Westpac blocked three outbound payroll runs this week for Melbourne hospitality groups after fraud teams flagged business-email compromise attempts that swapped wage and supplier account numbers hours before pay day, a pattern the bank said mirrors a surge in payment-redirection scams across Victoria’s restaurant and events sector.
What broke
Investigators told InfoHandle that attackers compromised or spoofed inboxes at two multi-venue operators and a catering collective, then emailed “updated” BSB and account details for high-volume suppliers and for individual chefs and floor staff. Payroll administrators approved the changes because the messages copied legitimate letterhead and arrived while managers were on site for AFL finals-week service.
Westpac’s institutional payments desk held the transfers when Confirmation of Payee checks showed account names that did not match the hospitality brands on file. No wages cleared to scam accounts, but one group missed a Friday pay cycle while HR re-verified every employee by phone—a step Scamwatch and Westpac both require but that understaffed back offices often skip when service is loud and urgent.
Who has the file
The Australian Cyber Security Centre has taken formal reports from at least one victim via ReportCyber, and Westpac referred the cluster to its dedicated scam intelligence unit. Victoria Police’s cybercrime squad confirmed it is aware of the hospitality targeting but has not named suspects; that gap is typical when criminals route through compromised Microsoft 365 tenants overseas.
IDCARE, the national identity and cyber support service, said call volumes from hospitality payroll staff rose in the first two weeks of September as venues restaffed for spring racing and festival calendars. Counselors urged operators to treat any “urgent” banking change as a callback event, using numbers from rosters rather than signatures on the email.
Bank controls in play
Westpac extended Confirmation of Payee to institutional clients in 2025, building on retail Verify checks that compare payee names against account records before money leaves. The bank said mismatches or unfamiliar accounts now trigger holds on bulk files uploaded through PaymentsPlus—the same rail many mid-size hospitality groups use for weekly wages.
SafeBlock, which lets customers freeze new debits from the mobile app, was not triggered in these cases because the fraud surfaced at the upload stage. Westpac nonetheless used the incidents to push dual approval for any change to beneficiary tables, a control large hotel chains already enforce but that single-site groups often defer.
What operators should verify
Scamwatch lists lookalike domains—an extra letter in a director’s name, a hyphen swapped in a catering domain—as the most common tell. Hospitality IT vendors said multifactor authentication on payroll inboxes remains uneven; several victims still allowed legacy POP access for booking platforms, which attackers used to hide rule-forwarding that sent copies of finance threads offshore.
Payroll bureaus that serve Melbourne’s laneway bars told InfoHandle they are rejecting email-only change requests unless a venue principal joins a three-way call. That friction costs minutes on busy nights but is cheaper than clawing back cleared funds, which banks rarely guarantee once payees withdraw cash.
What is still unknown
Westpac has not published loss figures for the hospitality cluster, and none of the three groups agreed to be named while staff reconfirm banking details. Law enforcement has not tied the Melbourne wave to a single syndicate, though metadata shared with ASD resembles invoice-scam traffic that spiked during prior tax-time campaigns.
For workers, the practical lesson is blunt: if pay is late after a “bank details updated” email, call payroll on a number from your contract, not the thread that announced the change. Westpac’s hoax line and ReportCyber intake remain the fastest paths to freeze a batch before it leaves the bank’s queue.
Hospitality accountants said they are snapshotting beneficiary lists nightly during finals season so any unauthorized edit shows up in a diff review Monday morning—a low-tech habit that outperformed expensive monitoring tools in two of the near-miss cases Westpac described to industry groups this week.
The Australian Signals Directorate noted in its latest annual threat report that business email compromise remains the most common cyber incident reported by Australian firms, a statistic hospitality payroll leads cited when asking insurers to cover callback verification training.








