Business Email Compromise: The Invoice Scam Built for Companies Your Size
7 min readEmail & Payment Fraud
There is a category of attack that produces no alert, installs nothing, breaks nothing, and moves more money out of small companies than ransomware does. It is called business email compromise, and if you only defend against one thing, defend against this.
It works because it is not really a technical attack. It is a social one that happens to arrive by email.
What the scam actually looks like
Here is the shape of it, assembled from how these cases consistently run.
A supplier you work with has a compromised mailbox — often not yours, theirs. The attacker does not act. They read. For two or three weeks they learn the vocabulary of the relationship: what you buy, what you pay, who signs off, when invoices land, how your finance person writes, that your CFO signs off "Thanks — J". They find the thread about the project that is already running late.
Then they wait for the right moment. Usually a genuine invoice is about to be sent. Sometimes it is the Friday before a holiday.
The email arrives in the correct thread, quoting the real conversation, from an address that is nearly right — one letter different, or a different top-level domain, or, if they compromised the mailbox properly, from the actual address. It says something entirely ordinary: our bank is being audited this quarter, please use the account below for this invoice. The amount matches the real invoice. The tone matches every previous email.
Your finance person pays it. There is no moment of suspicion because there is nothing to be suspicious of. Everything checks out — because everything except the account number is genuine.
You find out days or weeks later, when the real supplier asks where their money is.
The four variants you will meet
Supplier invoice fraud. As above. The highest-value variant, because the amounts are already large and already expected.
CEO fraud. A message that appears to be from you, to someone junior in finance, requesting an urgent transfer, often while you are visibly travelling or in a conference nobody can interrupt. It exploits the reluctance to double-check the founder. It frequently ends with a request for discretion — "don't loop in the team until it closes" — which is the tell, and which is also exactly why the recipient does not check.
Payroll diversion. An email that looks like it is from an employee to HR, asking to update their direct-deposit details before the next payroll run. Smaller amounts, so it gets far less scrutiny, and the same technique works every month.
Account takeover of your own mailbox. The most damaging version, because then the attacker is not imitating you — they are you. They send fraudulent invoices from your real domain to your real customers, delete the replies with a mailbox rule so you never see the confusion, and damage relationships you spent years building. If your customers ever get defrauded from your domain, the reputational bill outlasts the financial one.
Get the 31-point security checklist
The checklist, then one email a week on what changed and what a company your size should do about it.
Weekly. Unsubscribe in one click. See the checklist first.
Why the usual advice fails
Look at the standard guidance: check the sender address, look for urgency, beware of poor grammar.
Now check it against the attack above. The sender address was correct or one character off in a thread you were already reading. The urgency was real — that invoice genuinely was due. The grammar was fine, because they copied the writing style from three weeks of the supplier's own emails.
Every human-judgment defense fails here, and it fails for a structural reason: you are asking a person to detect a forgery of something they have never had reason to authenticate. Nobody verifies bank details on the other 200 invoices a year, so there is no baseline of suspicion for the one that matters.
Training does help — see how to spot a phishing email for the version worth teaching. But training alone cannot be your control for the thing that costs six figures. You need a control that works even when the employee is completely convinced.
The control that works: out-of-band verification
Here is the rule. It is boring, it takes ninety seconds per occurrence, and it defeats every variant above.
No change to payment details, and no unexpected or urgent payment request, is ever actioned on the basis of an electronic message alone — regardless of who it appears to come from.
Verification is by voice, on a phone number already held in our records from before the request arrived. Never a number, link, or contact detail contained in the message itself.
The person who verifies is not the person who received the request.
Three details carry the weight, and all three get dropped when companies write their own version:
Out-of-band. The verification must travel over a different channel than the request. If the attacker controls the mailbox, replying to the email to ask "is this really you?" is a question answered by the attacker. They will say yes. They will be charming about it.
A number you already had. The single most common way a good rule fails in practice. The email helpfully includes a phone number. It is answered by a person who confirms everything. The number must come from your own records, predating the request — your contract, your accounting system, the supplier's website you navigate to yourself.
Two people. Splitting receipt and verification breaks the authority gradient. A junior employee who has been told by the founder to keep something confidential will not challenge the founder. A second person who has never seen the email and is simply following the process will.
Then add three supporting measures:
- Make the rule unbreakable by seniority. State explicitly that no executive may waive it, including you, and that "the CEO said to skip it" is itself the strongest possible reason not to skip it. Say this out loud, more than once. Your finance person needs to believe that following the rule will never make you angry.
- Turn on MFA for email — the account-takeover variant starts with a stolen password. See MFA for small teams.
- Check your mailbox rules quarterly. Attackers create inbox rules that auto-delete or auto-forward messages containing words like "invoice", "payment" or "fraud", so their conversation stays invisible to the real owner. A rule you did not create is a compromise you did not know about.
Write the rule down (template)
Adapt and send. One paragraph beats a policy document nobody opens.
Payment verification — company policy
Any request to (a) change bank details for a supplier, employee or customer, or (b) make an urgent payment not already on the payment schedule, must be verified by telephone before it is executed.
The number called must come from our own records, not from the request. The call must be made by someone other than the person who received the request, and the caller records the date, number, and name of the person who confirmed.
This applies to every request, including requests appearing to come from company directors. No one can authorise skipping this step. Following this policy will never be held against you. Skipping it will.
If it already happened: the first four hours
Speed is the only lever you have, and the window is short.
Hour 1 — call the bank. Not email. Phone, and use the words "fraudulent transfer, please recall it". Funds are sometimes recoverable while they are still sitting in the receiving account, and often not once they have been moved on. This call is more urgent than anything else on this list, including working out what happened.
Hour 1 — report it. In the US, file with the FBI's Internet Crime Complaint Center at ic3.gov; their financial fraud process exists specifically to attempt recalls across banks and is materially more effective in the first day. In the UK, Action Fraud. In the EU, your national police cybercrime unit. Reporting is not paperwork — it is part of the recovery attempt.
Hour 2 — assume the mailbox is compromised until proven otherwise. Force a password reset and revoke active sessions for the affected accounts. Check for mailbox forwarding rules and unrecognised connected apps. Check whether MFA was enrolled with a device you do not recognise.
Hour 3 — find out which side was compromised. If the supplier's mailbox was the entry point, other customers of theirs are being targeted right now with the same thread. Call them, on the phone, and tell them.
Hour 4 — notify your insurer, and check what you are actually covered for. Many cyber policies treat funds-transfer fraud as a separate add-on rather than a core inclusion, sometimes with a much lower limit. Now is when you find out. See what underwriters ask for.
Then, once the immediate work is done: write down what happened without assigning blame, and fix the process gap. The employee who paid the invoice is not the failure. The absence of the rule is.
The one-sentence version
If money can leave your company because of an email, and no human voice on a known number is required to confirm it, then the size of your loss is set by the attacker, not by you.