A Western Australian government audit recently uncovered something that should concern every Australian business owner: poorly configured Microsoft 365 settings directly enabled a $71,000 invoice fraud. The attacker didn't need sophisticated hacking tools. They just needed one compromised email account and weak security settings to pull it off.

If government agencies with dedicated IT resources can fall victim to these attacks, this highlights a significant risk for small businesses running on tighter budgets. The solution involves both technical fixes and something equally important: phishing training for employees Australian businesses often overlook until it's too late.

What Actually Happened in the WA Government Fraud

The WA Office of the Auditor General documented a textbook business email compromise attack. A senior officer received a phishing email and clicked something they shouldn't have. The attacker then registered their own device to the compromised account from overseas, thanks to weak multifactor authentication settings that didn't flag the suspicious activity.

Once inside, the attacker set up email forwarding rules to hide their tracks. They spent weeks reading the officer's emails, learning how the organisation processed payments, who approved invoices, and what communication patterns looked normal. Then they sent fraudulent invoices that sailed through the approval process.

The fraud went undetected for a full month. The organisation eventually recovered the money through insurance and their bank, but here's the concerning part: investigators couldn't complete a proper forensic review because the agency hadn't kept sufficient logs. And at the time of the audit, the underlying M365 settings that made the attack possible still hadn't been fixed.

The Configuration Gaps That Made It Possible

The audit examined seven WA government entities and found security control weaknesses across all of them. None had data loss prevention controls set up properly across their M365 applications. All seven allowed staff to sync work data to personal cloud storage accounts like Dropbox, Facebook, and Google Drive with no technical barriers.

For authentication, these organisations relied on SMS text messages, voice calls, and email one-time passwords. The Australian Signals Directorate has specifically flagged these methods as highly susceptible to phishing attacks and social engineering.

A separate incident at one of the audited entities saw personal information about 32 individuals, including minors, emailed to a third-party provider. That provider uploaded the data to Dropbox, which was later compromised. Because no data loss prevention controls existed, the entity couldn't even determine the full extent of what was exposed.

Why This Matters for Small Business

You might think government security problems don't apply to your accounting firm, legal practice, or franchise operation. But the same M365 configuration issues exist in most small business setups. The difference is that government entities often have insurance and banking relationships that help them recover stolen funds. Many small businesses don't.

The attack pattern described in the WA audit, where someone compromises an email account and studies communication patterns before sending fake invoices, works against any organisation that processes payments. Professional services firms handling client funds are particularly attractive targets.

Email security testing through regular security awareness programs can help staff recognise phishing attempts before they click. But even well-trained employees make mistakes when they're busy, stressed, or distracted. That's why the technical settings matter too.

Simple Steps to Check Your M365 Security

You don't need to be a technical expert to review some basic M365 settings. Start with these:

  • Check your MFA settings. If you're using SMS or email codes, consider switching to an authenticator app. Microsoft Authenticator is free and more resistant to interception.
  • Review external sharing permissions. Can staff share files with anyone outside your organisation? Can they sync data to personal cloud accounts? You can restrict this in the admin centre.
  • Look at email forwarding rules. Attackers often set up forwarding to hide their activity. You can audit existing rules and restrict who can create them.
  • Enable audit logging. If something goes wrong, you'll want records of what happened. M365 can log sign-ins, file access, and email activity, but you may need to turn this on.

If these steps sound confusing, that's understandable. The ACSC provides guidance on personnel security that includes practical recommendations for businesses of all sizes.

Why Phishing Training for Employees Australian Businesses Matters

Technical controls help, but they can't stop every attack. The WA fraud started with a phishing email that someone clicked. Research on phishing training shows that regular testing and training reduces click rates over time, but the training needs to be ongoing and realistic.

One-off security presentations don't work well. People forget. They get complacent. New staff join without the same training. The employees who clicked on phishing emails six months ago might click again if they haven't practised recognising the warning signs.

Simulated phishing attacks give employees safe practice spotting suspicious emails. When someone clicks a test phishing email, they get immediate feedback explaining what they missed. Over time, this builds pattern recognition that kicks in automatically when a real attack arrives.

The WA audit found that organisations weren't conducting security assessments of third-party vendors during onboarding. This is another area where training helps. Staff who understand phishing risks are more likely to question unusual requests, even when they appear to come from trusted partners.

Connecting the Dots Between Settings and Training

Good M365 configuration and good phishing training work together. Strong MFA settings mean that even if someone falls for a phishing email and enters their password, the attacker still can't access the account easily. Data loss prevention controls mean that even if an account is compromised, sensitive information can't be exfiltrated without triggering alerts.

But organisational phishing research shows that technical controls alone aren't enough. Attackers adapt. They find workarounds. The human element remains the most flexible line of defence, which is why ongoing training matters.

For small businesses without dedicated IT staff, the challenge is finding time to manage both the technical side and the training side. Automated solutions can help. Platforms that run regular email security testing without requiring manual intervention let you maintain a training program without adding to your workload.

What You Can Do This Week

Start with awareness. Log into your M365 admin centre and look at your current security settings. Microsoft provides a Secure Score feature that identifies potential improvements. You don't need to fix everything at once, but knowing where you stand helps.

Then consider how you're training your team. If the last security training was a PowerPoint presentation six months ago, your staff are probably overdue for practice. Regular simulated phishing attacks keep recognition skills sharp without taking much time.

Want to see how your team would respond to a realistic phishing email? Start free and send yourself a test email. You might be surprised how convincing modern phishing attempts have become, and how much difference regular practice makes.