We’ve had three clients this month receive the same thing: an email that appears to come from a supplier, the bank, or the accountant, saying banking details have changed, with a “new” invoice attached. The account belongs to a money mule. By the time anyone checks, the payment is gone and it is very difficult to recover.
This is called business email compromise, and it is now far more common than the dramatic hacking people picture. There is no clever code involved. It relies entirely on the fact that changing banking details on an invoice is a completely normal thing for a supplier to do.
How it usually plays out
In most of the cases we deal with, one of two things has happened. Either a mailbox somewhere in the chain — yours, or your supplier’s — has been accessed, and the attacker has sat quietly reading real invoices to learn the amounts, the names and the tone. Or nobody was compromised at all, and the sender address is simply a convincing lookalike domain.
The second one is more common and much cheaper to run, which is why you see it so often. A domain with one letter changed is easy to miss on a phone screen, and the display name at the top of the email can say absolutely anything.
The two habits that stop it
1. Phone to confirm, on a number you already have
Before you change any banking detail for any supplier, phone them on the number you already hold — from a previous invoice, your accounting system, or your own contacts. Never the number in the email requesting the change.
Do it every time, for every amount. Making it unconditional is the point. The moment it becomes a judgement call about whether this one looks suspicious enough to bother checking, it stops working, because the whole design of the scam is to look unremarkable.
2. Read the address, not the display name
The display name is free to fake. The part after the @ is not. Open the sender details properly and read the actual domain, character by character, especially on a phone where mail apps hide it by default.
Worth adding if you haven’t
- Multi-factor authentication on every mailbox. This is the single highest-value change most small businesses can make, and on Microsoft 365 or Google Workspace it costs nothing extra.
- SPF, DKIM and DMARC on your domain. These make it harder for somebody to spoof you to your own customers, which is the version of this that damages your reputation rather than your bank balance.
- A rule that nobody pays alone. Any change to payment details gets a second person’s eyes. Most successful fraud goes through one person working quickly under pressure.
If you think you’ve been hit
Speed matters more than anything else. Phone your bank immediately and ask them to recall the payment — within the first few hours there is a real chance. Then change the password on the mailbox involved, enable MFA, and check the mailbox rules, because attackers commonly add a rule that auto-deletes or hides replies so the conversation stays hidden from you.
If you have one of these sitting in your inbox and you are not sure about it, forward it to us and we will take a look. No charge and no pitch — we would rather spend ten minutes on that than a week on the aftermath.
