Change one rule in how your business pays money. Any new bank account, and any urgent payment request, gets a call back on a number you already had before the request arrived. A familiar voice on the phone, or a familiar face on a video call, no longer proves who is asking.
That sounds dramatic until you see how ordinary the losses are.
Why does it work?
Because it looks routine. It works the way a hacked email always has, with one more layer of cover. The request itself is familiar: a supplier's new bank details, or the owner asking for a payment today. The only new part is that a phone call or a video call now backs it up.
Early in 2024 a finance worker in engineering firm Arup's Hong Kong office joined a video call with people he believed were the chief financial officer and other colleagues. Every one of them was a fake. He had suspected the first email was phishing, and the call put his doubts aside, because the people on it looked and sounded like colleagues he knew. He sent HK$200 million, about US$25.6 million, across 15 transactions. Arup confirmed to CNN that fake voices and images were used (CNN, May 2024).
You do not need a video call to lose money like this. A spoofed number is enough. Scamwatch warns that scammers use spoofing so a call seems to come from a legitimate number (Scamwatch, April 2024).
What does it cost you?
Australians reported A$2.18 billion lost to scams in 2025. Payment redirection came second, at A$166.8 million: a scammer changes where your money goes (National Anti-Scam Centre, Targeting Scams report 2025). Among small businesses reporting to Scamwatch, false billing was the most reported scam type, and the report says those reports generally relate to payment redirection.
Those are only the losses people reported. The money is often gone by the time anyone notices.
You may be thinking you would know your supplier's voice. The worker at Arup knew his colleagues too.
What rules actually stop it?
Four, and none of them needs software.
- The callback rule. Any change of bank details, and any urgent payment, gets a call back on a number you already hold: from your records, an old invoice, or a directory you looked up yourself. Never the number in the email. Never the number that just rang you.
- Two people for every new payee. One person sets the account up. A second person checks it on a call before the first payment leaves.
- A code word for urgent requests from the owner. Agree it in person. Never write it in email or a group chat, where a hacked account could read it.
- A plan for the bad day. If money has gone, ring your bank straight away. Report it to Scamwatch and ReportCyber as well.
The Australian Signals Directorate gives the same core advice for business email compromise: watch for a new contact, a new email address or new bank details, and call an existing contact to check before you pay (cyber.gov.au).
What goes wrong?
At the top. The rule usually dies the first time the owner is in a hurry and says just pay it, I'll sort it out later. Once that happens, the team learns the rule has an exception, and a scammer only needs the exception.
So the owner goes first. Tell your bookkeeper, out loud, to call you back on your known number every time you ask for an urgent payment. Thank them when they do.
Where do we stand on it?
Every workflow we build that touches money works one way: it never changes payment details or sends money without a person confirming it. Plenty of things can be sped up. Moving money on the strength of a message is not one of them.
One step for this week
Write the callback rule on one page and pin it where invoices get paid. Then tell your regular suppliers you now call back on file numbers before any change of details, so they expect the call. The same question belongs on any supplier list, next to what happens when it breaks.
This is how every workflow we build handles money. See what we build.





