A supplier's bank details "change" over email, and a business pays a scammer without realising until the real invoice turns up. It's one of the most common scams targeting small businesses in Australia, and one report a few years back put an actual dollar figure on how much it costs.
The numbers, for context
The Australian Cyber Security Centre's threat report for that year recorded business email compromise losses of close to $98 million nationally, an average loss of $64,000 per report. Separately, the average cost of a cybercrime report was over $39,000 for a small business, rising to $88,000 for a medium one. These aren't the newest figures Australia has, but they're a useful reminder that "small business" doesn't mean "small loss."
The scam isn't clever because it's technically advanced. It's clever because it looks exactly like an ordinary Tuesday.
The habit that actually stops it
Any request to change bank details, however official it looks, gets a phone call to a number you already had, not one in the email, before a single dollar moves. It takes two minutes and it's the single most effective thing a business can do about this specific scam.
Already covered in more detail
Sfinco's earlier post on invoice scams walks through the full pattern. Read it here, or see how an SMB Cyber Audit checks for this.