect your business. You can also add this approval process to any payments higher than an agreed-upon threshold. Staying up to date with popular scams will also be helpful for you and your team.

Put strong B2B payment security protections in place with Spenda

Spenda’s platform provides the secure infrastructure that businesses need to send invoices, make payments and manage their finances effectively. With our invoicing and payments platform, while customers need to input their details, this information remains secure and is securely sent to a payment gateway, which sends the Payment to the Supplier. This not only minimises the risk of error, but it mitigates the risk of cybercriminals intercepting your systems. Further, Spenda’s intuitive payment interface means you never need to share credit card or bank details over the phone or via email. Simply enter your information in the secure payment interface and payment will occur.

Our approach to security

Security is a fundamental part of the way we build software at Spenda. All of our software engineers are accountable for ongoing cybersecurity risk awareness within the software domain, and ensure all software solutions are designed, built and maintained to the highest security standard. Our products support two-step authentication (2SA) for enhanced protection against unauthorised access. 

In addition to our own internal security testing, Spenda’s products and services are also regularly (at least yearly) tested by independent external security consultants who perform penetration testing and other security assessments on our applications and cloud infrastructure. This approach allows all of a business’s transactions to be securely created, stored and audited within the Spenda infrastructure, and also sent securely across encrypted HTTPS channels to external parties or payment gateways, such as Fiserv.

Contact us

Contact us today to learn more about Spenda’s solutions and how they can benefit your business.

*This article is for general information purposes only. Consult a qualified financial advisor regarding any changes to or decisions about your business’s finances.

Subscribe to our blog

Spenda logo - goes to home page

Stay Connected

FacebookLinkedInTwitter

Industry Memberships

Spenda is a member of Australian Fintech
Spenda is a member of FinTech Australia
Spenda is a member of the Franchise Council of Australia
Specialised Solutions
  • Franchise groups
  • B2B Marketplaces
  • Suppliers & wholesalers
  • Retailers & service providers
Payments
  • B2B payments
  • B2C payments
  • Virtual credit facility
  • Payment methods
Software
  • Accounts Payable
  • Accounts Receivable
  • Auto / Workshop Management
  • eCommerce
  • Pay by Link
  • Payment Widget
  • Point of Sale
  • Purchasing
  • Quote Management
  • Sales Order Management
  • Service Management
  • Spenda Wallet
  • Warehouse Management
  • Integrations
Spenda
  • About us
  • Work for us
  • Referral Partner
  • Investor centre
  • Contact us
Resources
  • Blogs & insights
  • Security & compliance
  • Whitepapers & webinars
  • FAQs
  • T&C’s
  • Privacy
  • Prohibited payments
  • Spenda Cash Flow Privacy Policy
  • Electronic Verification T&C’s
  • Buyer Finance T&C’s

© Spenda Limited 2025