A construction company's money moves by email: quotes, variations, progress claims, supplier invoices, deposit requests. That is exactly the traffic business email compromise is built to intercept — and it is why construction keeps appearing in payment redirection loss figures. Australians lost $166.8 million to payment redirection scams in 2025, up 9.3% on the year before, and construction's mix of dozens of small suppliers, large one-off payments and site-based staff with no IT support makes it a natural target. This guide sets out what the attacks look like on a real project and how to build a security awareness programme around them.
Why construction gets targeted
- Money moves fast and by email. Progress payments, variations and deposit requests are routine on every job — a fraudster's fake updated-bank-details email slots straight into a normal Tuesday.
- Dozens of small suppliers per project. Every subcontractor and supplier is a legitimate invoice sender a scammer can imitate, and accounts staff process them in volume.
- A dispersed, mobile-first workforce. Site managers and foremen read email on phones between tasks; long-form training never reaches them.
- No IT department on site. The site office PC is shared, there is nobody nearby to ask, and small head offices rarely have dedicated security staff.
- High-value, time-pressured payments. A pending progress claim or a hold on a concrete pour creates exactly the urgency scammers script their emails around.
The attacks you will actually see
- Payment redirection (invoice fraud). An email that appears to come from a known supplier advises a change of bank details, often flagged as urgent because an invoice is due. The next genuine invoice is paid into the scammer's account.
- CEO or head-office fraud. A plain-text email from a lookalike domain asks project or finance staff to action an urgent payment or send a supplier list — no links or attachments, so filters see nothing to catch.
- Credential phishing. Fake password-expiry or MFA-reset notices for project portals, document sharing and email itself. One harvested password exposes tender documents, drawings and the inbox — and the inbox is the launchpad for the fraud above.
- Ransomware via the shared site PC. One infected attachment on the one computer everyone uses can lock drawings, contracts and program files.
| Threat | What it looks like | First-line response |
|---|---|---|
| Payment redirection | Supplier email with new bank details, often near an invoice due date | Callback on the number already on file before any change |
| CEO fraud | Plain-text urgent payment request from a lookalike domain | Verify by phone through a known contact, never the reply address |
| Credential phishing | Portal password-expiry or MFA-reset notice | Check the sender domain; report instead of clicking |
| Ransomware | Attachment on the shared site PC | Report immediately; isolate the machine |
Building the programme: five steps
- Start with a baseline. A gap assessment shows where the human-risk exposure actually sits before you buy anything.
- Run baseline awareness training. One short course on payment redirection, one on credential phishing — the two attacks that cost construction firms the most.
- Simulate monthly with construction pretexts. Bank-detail-change emails, tender-document links, timesheet-portal notices. Anyone who clicks is auto-enrolled into a micro-course on that exact trick. Cyber Aware's phishing simulations run this loop automatically from a library of 100+ templates.
- Keep it under five minutes and phone-first. Site staff complete micro-lessons on their phones between tasks; completion beats content length.
- Report monthly. Click rate, report rate and repeat clickers, trended over time — human risk reporting produces this per team and per person.
Making it stick on site
- Tie training to the toolbox talk. Five-minute micro-lessons sit naturally next to the safety briefing; both are habit-building, not one-off events.
- Celebrate reporters by name. A shout-out after each campaign builds the reporting habit that catches real attacks.
- Never punish a click. The moment the simulation feels like a trap, reporting dries up — and the next real attack goes unreported.
- Drill the callback habit. Recognition matters, but the process rule does more for the money: no bank-detail change is ever actioned without a phone call to the number already on file.
Evidence for tenders and clients
Human-risk controls are increasingly part of the conversation when head contractors and government clients assess suppliers: ISO 27001 requires security awareness training (Annex A 6.3), and certified organisations cascade those expectations down their supply chain. Monthly reporting gives you a dated trend line — click rates falling, report rates rising — that can be attached to prequalification questionnaires and tender responses instead of a one-off certificate.
If you are an MSP running this for construction clients, the programme can sit entirely under your brand — see the training platform and how it compares on simulation frequency, auto-enrolment and reporting.
Troubleshooting
- Staff still click bank-detail simulations. Escalate difficulty and repeat the pretext quarterly — recognition of the specific email plus the callback process rule closes most of the gap.
- Site staff never finish courses. Cut lesson length before cutting frequency; a five-minute phone lesson between tasks outperforms a 30-minute desktop module.
- Head office treats it as an IT problem. Put the managing director and finance lead in the same monthly report — when leadership appears in the chart, the programme stops being an IT chore.
- Repeat clickers persist. Treat it as coaching: targeted micro-training on the tactics that catch them plus a conversation about their actual inbox exposure.
FAQ
Do email filters make this unnecessary? No. Payment redirection and CEO fraud are plain-text emails with no links or attachments — there is nothing for a filter to catch, which is why the human layer carries those attacks.
How often should a construction company run simulations? Monthly for everyone, with finance and project managers getting a heavier cadence — they sit in the blast radius of invoice fraud.
What about subcontractors? Long-term subcontractor staff on your projects should be included — a white-labelled learner portal lets you extend the programme to them without adding them to your own directory.
Does this work for a small builder? Yes. A monthly simulation takes each person under a minute unless they click, and small teams typically improve fastest because results are visible to everyone.
What should finance change today? The process rule: no bank-detail change is actioned without a callback to the number already on file, and two people sign off on any payment over a set threshold. Training makes the rule stick.
Related guides
- How often should you run phishing simulations?
- Google Workspace phishing protection: complete 2026 workflow
- Security awareness training
- Phishing simulations
Sources
- National Anti-Scam Centre: Targeting scams report 2025 — $166.8m lost to payment redirection scams in 2025, up 9.3% year on year