Scams Targeting Small Businesses: How to Spot and Stop Them

Almost every scam that costs an Australian small business real money arrives dressed as a routine payment request: a supplier's new bank details, a renewal notice for something you genuinely do own, a login page that looks exactly like Xero. The defence is boringly simple — verify any change to payment details by ringing a number you already had, never one printed on the message. Here's what each of the big scams looks like, the controls worth switching on this month, and what to do in the first hour if you've already paid.

The scams that actually hit small businesses

The National Anti-Scam Centre's Targeting Scams report for 2025, released on 30 March 2026, recorded $2.18 billion in reported losses across 274,577 reports that involved money. Payment redirection was the second-costliest category at $166.8 million and phishing was fourth at $97.6 million — the two categories that most often land on a business rather than a household. (The report doesn't split losses between businesses and consumers, so treat those totals as the whole picture, not the business share.)

Scam How it reaches you The tell
Payment redirection Email from a supplier, subbie or "the boss" with updated bank details Account details change mid-relationship; reply-to address is subtly wrong
False billing Invoice or renewal notice for a listing, ad, subscription or toner Nobody can find the order, and the ABN doesn't match the supplier you know
Government impersonation SMS, email or call claiming to be the ATO, ASIC or myGov Links or QR codes in an unsolicited message, threats, odd payment methods
Phishing "Your Xero session expired", "shared file", "mailbox full" A login page on a lookalike domain, for something you didn't start
Overpayment New customer pays too much, then asks for the difference back Refund requested to a different account or method than the payment came from
Remote access Call from "your telco" or "Microsoft" about a fault on your line You're asked to install AnyDesk, TeamViewer or similar

Payment redirection: the one that empties the account

A scammer gets into an email account — yours, your supplier's, or a bookkeeper's — and simply reads for a few weeks. When a real invoice goes out as a PDF, they intercept it, change the BSB and account number, and send it on. Everything else is genuine: the logo, the job reference, the amount, the writing style. The variant aimed at your staff is the same idea in reverse, with an email from "you" asking the office manager to pay an urgent bill before you board a flight.

Construction, real estate, legal and trades businesses are common targets, because they routinely move large one-off amounts and nobody blinks at a $40,000 progress claim. The money is usually pulled out within minutes of landing.

Fake ATO, ASIC and "ABN renewal" notices

Government impersonation works because the real agencies genuinely do contact you. Three rules cut through it:

  • The ATO doesn't put hyperlinks or QR codes in unsolicited emails or texts, and never demands payment by gift card, cryptocurrency or a personal bank transfer. It won't threaten immediate arrest, and it won't cancel your ABN over the phone.
  • ASIC does send real renewal notices — business names cost $47 for one year or $108 for three, and a company annual review is $342 (as at September 2026). But you pay ASIC directly through ASIC Connect. Deceptive third parties scrape the public register and post invoices at inflated prices; paying one can appoint them as your registered agent, which redirects your future ASIC mail to them.
  • There is no ABN renewal fee. An ABN is free and never expires, so any bill for renewing an ABN is either a scam or a middleman charging you for a free form. The same applies to "Director ID renewal" — that number is issued once, for life.

If a notice looks plausible, don't click anything in it. Log in to ASIC Connect or check ABN Lookup yourself and see whether anything is actually due.

False billing: invoices for things you never ordered

These are cheap and constant. The classics are online business directory listings, "domain renewal" notices sent by companies that aren't your registrar (often with a name designed to look official), search engine registration fees, and boxes of printer toner nobody ordered. Amounts are usually small enough — $180 here, $400 there — that a busy bookkeeper pays them rather than asking.

Domain notices deserve special mention: read the fine print and many are technically offers to transfer your domain to their service, not renewals of what you have. Your actual expiry date is in your registrar's dashboard, and nowhere else. If you can't remember who your registrar is, the receipt from when you bought the name will tell you — pay them, and nobody else.

Phishing for your Xero, MYOB and email logins

Accounting logins are the crown jewels: payroll bank accounts, supplier details, customer contacts and enough identity data to open credit elsewhere. The bait is a "shared document", an expired session warning, or a payslip notification. The page it opens looks right, the URL almost does, and the moment you type your password the attacker is inside.

One quiet detail worth checking: after a mailbox is compromised, attackers often create an inbox rule that auto-forwards or auto-deletes mail containing words like "invoice", "BSB" or "payment", so you never see the customer asking why the bank details changed. Check your mail rules and forwarding settings now, and again after any suspicious login.

Overpayment and refund scams

A new customer pays more than the invoice, blames a mistake, and asks for the difference back — usually urgently, and usually to a different account. Say the order was $1,700 and they've paid $4,200, so you refund the $2,500 difference. Days later the original payment is reversed as fraudulent or stolen, and you're out the full $2,500 plus the goods. The rule: refund only to the original payment method and account, and only once the money has genuinely cleared, not just appeared.

The one rule that stops most of it

Any change to bank details gets verified by voice, on a number you already had. Not the number in the email, not the number on the new invoice, not by replying to the thread — a number from an old invoice, your accounting software, or the supplier's website that you typed in yourself. If the account has been compromised, the scammer is the one answering the phone number they supplied.

Write it down as a policy and tell your team it applies to you as well. The single most useful sentence you can give a junior staff member is: "If a payment request is urgent and comes from me, ring me. You will never get in trouble for checking." Payment redirection works on hierarchy and hurry, so remove both.

Controls worth setting up this month

None of these take long, and most are free.

