At a glance
Business email compromise can allow cybercriminals to steal information or damage a business’s reputation.
If you think your business email is compromised, report it to your financial institution and us immediately. You should also check your account security and let any affected contacts or third parties know.
Emergency help: If there is an immediate threat to life or risk of harm, call 000.
Business email compromise explained
Business email compromise is when cybercriminals gain unauthorised access to your business email account. This can result in stolen information, financial loss or damage to you and your organisation’s reputation.
Learn more about business email compromise.
Signs you may be affected
You may be experiencing business email compromise if you:
- can’t access your account, even though the username and password are correct
- have been logged out of your account on all devices
- notice login times or locations that you don’t recognise
- receive unexpected password reset notifications
- notice changes to your account and emails that you didn’t make
- stop receiving expected emails in your inbox
- receive an alert about suspicious account activity.
If this is happening now
You can reduce further harm by taking immediate action.
Report the incident
It’s important to record what happened and report the incident to us.
Try to record as much as possible, including:
- what happened
- when it happened
- how you think the compromise occurred
- what steps you took to secure your account after the incident (such as changing your password).
After you submit your report, remember to record your Report Reference Number (starting with CIRS-). You may need it when dealing with banks, insurers or other organisations. Keep a record of any actions you take so you can update the police, your bank or other organisations if needed.
If you think your bank account or credit card details may have been exposed, contact your bank or financial institution immediately. They may be able to stop unauthorised transactions and disable your account.
If any of your customers or suppliers have lost money because of the incident, encourage them to contact their financial institution immediately.
Secure your accounts
Review your account security, even if you’re unsure whether it was compromised. This can help you:
- regain control of your account
- remove unauthorised access
- reduce the risk of future incidents.
Complete as many of the following steps as possible:
- change your password
- update your account recovery details so email address and phone numbers are correct
- sign out of all active devices to remove unauthorised access
- turn on multi-factor authentication
- remove rules or settings you don’t recognise
- review connected apps and services to remove access if you don’t recognise them
- check recent account activity for logins from unfamiliar devices, locations or times
- check all account folders for emails you didn’t send or actions you didn’t take.
For more details, learn how to secure your accounts.
Notify contacts and relevant third parties
If your email account is compromised, let your contacts know as soon as possible. This includes your customers, suppliers and colleagues. Telling them what has happened can help them spot suspicious emails and avoid scams, such as:
- requests for payment
- changes to bank details
- malicious links and attachments.
If the compromise has caused serious harm to your contacts, you may need to notify your customers and report it.
If you’re unsure about your reporting obligations:
- seek legal advice
- refer to the guidance on data breach reporting requirements from the Australian Information Commissioner (OAIC).
If you’ve been affected by identity theft, contact IDCARE for free support and advice.
What to do next
Take these extra steps to reduce the impact of a business email compromise.
Send a takedown request
If someone has sent emails pretending to be you or your business, confirm they came from your exact email address. Cybercriminals often use a similar-looking email address or domain name. This type of impersonation is known as domain spoofing.
If your domain is compromised, send a takedown request to the .au Domain Authority (auDA). They manage all domains that end in .au.
If a fake domain incorporates your registered business name or is a misspelling of your domain name:
- submit a complaint to auDA
- seek further advice
- contact the registrar and request they take it down.
You can find the registrar with a ‘whois’ lookup. For .au domains use whois.auda.org.au and for international domains use lookup.icann.org. If the results include a Registrar Abuse Contact Email, send your takedown request to that email. If there is no contact email listed, search for the registrar’s website and their abuse form or contact email.
When sending your takedown request to the registrar, include:
- who the registrant is
- the fake domain name
- the Registrant ID – usually an Australian Business Number (ABN) or an Australian Company Number (ACN)
- how the domain name is similar to yours.
Remember, if someone is impersonating you, they may use your details to appear more legitimate. If they have, make sure to highlight that information.
Contact the email provider
If someone uses an email account from a provider such as Gmail or Outlook to pretend to be you, this is called display name spoofing. The email may appear to come from you, but the email address is different.
If you’re affected by display name spoofing, send an abuse report to the email service provider. The provider may investigate and take action if needed.
- For Microsoft Outlook, Live or Hotmail, forward the email as an attachment to abuse@outlook.com.
- For Google Gmail, report abuse from a Gmail account.
- For other email providers, check their websites for abuse reporting methods.
How to get help and report
It’s important to record what happened and report the incident to us. Follow the steps outlined under report the incident.
You may also have legal obligations to report a data breach if personal information has been leaked. Follow the steps outlined under notify contacts and relevant third parties.
If you want to talk to someone, call our hotline on 1300 CYBER1 (1300 292 371). We’re available 24 hours a day, 7 days a week.
Stay protected
Learn more about how to protect your organisation from business email compromise.