Verify any change of payment details by phoning a number you already had, never one from the email. This attack succeeds because the message is genuinely from a compromised account or a near-identical address.

How it works

Somebody gains access to a supplier's email, or registers a domain one character different from theirs.

They watch the correspondence, learn who invoices whom and for how much, and wait for a real invoice to be due.

Then they send one that looks correct in every respect, with a note that bank details have changed.

You pay it, because everything about it is familiar: the format, the amount, the person's name, the ongoing conversation it appears to continue.

The money goes to an account that is emptied within hours, and it is very rarely recovered.

Why it succeeds against careful people

Because none of the usual advice applies.

There is no obvious spelling mistake, because the message was written by somebody reading your actual correspondence.

The address is either genuine, from a compromised account, or differs by a character nobody reads: a letter swapped, a hyphen added, a different extension.

The timing is right, because they waited for a real invoice.

And the request is plausible, because businesses do change banks.

This is not a badly written scam. It is a well-researched one, and being careful about obvious fakes does not protect against it.

The one rule that works

Verify every change of payment details by voice, on a number you already had.

Not the number in the email. Not a number in the signature. A number from a previous invoice, your own records, or their website.

Speak to a person and confirm the change. That single step defeats the entire attack, because the person on the phone will say they did not send it.

It takes two minutes and it applies without exception, including when the request seems urgent, which is precisely when it will seem urgent.

A worked example

A contractor who received an invoice from a materials supplier he had used for six years.

The email came from the account manager he always dealt with, referenced the correct delivery, and carried the right amount.

It said their bank had changed and gave new details.

He paid it. Three weeks later the real supplier chased the unpaid invoice.

The account manager's email had been compromised, and the message had genuinely come from her account, which is why nothing looked wrong.

The bank could not recover it. The supplier still needed paying, so he paid twice.

He now phones for any change to payment details, on a number in his own records, and has done so twice since with no difficulty.

What to watch for

The third requires deliberate attention. Nobody reads addresses carefully, and one transposed letter is invisible at a glance.

The version aimed at you

The same attack runs in the other direction, and small businesses are frequently the source rather than the target.

If your email is compromised, your customers receive invoices with altered details, and they pay them.

You then have customers who have paid somebody else, still owe you money, and are unhappy with both facts.

Which makes securing your own email a protection for your customers as much as for you, and it is the strongest practical argument for two-factor on the account you send invoices from.

The counter-case

Where verification is impractical and something else is needed.

High-volume payments where phoning about every change would be unworkable. There the answer is a documented process: a second approver, a callback threshold, and a standing rule that details are never changed by email alone.

Overseas suppliers in different time zones, where a call is difficult. A video call or a message through a channel you already use, rather than replying to the email, is the equivalent.

What is never acceptable is verifying by replying to the message, because that reply goes to whoever sent it.

The internal version

A variant aimed at businesses with staff, and it works on the same principle.

An email appearing to come from the owner, to whoever handles payments, asking for an urgent transfer. Frequently while the owner is known to be away, which the attacker learned from an out-of-office reply.

It is short, slightly pressured, and asks for discretion because a deal is confidential.

The defence is the same: verify by voice, on a known number, regardless of who appears to have sent it and how urgent it seems.

Which requires saying explicitly to whoever handles money that they will never be criticised for checking, because the attack relies on somebody being reluctant to question the boss.

That permission, given in advance, is worth more than any technical control.

Telling your own customers

A courtesy that protects both sides.

State on your invoices that your bank details will never change by email, and that any such message should be verified by phone.

That single line means a customer who receives a fraudulent invoice in your name has been told what to do about it.

It costs nothing and it is one of the few security measures that visibly protects somebody else.

Some businesses also confirm bank details verbally at the start of a new relationship, which sets the expectation from the very beginning.

If it has already happened

  1. Contact your bank immediately, since speed is the only thing that helps.
  2. Contact the receiving bank if you can identify it.
  3. Report it to the police and to the national anti-fraud centre.
  4. Tell the supplier, whose email may be compromised.
  5. Check your own accounts for signs of access.
  6. Warn your customers if your email was involved.

The first is genuinely time-critical. Recovery is occasionally possible within hours and almost never after a day.

Recovery of transferred funds depends almost entirely on how quickly the receiving bank is contacted, which is why this list starts where it does rather than with reporting.

The account most worth protecting first is covered in turning on two-factor everywhere that matters.


Frequently asked questions

How does this work?

Somebody accesses a supplier's email or registers a near-identical domain, watches the correspondence, and sends a real-looking invoice with changed bank details.

Why does it succeed against careful people?

There are no spelling mistakes, the address is genuine or differs by one character, the timing matches a real invoice, and businesses do change banks.

What is the one rule?

Verify every change of payment details by voice, on a number you already had. Not the number in the email. That single step defeats the whole attack.

What should I watch for?

Any change of bank details, urgency, a slightly different address, a reply-to that differs from the sender, or an unexpected new contact.

Can this happen in reverse?

Yes. If your email is compromised, your customers receive altered invoices and pay them, then still owe you money and are unhappy about both.

What if it has already happened?

Contact your bank immediately, since recovery is occasionally possible within hours and almost never after a day. Then report it and warn anybody affected.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Invoice arrived with new bank details?

Phone a number from your own records before paying. That two minutes is the whole defence.

Start a Conversation