⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Remote Australia-wide · on site around Brisbane

An invoice was paid to the wrong account

Or a client paid one of yours to an account that was not yours. Either way somebody has lost money, you have just found out, and you need to know what to do in what order.

That is what this page is. Not how to have prevented it, which is no use to you today.

One thing before the list, because it is worth saying and nobody says it. This is not a fraud that catches inattentive people. It works by reading a real conversation between two businesses that trust each other, waiting for the invoice, and joining in at exactly the right moment with the right names, the right project and the right tone. Being fooled by it means somebody put weeks into fooling you specifically. Everything below is easier to do once that is out of the way.

Do this first

Ring the bank. Now, before you finish reading.

This is the only step that can affect the money, and it is almost never what people do first. The instinct is to check the mailbox, work out how it happened, and tell somebody internally. All of that can wait an hour. The bank cannot.

Australian government guidance is to contact your bank or credit union immediately where funds have gone to fraudulent account details, because they may be able to stop a transaction or freeze the receiving account. Whether that works depends on whether the money is still sitting where it landed, and that is not something you can influence except by calling sooner.

Call on the number in your banking app or on the back of your card. Never a number from the email chain, and never a number somebody in that chain sent you.

Then the mailbox, in the next hour

Short version, because containment is covered properly elsewhere. Reset the password, sign out of every session, turn on multi-factor authentication if it was not on, and then check three things that survive all of that: mailbox forwarding, inbox rules, and which third-party apps have been granted access to the account. Also check the account recovery details, because changing those is how somebody keeps a way back in.

The rules are the part to slow down on. A well-run compromise almost always includes a rule that moves replies from one particular sender into an obscure folder or straight to deleted items. That is the mechanism that lets a fraud run for weeks inside a live mailbox without the owner noticing anything: they are not seeing the half of the conversation that would give it away.

If mail has already been deleted, by the rule or by anybody else, what is still reachable and for how long is on the deleted email recovery page. Read it before you change anything, because some of those windows are short.

If you are still in the middle of it rather than looking back at it, the containment sequence and out-of-hours help are on the emergency Microsoft 365 support page.

Before you tidy anything up

This sits here, third, because by now the instinct has arrived: delete the rules, wipe the account, change everything, put it behind you. That instinct is completely understandable and it destroys the only record of what happened.

Three different groups may need that record. Your insurer, who will want to know what happened before deciding anything. Police, if the report is referred. And the other business, or their lawyers, if there is any argument later about who was breached and therefore who wears the loss. That last one is more common than people expect, because both sides usually assume it was the other.

What to keep, before anything is changed

  • The fraudulent emails themselves, as original messages rather than screenshots or forwards. A forward loses the headers, and the headers are most of the evidence.
  • The rules and forwarding settings exactly as you found them. Write down or screenshot what they were before deleting them.
  • Sign-in and audit records. These age out of a Microsoft 365 tenant on a retention schedule, and on some plans that is a matter of weeks, so they are the first thing to become unrecoverable.
  • The payment records: the invoice as received, the account details used, the transfer confirmation and the times.

Preserve first, clean second. The clean-up will be available to you tomorrow and next week. The record will not, and by the time somebody asks for it the question of whether you still have it has already been decided.

Who has to be told, and roughly when

Four conversations. The order is not arbitrary, and the third one is the one people avoid.

Your bank, first and immediately

Covered above, and it stays at the top of this list because it is the only call that can affect the money. Call on the number from your own records or your banking app, never a number that came from the email chain.

ReportCyber, which is the police route

ReportCyber at cyber.gov.au is the national reporting channel and it is how a cybercrime report reaches law enforcement. Be realistic about what it does: reports are assessed and referred where there is enough to act on, so it is not the same as an investigation starting. It is still worth doing quickly, because you are given a reference number beginning CIRS, and your bank and your insurer will both ask for it.

The other party, sooner than feels comfortable

This is the one people put off, and putting it off is the expensive choice. If your mailbox was the one compromised, whoever you were corresponding with may be mid-fraud right now and does not know. If theirs was compromised, they need to find that out before it happens to the next customer. Ring them, do not email, because the mail chain may be the thing being read.

Your insurer, and read the clause first

Policies that cover this commonly require notification within a short period of you becoming aware, and some require it before you engage anyone to investigate. Read the notification clause before you do anything that might sit outside it, or ring your broker and ask. That is a five-minute call that occasionally makes a very large difference.

The privacy question, which is separate from the money

A payment redirected to a fraudulent account is a theft. Whether it is also a reportable data breach is a different question with a different answer, and the two get tangled together constantly.

