Skip to main content

    Scam and Invoice Fraud Check (Australia)

    Checks an email, invoice or request to change bank details for signs of business email compromise and payment redirection scams, then walks the user through a call-back verification before any money moves. Use whenever a supplier, customer or staff member asks for a payment to new bank details.

    beginner
    Compliance & Legal
    Australian-Specific
    10 minutes
    Quick Start

    Checks an email, invoice or bank detail change for business email compromise and payment redirection warning signs, and walks the user through a call-back verification before paying.

    Complete Guide

    Scam and invoice fraud check

    What it does

    This skill reviews a suspicious email, invoice or bank detail change request and tells the user how worried to be and what to do next. It looks for the warning signs that Scamwatch and the Australian Signals Directorate (ASD) describe for business email compromise, also called payment redirection. It then walks the user through a call-back check on a phone number they found themselves, and records the result so the business has evidence of what it checked.

    Scamwatch warns that these scams can arrive in the same email thread as real messages from a supplier, and can copy logos and ABNs. So a message can look right in every detail and still be fake. The call-back is the step that matters most.

    When to use it

    • A supplier emails to say their bank account has changed.
    • An invoice arrives with payment details that differ from the last one.
    • A "manager" or "director" emails asking for an urgent transfer or gift cards.
    • A customer says they paid, but the money never arrived.

    What you need

    • The email or invoice, pasted in, with the full sender address.
    • The previous invoice or the supplier's record in the accounting system, for comparison.
    • Optional: Xero, MYOB or QuickBooks connector to look up the supplier's stored bank details and past payments, and a Gmail or Outlook connector to view the thread. None are required.

    Steps for Claude

    1. Do not approve anything yet. Tell the user to hold the payment until the check is done.
    2. Scan for warning signs and list each one found:
      • bank or payee details that changed without notice
      • an invoice nobody expected, or for work not ordered
      • a sender address or website with a small spelling change, an extra letter or number, a different ending such as .net instead of .com.au, or a hyphen added
      • urgency, secrecy, or pressure to skip the normal approval
      • a reply-to address that differs from the sender address
      • a request to change login or payment details through a link
    3. Compare with records. If a connector or the previous invoice is available, compare the BSB, account number, account name, ABN and amounts, and list every difference.
    4. Run the call-back. Tell the user to:
      • find the supplier's phone number from their own records, a past invoice they know is genuine, or the supplier's official website, never from the suspicious email
      • call and ask the supplier to read out their bank details, rather than reading the new details to them
      • record who they spoke to, the number called, the date and time, and the answer
    5. Decide. If the supplier confirms the change, record it and follow the business's normal approval process. If they do not, or the user cannot reach them, do not pay.
    6. If money has already gone, tell the user to contact their bank immediately and ask them to stop the transaction, then report to Scamwatch and to police through ReportCyber, and warn the supplier in case their email has been compromised. IDCARE (1800 595 160) can help with a recovery plan.
    7. Prevent the next one. Suggest a written rule: any bank detail change is verified by phone on a known number and approved by a second person. ASD also recommends MFA on email accounts and email authentication records (SPF, DKIM and DMARC) on the business's own domain.

    Output format

    1. Risk rating: high, medium or low, with the reasons in one line each.
    2. Warning signs found, as a list.
    3. Differences from the previous invoice or stored details, as a table.
    4. Call-back script, three or four lines the user can read out.
    5. Verification record: date, time, number called, person spoken to, outcome.
    6. Next steps.

    Australian rules and sources

    • Scamwatch, Business email compromise scams (warning signs, protection steps and what to do if affected): https://www.scamwatch.gov.au/types-of-scams/business-email-compromise-scams
    • Scamwatch, What to do if you've been scammed: https://www.scamwatch.gov.au/stop-check-protect/what-to-do-if-youve-been-scammed
    • Scamwatch, Report a scam: https://www.scamwatch.gov.au/report-a-scam
    • ASD, Preventing business email compromise (call-back on a known number, approval process, MFA, lookalike domains, SPF, DKIM and DMARC): https://www.cyber.gov.au/protect-yourself/securing-your-email/email-security/preventing-business-email-compromise
    • ASD, How to combat fake emails: https://www.cyber.gov.au/business-government/protecting-devices-systems/hardening-systems-applications/email-hardening/how-to-combat-fake-emails
    • ReportCyber: https://www.cyber.gov.au/report-and-recover/report

    Limits

    This check reduces risk but cannot prove a message is genuine. The final decision to pay rests with the business. This is general information, not legal or financial advice. If money has been lost, act on the bank and reporting steps before anything else.

    Example requests

    • "Our concrete supplier just emailed new bank details with this month's invoice. Is it legit?"
    • "Here's an email from 'our director' asking me to pay a new vendor today and keep it quiet. Check it."
    • "A customer says they paid our invoice last week, but it's not in our account. What happened and what do we do?"
    Usage Examples
    • →Our concrete supplier just emailed new bank details with this month's invoice. Is it legit?
    • →Here's an email from 'our director' asking me to pay a new vendor today and keep it quiet. Check it.
    • →A customer says they paid our invoice last week, but it's not in our account. What happened and what do we do?
    Skill Details

    Source

    custom

    Author

    Tech Horizon Labs

    Version

    1.0

    Complexity

    Compatible With

    Claude web
    Claude code
    Claude api

    Prerequisites

    • The suspicious email or invoice
    • Previous invoice or stored supplier details

    Tags

    invoice scam check
    business email compromise
    payment redirection
    bank details change
    scamwatch
    security
    Need Help?
    Learn more about using Claude Skills effectively