Share

Cybercriminals Targeting Construction Sector in Sophisticated Email Scams

The Australian Federal Police (AFP) has sounded the alarm over a sharp rise in cyberattacks targeting Australia’s construction sector, with criminals using fake emails to steal millions from builders, suppliers and homeowners. The scam, known as Business Email Compromise (BEC), involves cybercriminals impersonating a business or employee to trick victims into redirecting legitimate payments into […]

Read

Thu 6 Nov 25 6:00:00 AM

tgb-logo-crop

The Australian Federal Police (AFP) has sounded the alarm over a sharp rise in cyberattacks targeting Australia’s construction sector, with criminals using fake emails to steal millions from builders, suppliers and homeowners.

The scam, known as Business Email Compromise (BEC), involves cybercriminals impersonating a business or employee to trick victims into redirecting legitimate payments into fraudulent accounts. According to the AFP, construction companies, especially small and medium-sized operators, have become prime targets because of their large transaction values, frequent invoicing, and limited cybersecurity resources.

“The construction sector, with its high-value transactions and complex subcontracting chains, has become an attractive target for organised cybercrime groups operating both domestically and offshore,” said Richard Chin, AFP Assistant Commissioner of Cyber Command.

TGB Podcast

Millions lost and climbing fast

The scale of the problem is staggering. According to the National Anti-Scams Centre’s 2024 Targeting Scams Report, Australians lost more than $152.6 million to BEC scams in 2024 a 66 per cent increase from the previous year. The AFP says it’s now among the top three self-reported cybercrimes in Australia, accounting for around 13 per cent of all business-related reports.

Builders are particularly at risk. Many are running fast-paced operations with tight cashflows and rely on email for everything from subcontractor invoices to supplier payments. Cybercriminals know this and they exploit it with alarming precision.

“We’re all busy and it’s easy to rush through tasks, but when it comes to payments, taking a moment to stop and verify can be the difference between protecting your hard-earned cash and becoming a victim,” Chin said.



How builders are being targeted

BEC attacks are not random. Criminals often monitor real construction project communications for weeks or even months before striking.

They use social engineering and real-time surveillance to mimic the tone, formatting, and timing of genuine emails, sometimes even referencing past correspondence or using hacked accounts to send legitimate – looking invoices.

Common tactics include:

  • Intercepted Invoices: Hackers gain access to legitimate email chains and modify bank details on invoices.
  • Spoofed Addresses: Fraudulent domains are created that closely resemble a real business (e.g., replacing an “l” with an “I”).
  • Urgency Scams: Victims are pressured to make “urgent” payments to avoid project delays.
  • Malware Links: Clicking a malicious link or opening an attachment quietly installs malware that captures login credentials for banking and email systems.

Once inside, the attacker can create hidden rules to automatically forward or delete messages containing words like “invoice” or “payment”, making detection difficult.



Real builders, real losses

In one case, a South Australian conveyancing firm narrowly avoided disaster after a client overseas received a fraudulent $338,000 invoice during a property settlement. Thanks to early detection and a joint effort through AFP Operation Dolos, the funds were recovered before being laundered through offshore accounts.

But not every victim is so lucky. A Tasmanian homeowner lost $120,000 after hackers intercepted her correspondence with a local construction company and sent a near-identical invoice with fake banking details. The money was never recovered.



Operation Dolos and the fightback

The AFP’s Operation Dolos, launched in 2020, is leading Australia’s response to this wave of financial cybercrime. The taskforce includes the Joint Policing Cybercrime Coordination Centre (JPC3), AUSTRAC, the Australian Criminal Intelligence Commission, and international law enforcement partners.

Its mission: track, intercept and disrupt organised cybercriminal syndicates and recover stolen funds where possible.

Chin says prevention remains the strongest defence:

“Cybercrime prevention is a shared responsibility. Taking simple steps like verifying payment details through a secondary channel can stop these scams in their tracks.”



What builders can do right now

For an industry that prides itself on hands-on skill and trust-based relationships, these attacks hit hard. But there are practical measures every builder can take today to reduce the risk:

1. Verify payment details verbally

Before paying large invoices or new suppliers, call the contact on a previously verified number to confirm account details. Never rely solely on email.

2. Use secure domains and multi-factor authentication

Ensure company emails use business-grade security (e.g., Microsoft 365 or Google Workspace) and enforce multi-factor authentication (MFA) for all users.

3. Train your team

Educate staff on spotting phishing emails, checking URLs, and avoiding suspicious attachments. Even one compromised account can expose an entire business.

4. Segregate financial approvals

Implement a two-step payment process where a second person must verify or approve all bank transfers.

5. Back up critical data

Regular, offline backups prevent total data loss if systems are compromised.

6. Report fast

If you suspect you’ve been scammed, contact your bank immediately and report it through ReportCyber(report.cyber.gov.au). Fast action dramatically increases recovery chances.



Building smarter defences

The AFP’s ClickFit campaign aims to raise awareness and help small businesses recognise early warning signs. The campaign’s message aligns with a broader theme we’ve seen across The Good Builder community: the need for smarter systems, stronger collaboration, and better education across the industry.

Cybersecurity may not feel like a traditional construction issue, but in today’s landscape, protecting your inbox is as critical as protecting your site.

Builders are being urged to treat digital security the same way they treat workplace safety through daily awareness, clear processes, and a culture of vigilance.

“It’s about mindset,” Chin added. “The same discipline builders apply on-site checking, verifying, double-checking needs to extend to their inboxes.”



The bigger picture

With housing demand surging and the average residential project now involving hundreds of online transactions, the construction industry has become a lucrative hunting ground for cybercriminals. The AFP’s message is clear: no one is too small to be targeted.

The rise of digital project management tools, online contracts, and electronic invoicing has brought huge efficiency gains but it’s also created an expanding attack surface. As construction businesses modernise, cybersecurity must evolve with them.

The next phase of growth for the sector won’t just be about building better homes, it’ll be about building safer systems.

TGB Editorial
Author: TGB Editorial

0 Comments

Submit a Comment

TGB Editorial

TGB Editorial

Related News

TRENDING

BROWSE FURTHER