PrivacyCyber SecurityEmail Exposure Real StoriesInternational

She Noticed One Extra Letter in an Email. It Saved AU$1.2 Million.

Scan My ShadowSeptember 2, 20265 min read

TL;DR: A Westpac banker in Western Australia stopped a first-home buyer from transferring AU$1.2 million to scammers, after noticing the tone of an email was slightly off — and then spotting a single extra letter hidden in the sender's address. The real target wasn't the customer's inbox at all. It was her settlement agent's.

👉 See if your data's already leaked — free 30-second check →

Most of the stories in this series are about digital arrest scams in India. This one is different — and worth including precisely because of that. It shows the same core lesson shows up everywhere, in a completely different scam, on the other side of the world.

What happened in Perth

A young mother was buying her first home and preparing for property settlement — the final step where the purchase money changes hands. She visited Westpac's Riverton branch to make what she believed was a routine transfer, based on an email she'd received about the settlement.

Her personal banker, Neet Kukreja, had worked with her throughout the homebuying process and immediately sensed something was off. "The tone was slightly different. It didn't read like the previous emails, and that made me pause," Kukreja later said. The email asked for funds to be sent to a "settlement account" in a way that didn't match how these payments usually work.

Instead of processing the transfer, Kukreja cross-checked it against earlier communication and found that the staff member named in the reply was actually on leave. Then she spotted the detail that confirmed her suspicion: the sender's email address had one extra letter, invisible unless you were looking closely.

Rather than act on the email, she paused, brought in the branch manager, and contacted the settlement agent directly. The agent confirmed no such payment request had been sent. It turned out the agent's own email account had been compromised, and scammers were using it to send convincing, fraudulent payment instructions. The AU$1.2 million transfer never happened.

Why this isn't really "her email got hacked"

The most important detail in this story is the one that's easy to miss: it wasn't the customer's email account that was compromised, and it wasn't Kukreja's. It was a third party — the settlement agent — sitting in the middle of a legitimate transaction. That's the defining shape of a business email compromise (BEC) scam: attackers don't need to hack the person who's about to pay. They just need to hijack one trusted voice in a chain of emails everyone already expects to receive.

This is exactly why "check if my email's been leaked" isn't the whole story. Your own inbox can be spotless and you can still be targeted through someone else's compromised account, as long as that account is one you'd normally trust without a second thought.

What actually stopped it

What to do if you're expecting a large transfer

Business email compromise scams like this one rely on impersonating people you already trust — which is part of why knowing what's publicly discoverable about you and the people you work with matters. A Scan My Shadow report shows you what's already exposed about your own phone number and email, so you have a clearer picture of what a convincing impersonation attempt might be built from.

For the mechanics behind how attackers piece together enough detail to sound credible, see what OSINT is and how it's used to find information about you.

Similar interventions keep showing up internationally wherever this kind of scam is tried — see also The Renfrew Pensioner Who Nearly Lost £10,000 — Twice — Until Bank Staff Stepped In and The Grocery Store Cashier Who Stopped an 89-Year-Old From Being Scammed.

Frequently Asked Questions

Was the customer's own email hacked?

No. The settlement agent's email account was compromised, and scammers used it to send convincing but fraudulent payment instructions. This is a common pattern in business email compromise scams.

How do scammers use one wrong letter in an email address?

A lookalike domain that differs by a single character can pass a quick glance while routing replies to the scammer instead of the real sender.

Why are property settlements a common target for this scam?

Settlements involve large, one-off transfers with genuine urgency, multiple parties exchanging details by email, and a customer who isn't yet familiar with what a normal request should look like.

What can I do to avoid a similar scam?

Verify any request to change payment details by phone, using a number you already have on file — never one provided in the email itself — before transferring any large sum.

Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.

Phone + email scan · 1,500+ data sources worldwide · Full report
₹498one-time
Scan My Digital Footprint
Secure payment via Razorpay
  • Results within about 5 minutes
  • Clear, plain-English report
  • Delivered straight to your inbox
  • No login or passwords required
  • Scan data deleted after report is generated