->
Back to the Blog
News Hooks

They checked the bank details. The fraudster passed the check

Automate claims intake and validation while keeping Security of Payment checks, variation controls, and real-time governance in place before payment runs.

Cooper Barnard-Brown

September 17, 2026

One scam category is still growing. It's the one aimed at your finance team.

Australians reported $2.18 billion in scam losses in 2025. Investment scams fell. Romance scams fell. Overall reports fell. But, one major category went the other way: payment redirection, where losses rose a staggering 9.3% to $166.8 million.

It keeps working because nothing appears to break. There's a real supplier, and a real invoice for real work, and only one changed line of the bank details.

And the loss sits with whoever pressed pay. In Mobius Group Pty Ltd v Inoteq Pty Ltd, an electrical contractor invoiced Inoteq $235,400 for work on a Rio Tinto project. A fraudster, controlling the contractor’s compromised email, advised that the bank details had changed. Inoteq did what most finance teams would call diligence: a staff member phoned to check. The line was bad, so they emailed for proof instead. The fraudster, sitting in the inbox, confirmed it. Inoteq paid, recovered just $43,541, and the Western Australian District Court then ordered it to pay the real invoice for a second time. That is roughly $190,000, plus interest, for work it had already paid for once.

Notice what Inoteq got right, because that's the part that should worry you. They spotted the change. They tried to verify. They even reached for the phone. The judge called that "prudent”, but "inadequate," because when the call didn't land, the fallback was the one channel the attacker controlled: email. When verification depends on a person chasing an answer themselves, while under pressure to keep up with the hundreds or even thousands of invoices flowing in. At scale, that is a recurring opportunity for failure.

That's the control most organisations still rely on, and RedOwl turns that fragile, manual check into an independent, recorded verification step before payment is released. When a supplier's bank details change, RedOwl verifies the new account independently, confirming it actually belongs to that supplier, before the payment is released, rather than trusting a reply in an email thread. The check doesn't run over a channel anyone can hijack. And every verification, flag and approval is logged, timestamped, and attributed, so if the payment is ever questioned, the evidence already exists.

If a trusted supplier's bank details changed tomorrow, what in your process would actually stop, and verify the payment?

Get in touch with the RedOwl team

Whether you have a question or need support, reach out and we’ll connect you with the right person.

Contact Us ->

Sources

  • National Anti-Scam Centre, Targeting Scams: report on scams data and activity 2025nasc.gov.au(Commonwealth of Australia, public government report). Source of the $2.18 billion total and the $166.8 million payment redirection figure.
  • Mobius Group Pty Ltd v Inoteq Pty Ltd [2024] WADC 114, District Court of Western Australia — published judgment, public record.
  • ABC News, Scammed company Inoteq ordered to pay $190k to Mobius Group after paying fraudulent invoiceabc.net.au (publicly accessible news article).
  • Case detail, including the $43,541 recovered by the paying party's bank — Kennedys, Liability for bank payment fraud – lessons from Mobius v Inoteqkennedyslaw.com (publicly accessible legal commentary).