Generic advice about business email compromise tells you to verify changed bank details. Good advice, and it stops short of the thing that makes this expensive for a migration practice specifically.
When a payment is redirected out of a general business, the business loses money. When it happens in a migration practice, the money that moves is frequently the client's — funds held for a visa application charge, a disbursement, or fees not yet earned. The fraud does not extinguish your obligation to that client. You still hold their money on the ledger, you still owe the departmental charge, and you still have to answer for an account that no longer balances.
The ASD's small business cyber security guide covers the general controls. This is about the shapes the attack takes when the business is a migration practice, and the obligations that attach afterwards.
Why practices are attractive targets
Three characteristics combine badly.
Large, expected, one-off payments. A visa application charge for a family can run into five figures. Clients expect to be told an amount and where to send it, and they have no baseline for what your bank details should look like.
Clients who cannot easily verify. Many are offshore, in a second language, in a different time zone, and dealing with a professional they have never met in person. The social conditions that let someone question an unusual instruction are largely absent.
Urgency is normal. Deadlines are real, bridging visas cease, and "this must be paid today or the application cannot be lodged" is a sentence your clients have genuinely heard from you. It does not read as a red flag because it is not, usually.
The four shapes it takes
The invoice interception
The attacker sits in a mailbox — yours or the client's — reads until an invoice is sent, then sends a follow-up correcting the bank details. The email is genuine in every respect except the account number, and it often arrives from the real address, because the mailbox is compromised rather than spoofed.
Mailbox rules are the tell. An attacker who has read access will usually create a rule that files replies containing "invoice" or "payment" into an obscure folder so the real conversation is invisible to the account owner. Checking rules is a five-minute exercise almost nobody performs.
The agent impersonation
A client receives an email that appears to be from you, asking them to pay a departmental charge to a new account, or to a "Department of Home Affairs payment portal". Clients have no reliable way to tell a lookalike domain from yours, and the request is entirely consistent with what you have already told them to expect.
The document lure
Not every phishing email asks for money. A message purporting to carry a visa grant notice, a request for further information, or a police certificate is opened because opening documents is the job. Two consequences follow: credential theft, and a document of unknown provenance entering the matter.
That second one has a Code dimension. Section 20 prohibits giving a government official a document you suspect, or reasonably ought to suspect, is false or misleading unless you disclose the suspicion or take all reasonable steps to determine the position. Section 41 prohibits giving a client a false or misleading document on similar terms. A file that has had unauthorised access is a file whose documents need checking before anything is lodged or sent on.
The internal instruction
An email that appears to come from the principal, to a bookkeeper, asking for a transfer to be actioned quickly and quietly. It works best in practices where the principal is genuinely unavailable and genuinely does send terse instructions.
Verification that survives a compromised mailbox
The controlling principle is that the channel used to request a change cannot be the channel used to verify it. If the request arrives by email, the verification cannot be by email — including a reply, because a reply goes to whoever controls the mailbox.
Practically:
- Call back on a number you already hold from the file or the signed agreement, never the number in the message.
- Set bank details once, at engagement, and treat any change as a new verification event regardless of who asks.
- Tell clients in the agreement that your details never change, and that any message saying otherwise should be treated as fraudulent until they have spoken to you. A client who has been warned is a far better control than any technical measure.
- Require two people for any change to a payee or a payment above a threshold you set.
- Send payment instructions through the portal, not as an email attachment, so there is one authoritative place to check.
The obligations that attach afterwards
This is where migration practices are exposed in ways a general business is not.
The money is still owed. Where redirected funds were client money, the client's ledger position does not change because you were defrauded. Section 50 restricts what may be paid out of the account holding client money, and section 50(1)(f) prohibits paying out more for a purpose than was paid in for that purpose — so covering the shortfall by drawing on other clients' balances is a second breach on top of the first. Our guide to trust accounting covers the account discipline this assumes.
The deadline does not move. A departmental charge that did not arrive can invalidate an application. The fraud is a reason; it is not a remedy.
The breach obligations start. A compromised mailbox in a migration practice has almost certainly exposed passport scans, police certificates and health information. That is a data breach question with its own clock, quite separate from the money.
The file needs re-verifying. Anything received or sent during the compromise window is of uncertain provenance.
The five-minute check
Do these today rather than after an incident:
- Are there mailbox rules you did not create, on any account?
- Does your standard invoice carry a "our details never change" warning?
- Is there a call-back rule for payee changes, using a number from the file?
- Does the client agreement warn clients about payment fraud?
- Can any one person move client money alone?
- Would a member of staff feel able to question an urgent instruction from the principal?
That last one is a culture question, and it is the control that fails most often. A practice where nobody delays a partner's urgent request has removed its last line of defence.
Where a system helps
Business email compromise depends on email being the system of record. It works because the invoice lives in a thread, the bank details live in a PDF, and the only version of the truth is whichever message someone read last.
Moving payment instructions into a portal, keeping invoices in a system rather than as attachments, and giving clients one authoritative place to check what they owe removes most of the attack surface — not by making email safer, but by making it non-authoritative.
LodgeHQ issues invoices and payment details from the matter and shows the client the same record you see. Our comparison of CRM options for migration agents covers the wider choice; start a free trial to see how it changes the payment conversation.
Verify before you rely on it
Attack patterns change faster than published guidance. Check the ASD's current small business material, and report incidents through cyber.gov.au — reporting is also how the sector's guidance gets updated.
This is general information for migration practices, not security or legal advice. If money has already moved, contact your bank immediately, then get legal advice on your obligations to the client whose funds were involved.