The Australian Signals Directorate's threat reporting put self-reported business email compromise losses at roughly $84 million in a single year, making it one of the top three cybercrimes reported by Australian organisations. Schools are firmly on the target list — and not for the reasons most people assume. Attackers aren't after the server room; they're after the front office.
Payment redirection fraud is brutally simple: a criminal impersonates (or quietly takes over the mailbox of) someone your office trusts — a builder mid-project, a regular supplier, the principal — and asks for a payment or a change of bank details. The invoice is real; only the BSB and account number have changed. Because Australian banks have historically not matched account names to account numbers at the point of payment, the transfer sails through.
Why schools specifically
- Public project trails. Building works, tenders and fundraising campaigns are announced in newsletters and on websites — telling criminals exactly which suppliers to impersonate and when a large progress payment is due.
- Small finance teams, high transaction volume. One or two people processing fees, refunds, excursions, contractor invoices and payroll is the perfect environment for a well-timed "urgent" email.
- A trusted brand to abuse. The other direction matters too: a compromised school mailbox is used to send fake fee invoices to hundreds of parents. The school loses nothing directly — except the trust of every family who paid.
The process controls (free, start this week)
- Call-back verification, no exceptions. Any new payee or change of bank details is confirmed by phone using a number you already had on file — never one in the email or invoice. Make it policy, in writing, and empower staff to hold payments that haven't been verified.
- Two people on every payment above a threshold. Creation and approval separated, always.
- Slow down "urgent". Urgency plus secrecy plus a payment request is the fraud signature. A genuine principal will not object to a verification call; a fraudster will apply pressure.
- Brief the whole office each term. Five minutes on current lures beats an annual compliance module.
The technical controls (your IT partner's job)
- MFA on every mailbox — the single control that defeats most account takeovers.
- Alert on the takeover tells. New inbox rules that auto-forward or hide replies, sign-ins from unusual locations, OAuth grants to unknown apps — these are the fingerprints of a compromised mailbox, and they're exactly what 24/7 SOC monitoring watches for. (This article's examples are drawn from real patterns our analysts triage.)
- Set up DMARC, SPF and DKIM so criminals can't send mail that says it's from your domain — protecting parents from fake fee invoices carrying your school's name.
- Banner external mail. A simple "this message came from outside the school" tag defeats a surprising share of impersonation attempts.
If money has already moved
Speed decides recovery. Call your bank immediately and ask for the transfer to be recalled, report through ReportCyber (cyber.gov.au), preserve every email as evidence, and have your IT provider check whether a school mailbox was compromised — if it was, the fraud may still be running against your suppliers and parents.
Worried about your office's exposure?
Our security assessments include a payment-fraud review: mailbox hardening, DMARC, alerting and the finance controls above, tested against how your office actually works. Book a free consultation.