Think of ClickFit like road safety for processing payments
STOP your scroll
CHECK before you pay
PROTECT your business
Call 000 if you need urgent help
Cybercriminals often impersonate trusted businesses, suppliers, executives and colleagues to deceive people into transferring money or sharing sensitive information.
They may spend weeks or months monitoring business communications before changing payment details on a legitimate invoice or payment request, causing funds to be transferred to a bank account controlled by criminals.
Known as Business Email Compromise (BEC), this type of cybercrime can affect businesses of any size. Anyone responsible for processing invoices, managing payments or approving transactions may be targeted.
This is why being ClickFit is so important to help Australians recognise BEC warning signs and protect their business from financial loss.
STOP your scroll
CHECK before you pay
PROTECT your business
It often begins when criminals gain access to a legitimate email account or create an email address that closely resembles a trusted organisation. They monitor communications to understand how payments are processed. They may then send convincing payment requests or alter the account details on a legitimate invoice before resending it, causing payments to be directed to a bank account they control.
Common warning signs include:
Criminals often create a sense of urgency by claiming payments are overdue, demanding immediate action, requesting secrecy or pressuring staff to bypass normal approval processes.
Always independently verify requests to change payment details or transfer funds using trusted contact information. Do not reply directly to the email or use the contact details provided in the message.
The impact of BEC can extend beyond financial loss. Victims may experience operational disruption, recovery costs, reputational damage, loss of trust and significant emotional stress.
ClickFit is a simple six step approach that helps businesses and employees identify BEC warning signs and verify payments before money is sent.
Pause before you action any invoice, email, payment request or bank detail changes. Criminals are counting on you to rush. Always double-check.
Compare bank account details with previous invoices and be alert to changes in bank details, payment processes and email addresses.
Watch for slight changes in email addresses or domains, unexpected emails, calls or shared documents, and unusual requests for payment.
Always verify payment requests or changes to bank details using a trusted phone number or in person. Never use contact details provided in the email.
Be suspicious of urgent payment requests, demands for secrecy, or attempts to bypass normal approval processes. Criminals create pressure to stop you from checking.
If you have transferred money or something doesn’t feel right, call your bank via their official contact, notify your IT team and report it to police through cyber.gov.au/report
Follow these steps: