Business email compromise: invoice and payment fraud

Business email compromise (BEC) rarely looks like a break-in. Instead, an attacker quietly reads or takes over a trusted mailbox — yours, a supplier's, or a customer's — and waits for a real invoice or payment conversation to hijack, often by changing bank details at exactly the right moment.

This page sets out how to contain a suspected case, what to do before more money moves, and how Cyber Crisis Desk turns those steps into a tracked response.

Signs of business email compromise

  • An invoice or payment email arrives with new bank details, often with urgency language.
  • A supplier or customer says they never sent an email you have, or never received one you sent.
  • Slightly altered email addresses or reply-to fields that do not match the real domain.
  • A mailbox rule quietly forwarding or hiding messages that mention "invoice", "payment" or "bank".
  • Unusual sign-in activity or a sign-in alert on a finance team member's account.
  • A payment goes to an account name that does not match the usual supplier, or a bank flags a mismatch.
  • Requests to change payment details by email alone, with no phone confirmation offered.

Safe immediate actions, in order

  1. Stop any pending payment tied to the suspicious email or changed bank details immediately, even if it means delaying a legitimate supplier.
  2. Call your bank or payment provider straight away if a transfer has already gone out. Recall requests are time-sensitive and success depends on speed.
  3. Verify any change of bank details out of band — by phone, using a number you already had on file, never one from the suspicious email — before paying anything against it.
  4. Secure the mailbox involved: change its password, enable two-step verification, sign out other sessions and revoke app passwords or connected apps.
  5. Check mailbox rules, forwarding and delegate access for anything you did not create, and screenshot it before removing it.
  6. Tell your finance team and the counterparties involved so nobody else acts on the same fraudulent details.
  7. Pause similar payments in progress until the mailbox and process have been checked.

Evidence worth preserving

  • The full email(s) with headers, including sender address and reply-to details.
  • Screenshots of any mailbox rule, forwarding address or delegate access found.
  • Bank transfer confirmations, reference numbers and the receiving account details.
  • Sign-in and activity logs for the mailbox around the relevant dates.
  • A written timeline of who was contacted, when, and what was said or agreed.

What to avoid

  • Do not pay or approve a bank-detail change based on an email alone, however convincing.
  • Do not confirm details using contact information found in the suspicious email itself — it may lead back to the attacker.
  • Do not delete the mailbox rule or suspicious email before capturing evidence of it.
  • Do not attempt to trace, identify or contact the attacker. Cyber Crisis Desk is strictly defensive: no hack-back, no tracing.
  • Do not assume a single mailbox reset ends it — check every account that shares credentials or delegate access.

Who to involve

  • Your bank — immediately, for any transfer already made, and to flag the receiving account details for other customers' protection.
  • The counterparty — the supplier or customer whose name was used, so they can check their own mailbox and warn other clients.
  • Your insurer — if you hold cyber or crime cover, check notification deadlines before agreeing any write-off.
  • Your data-protection regulator — if personal data of others was likely accessed through the mailbox. In the UK that is the ICO; other countries have their own authority and deadlines.
  • Law-enforcement or national reporting channels — for example Action Fraud and the NCSC in the UK, and the equivalent body where you operate.

Cyber Crisis Desk is not a law-enforcement, legal or forensic service and does not report or recover funds on your behalf. It prepares the structured information you need to do so quickly.

How Cyber Crisis Desk helps

A short free triage identifies whether this looks like a compromised mailbox, a spoofed domain, or a hardened supplier-payment process problem, and selects the matching playbook.

  • Client Next Action keeps stopping the payment and calling the bank at the top, ahead of any cleanup work.
  • Evidence requests collect headers, rules and bank references into one private case file.
  • Recovery tracks record mailbox hardening and payment-process fixes so nothing is left half-done.
  • Structured reports assemble a timeline you can hand to your bank, insurer or authority.
  • Monitoring and closure keeps the case open until follow-up checks actually pass.

See how the guided workflow fits together or compare the plans and the one-time Emergency Pass.

Hardening your payment process afterwards

  • Require a phone call to a known, pre-agreed number for any bank-detail change.
  • Add a second approver for payments above a threshold, separate from the person who receives invoices.
  • Enable two-step verification on every mailbox with finance access, not just the obvious ones.
  • Review delegate access and shared mailboxes regularly, and remove access no longer needed.
  • Train staff to treat urgency and secrecy in a payment request as a warning sign, not a reason to hurry.

Clear limitations

  • We cannot recover money already transferred, and only your bank can attempt a recall.
  • We cannot make account changes for you; only you or your administrator can act on your systems.
  • This is guided response, not a substitute for a qualified incident-response team in a severe, regulated or contested case.
  • We do not provide legal advice or make legal determinations for you.

Common questions

We already paid a fraudulent invoice. Is it too late?
Call your bank immediately regardless of how much time has passed. Recall requests can sometimes succeed even hours or days later, especially if the receiving bank is alerted quickly, but speed matters far more than anything else.
How do attackers know about our real invoices?
Usually because they have read access to a mailbox involved in the deal — yours, the supplier's, or an intermediary's — sometimes for weeks before acting, watching for a genuine payment conversation to hijack.
Is a phone call really necessary for every bank-detail change?
Yes, using a number you already had on file rather than one supplied in the email. This single habit blocks the great majority of BEC payment fraud, because the attacker cannot fake a call to a number they do not control.
Do we need to tell the supplier or customer involved?
Yes, promptly. Their mailbox may also be compromised, and other clients of theirs could be targeted with the same fraudulent details.

Related incident help

Work through it with a plan

Emergency triage is free and takes a couple of minutes.