Insight
Invoice fraud and business email compromise: the controls that stop payments going to criminals
Some of the most costly cyber incidents for small and mid-sized companies involve no malware at all. A criminal sends a convincing email asking for an invoice to be paid to new bank details, and a legitimate employee makes the transfer. Preventing it takes a combination of email security, finance processes and system controls.
How the fraud works
Business email compromise covers attacks in which criminals use email to impersonate a trusted party and trick someone into transferring money or revealing information. Invoice fraud is one of the most common forms: the victim receives what looks like an invoice or a change-of-bank-details notice from a real supplier, and pays the criminal’s account instead.
Attackers use several techniques. They may compromise a supplier’s or customer’s real mailbox, read ongoing conversations and reply within the thread at the right moment. They may register lookalike domains that differ from the real one by a single character. They may spoof the display name or, where email authentication is weak, the domain itself. Some impersonate executives and request urgent confidential payments.
Because the emails often continue real conversations with correct invoice numbers and amounts, spotting them by content alone is unreliable. Controls must assume that a convincing email can arrive.
Finance process controls
The single most effective control is independent verification of bank detail changes. When a supplier requests a change, finance should confirm it by calling a phone number already on file or taken from the supplier’s official website, never a number in the email requesting the change.
- Verify changes out of band
- Confirm any new or changed bank details through a known contact and channel before updating records.
- Separate duties
- Different people should change supplier master data and approve payments.
- Dual approval
- Require two approvers for payments above a threshold and for first payments to new accounts.
- Cooling-off period
- Hold first payments to newly changed bank details briefly to allow checks and notifications.
- Confirm with the supplier
- Send a notification to the supplier’s known contacts when their bank details change.
- Urgency is a signal
- Treat pressure, secrecy and requests to bypass normal steps as warning signs, not reasons to hurry.
Email security controls
Protect your own domain from spoofing with SPF, DKIM and a DMARC policy that moves towards quarantine or reject once legitimate senders are authenticated. That prevents criminals sending mail that appears to come exactly from your domain to your customers and suppliers.
Protect mailboxes from takeover with multi-factor authentication, ideally phishing-resistant methods for finance and executive accounts, and monitor for suspicious sign-ins and new inbox rules, which attackers often create to hide replies or forward messages.
Help employees spot lookalikes. External email warnings, highlighting of first-time senders and checks for domains similar to known suppliers or your own domain make impersonation easier to notice.
System and payment controls
Supplier master data changes in the ERP or accounting system should be logged, restricted to authorised roles and require approval. Reports of recent bank detail changes should be reviewed before payment runs.
In the euro area, Verification of Payee checks whether the payee name matches the account holder before a credit transfer is authorised. A mismatch warning on a supplier payment should stop the payment until the details are verified independently. Businesses submitting batch payments can opt out of the check for those batches, which removes this protection, so the decision should be deliberate.
Consider supplier portals where suppliers maintain their own details after authenticating, rather than sending changes by email, and electronic invoicing channels that deliver invoices through authenticated networks instead of attachments.
Protecting your customers
Criminals also impersonate your company to your customers, asking them to pay your invoices into fraudulent accounts. Tell customers clearly how your bank details will be communicated and that you will never change them by email alone. Include the legal name of the account holder and IBAN consistently on invoices, and publish a way to verify payment details.
If your own mailbox is compromised, attackers may use it to target customers, so incident response should include warning customers who were in recent contact.
When fraud happens
Speed matters. Contact your bank immediately to try to recall or freeze the payment, report to the police, preserve the emails and logs, reset compromised accounts and check for inbox rules and other persistence. Consider whether personal data was exposed, which may trigger data protection notification duties, and inform affected partners.
Afterwards, review which control failed and fix the process rather than blaming the person who made the payment. Attackers design these schemes to exploit normal, well-intentioned behaviour.
Questions
What is business email compromise?
Attacks in which criminals use email to impersonate trusted parties and trick people into transferring money or revealing information.
What is the most effective control against invoice fraud?
Independently verifying bank detail changes through a known contact and channel before updating records or paying.
Does DMARC stop invoice fraud?
It helps by preventing exact spoofing of your domain, but it does not stop lookalike domains or compromised supplier mailboxes.
Can Verification of Payee help?
Yes. A name mismatch warning on a payment in the euro area is a strong signal to stop and verify.
Why check for new inbox rules?
Attackers who take over mailboxes often create rules to hide or forward messages and avoid detection.
What should we do if we paid a fraudulent account?
Contact the bank immediately, report to police, preserve evidence, secure accounts and assess notification duties.
How do we protect customers from fake invoices in our name?
Explain how bank details are communicated, keep invoice details consistent and offer a way to verify payment information.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Complete Digital Transformation — The whole stack, sequenced — brand, web, marketing, CRM, automation, reporting and infrastructure — with benefits measured afterwards rather than projected and forgotten.
- Quote to cash without re-keying: where the handoffs break
- Product data is the e-commerce growth lever nobody budgets for
- Italy’s e-invoicing through the SdI: how Europe’s first B2B clearance model works in practice
- What law firm marketing can say in Germany, France, Italy, Spain and the Netherlands
- All insight articles
Worried about fake bank detail changes?
We tighten email authentication and mailbox security, add approval controls to supplier data in finance systems and set up supplier portals for bank details.
Get in touch