Control What it stops Effort
MFA on email, banking and accounting software Credential phishing, mailbox takeover An hour
eInvoicing through Peppol Invoice interception entirely 15 minutes
Confirmation of Payee at your bank Paying an account whose name doesn't match Already on, at most banks
Two-person sign-off above a set dollar figure Fake boss and urgent-payment scams A conversation
Locked supplier master file Silent edits to stored bank details Software setting
Quarterly check of email forwarding rules Hidden mailbox rules after a breach 10 minutes

Two are worth expanding. eInvoicing sends invoices software-to-software rather than as a PDF in an inbox, so there's nothing to intercept and doctor — it's built into Xero, MYOB and QuickBooks (free or low-cost on most small business plans) and it's the only control here that removes the attack rather than reducing it. Confirmation of Payee checks the account name against the BSB and account number before a first-time payment goes out; it's been rolling out since July 2025 and by July 2026 was live at more than 100 Australian financial institutions. It isn't foolproof, but a "no match" warning on a supplier you've paid for years is a hard stop.

Everything else sits on the same foundation as your general cyber security basics: multi-factor authentication, a password manager, tested backups and patched devices. If a scam or breach would genuinely hurt, cyber insurance covers the forensic and legal response, though most policies expect you to have MFA switched on before they'll pay.

What to do in the first hour

Speed matters more than paperwork. Work down this list.

  1. Ring your bank. Ask them to attempt a recall on the payment. If it's been minutes rather than days, the funds are sometimes still sitting in the receiving account.
  2. Contact the receiving bank too and lodge a fraud report on that account. Your own bank can tell you which institution the BSB belongs to.
  3. Change passwords on email, accounting software and banking from a device you know is clean, and switch on MFA if it wasn't already. Then delete any mail rules you didn't create.
  4. Tell whoever else is exposed. If your mailbox was the compromised one, your customers are receiving doctored invoices right now. A short, plain warning to your contact list beats an awkward explanation later.
  5. Report it. Scamwatch (scamwatch.gov.au) for the scam itself, ReportCyber (cyber.gov.au) if accounts or devices were compromised, and the ATO on 1800 008 540 if tax file numbers or ATO credentials were handed over.
  6. Call IDCARE on 1800 595 160 if identity documents or a director ID were exposed. It's a free national service and it'll write you a response plan.
  7. Notify your insurer and your accountant, and check whether the loss triggers Privacy Act notification obligations if customer data went with it.

If your bank knocks back your claim, small businesses can escalate to the Australian Financial Complaints Authority, and since 12 March 2026 AFCA can also consider complaints against the bank that received the scam funds — not only your own.

Key takeaways

  • Payment redirection and false billing do the most damage to small businesses; payment redirection alone cost Australians $166.8 million in 2025.
  • Verify every change to bank details by phone, on a number you already had — this one habit prevents the most expensive scams.
  • The ATO never puts links or QR codes in unsolicited messages, ABNs and director IDs never need paid renewal, and ASIC fees are paid directly through ASIC Connect.
  • Refund overpayments only to the original account, only after funds have genuinely cleared.
  • MFA, eInvoicing, Confirmation of Payee and two-person sign-off on large payments remove most of the attack surface for very little money.
  • If you've paid, ring your bank within minutes, then the receiving bank, then secure your email before doing anything else.

Where to get help

  • Scamwatch (scamwatch.gov.au) — report a scam, and browse current alerts aimed at businesses.
  • ReportCyber (cyber.gov.au) — the police-referred reporting channel for compromised accounts, devices or data.
  • IDCARE — 1800 595 160, free identity and cyber support for individuals and small businesses.
  • ATO scam line — 1800 008 540, or use the "verify or report a scam" page on ato.gov.au before acting on any ATO contact.
  • ASIC Connect and ABN Lookup — the only places to confirm what you actually owe on a registered business name.
  • AFCA (afca.org.au) — free external dispute resolution if your bank won't help, for businesses with fewer than 100 employees.

Frequently asked questions

What is the most common scam targeting small businesses in Australia?

False billing and payment redirection are the two that hit small businesses hardest, and they're really the same trick wearing different clothes: a bill that looks routine, with bank details that belong to a scammer. Payment redirection alone accounted for $166.8 million of the $2.18 billion Australians reported losing to scams in 2025, according to the National Anti-Scam Centre.

How do I know if an email about changed bank details is a scam?

Assume it is until you've confirmed it by phone on a number you already had — from an old invoice, your accounting software or the supplier's website you typed yourself. Never ring the number in the email, and don't reply to it either, because if the account is compromised the scammer is the one answering. Legitimate suppliers won't mind the call.

Does the ATO send text messages with links?

No. The ATO doesn't send unsolicited emails or texts containing hyperlinks or QR codes, and it's been stripping links out of its outbound SMS specifically so that any message with one is easier to pick as fake. If you get a text about a refund or a debt, don't tap anything — log in to myGov or the ATO app yourself, or ring 1800 008 540.

Do I have to pay to renew my ABN or business name?

There's no such thing as an ABN renewal fee — an ABN is free and never expires, so any invoice for one is a scam or a private middleman. Business names are different: ASIC does charge $47 for one year or $108 for three (as at September 2026), but you pay ASIC directly through ASIC Connect, never through a link in an unsolicited letter.

Can I get my money back if my business paid a scammer?

Sometimes, if you move fast. Ring your bank straight away and ask them to attempt a recall — funds are occasionally still sitting in the receiving account for a few hours — and lodge a report with the receiving bank too. Since 12 March 2026 small businesses can also take a complaint to AFCA about the bank that received the scam funds, not just their own.

General information only. This guide doesn't take your personal or business circumstances into account and isn't financial, legal or tax advice. Rates and thresholds change — check the official sources linked in this guide and get qualified advice where your circumstances require it.