The Notifiable Data Breaches scheme is about personal information rather than money. It applies to entities covered by the Privacy Act, which broadly means businesses with an annual turnover of more than $3 million, plus a set of categories that are covered regardless of size: health service providers, businesses that trade in personal information, credit reporting bodies, certain Commonwealth contractors, reporting entities under the anti-money laundering legislation, and several others. Many small businesses are outside it. Some are squarely inside it and do not realise, and health service providers are the most common surprise.

Where it does apply, the test has three parts: there has been unauthorised access to, disclosure of, or loss of personal information you hold; it is likely to result in serious harm to someone; and you have not been able to prevent that likely harm through remedial action. If all three are met, the Commissioner and the affected individuals both have to be notified.

The anti-money laundering category grew on 1 July 2026, when the AML/CTF reforms brought real estate professionals, lawyers, conveyancers, accountants and several other professions under AUSTRAC regulation. If your practice provides designated services, the Privacy Act applies to that work regardless of turnover. What that means for a Microsoft 365 tenant is a separate page, because the technical side of it is a job in itself.

The 30 days is a ceiling, not a plan

Where you suspect an eligible breach but are not sure, the obligation is to assess, and to take all reasonable steps to complete that assessment within 30 calendar days of becoming aware of the grounds. The assessment itself has to be reasonable and expeditious. Thirty days is the outer limit rather than the target.

This is the practical reason the forensic work in the next section is not optional for some businesses. You cannot assess whether personal information was accessed, or judge the likelihood of serious harm, without knowing what was actually in that mailbox and what was actually reached. The clock is running while you find out.

If you do notify people, send them somewhere useful

A notification that tells somebody their personal information was exposed and then stops is the version that makes people angry, and it is the version most businesses send, because writing it is uncomfortable and nobody knows what to offer.

There is an Australian answer to that. IDCARE is an independent not-for-profit that the OAIC describes as Australia's national identity and cyber support service, and it connects people with a specialist identity and cyber security counsellor. Individuals can contact it themselves on 1800 595 160 or through the Get Help path on their site, and organisations can arrange support for a group of affected people rather than leaving each of them to work it out alone.

Naming it in your notification costs you a sentence and changes the character of the message from an admission into something the reader can act on. Almost nobody outside Australia writes about this, and almost nobody inside Australia includes it.

This is general information about how the scheme works, not advice about your situation, and I am not a lawyer. Whether your business is covered and whether a particular incident is notifiable are questions for the OAIC's own guidance or for a lawyer who can look at the facts. Getting that answer wrong in either direction has consequences, so it is worth asking somebody who can be accountable for the answer.

Working out what actually happened

Once the money and the mailbox are dealt with, everything anybody asks you reduces to three questions. Your insurer wants them answered. Your privacy assessment depends on them. And so does knowing whether you are actually finished.

How did they get in?

A password from an unrelated breach, a convincing sign-in page, a token stolen from a session, or no compromise of your tenant at all because it was the other party who was breached and your domain was only imitated. These have genuinely different answers and you cannot fix the right thing until you know which one it was.

What did they see?

A mailbox is a filing cabinet. Contracts, bank details, identity documents somebody emailed once, staff records, client information. What was accessible is a different question from what was used, and it is the question that decides whether anything below in the notification section applies to you.

Are they still in there?

The uncomfortable one, and the reason a password change is not the end of it. Persistence usually survives a reset: a rule, an app that was granted access, a device that was enrolled, a second account that was created. Establishing that the door is actually shut is a separate exercise from closing it.

Answering them is a reconstruction job rather than a repair job: message trace to follow what moved and where, audit logs to establish sign-ins and what was touched, mailbox forensics to recover rules and items that were deleted to cover the tracks, and a timeline that sets out when access started and when it stopped. The output is a written account in plain language that an insurer, a lawyer or the other business can read.

That is what email investigation and eDiscovery is, and it is the right next call once the immediate steps are done. It is scoped and quoted after a short conversation, because the size of it depends entirely on how long the access ran and how much needs establishing.

Afterwards, and only afterwards

There is a version of this page that pivots here into selling you hardening. You are not in the market for that today and the recommendations will keep. When you are ready, the two that matter most for this particular fraud are stopping your domain being imitated, which is SPF, DKIM and DMARC, and the wider tenant review in the Microsoft 365 Health Check. The preventative side is written up properly in the article on preventing business email compromise.

Questions people ask at this point

Talk it through

Confidential, and there is no charge for working out whether you need anything from me. If the answer is that you have already done the important parts, that is what you will be told.

If this is happening right now, calling is faster. 0403 401 250, or email jamie@hamilton365.com.au