← Back to Blog

August 21, 2026 · Backgrounder Team

The Invoice Is Real. The Account Number Isn't.

Most fraud advice assumes the message will look wrong. Business email compromise is built on the opposite premise: it looks exactly right, because it is describing something your company was already going to do.

There is no malware, no attachment, and often nothing for a security filter to catch. There is an invoice you were expecting, from a supplier you use, arriving on the schedule you would expect it — with one detail changed. It is now one of the most common things people bring to us for a second opinion.

The attack isn't a break-in. It's a payment you already approved, going to a new account number.


Why it works when other things don't

A phishing email asking you to sign in somewhere is asking you to do something unusual. A payment request is asking you to do your job.

Before the request arrives, the attacker has usually been reading. A compromised mailbox — yours, your supplier's, your lawyer's — hands over the invoice schedule, the amounts, the names of the people who approve things, the way your team writes to each other, and the exact moment a payment is due. When the fraudulent message finally lands, it isn't a guess. It sits inside a real thread, in the right voice, at the right time.

That's also why "check the sender" fails here. If the supplier's mailbox is the compromised one, the email genuinely came from your supplier. Nothing about the address is wrong. Only the bank details are.

The four shapes

The changed bank details. A supplier you pay regularly writes to say they've switched banks, and here is the updated remittance information for the invoice you already have. This is the most common form and the most expensive, because the payment was legitimate — only the destination was replaced.

The executive request. A message that appears to come from an owner, a CEO, or a finance director, asking for an urgent transfer, a gift card purchase, or a payroll change, usually with a reason not to discuss it: a deal in progress, a flight about to take off, a supplier who must be paid today. The pressure is the product.

The payroll diversion. An email from an employee to HR or payroll, asking to update their direct deposit details before the next run. It's small, it's routine, and it usually isn't noticed until someone doesn't get paid.

The closing wire. A property purchase, an acquisition, an escrow payment. Someone in the chain — agent, lawyer, title company, buyer — has a compromised mailbox, and revised wire instructions arrive shortly before the money is due. These are the hardest to recover because the amounts are large and the transfer is a single one-off, so nothing looks out of place afterwards.

The one control that stops all four

Every version of this attack has the same weak point: it can only exist in a channel the attacker controls. Leave that channel and it collapses.

Any change to where money goes gets confirmed by voice — on a number you already had, before the payment leaves.

  • New or changed bank details on an invoice: call the supplier's known contact before the payment is released, not after.
  • Urgent transfer request from a senior person: call them. If they're genuinely mid-flight, the payment can wait until they land.
  • Payroll detail change: confirm with the employee on the number in your HR records, or in person.
  • Wire instructions for a closing: call the firm on the number from the engagement letter or their published main line, and read the account details back to them digit by digit.

Never use a phone number, link, or contact address contained in the message. Supplying a helpful number to call is a standard feature of these operations, and it will be answered.

Two more habits worth making permanent: require two people to approve any change to payment details, and tell your suppliers and clients in writing that you will never change bank details by email alone. That second one protects you in both directions — it makes your own change requests verifiable, and it gives your customers a reason to call when a fake one arrives.

Tells that survive a genuine sender

The sender may be real, so the useful signals are in the request itself.

  • The destination changed. New account, new bank, new country, "our usual account is under audit." Any change to where money goes is unverified by default.
  • Urgency arrives with secrecy. Do it today, don't loop in the team, I'm about to be unreachable. Legitimate finance requests survive a phone call.
  • The process is being routed around. A request that skips the usual approver, the usual system, or the usual paperwork is worth a pause even when the person asking is real.
  • The reply is addressed somewhere else. Hit reply and check where it actually goes before typing. Attackers redirect replies to a lookalike domain so the real owner never sees the exchange.
  • The domain is nearly right. One letter added, one swapped, .co instead of .com, a hyphen that wasn't there before. Read the registered domain — it sits immediately to the left of the first single slash — rather than the display name.
  • The timing is too good. A request that lands exactly when a payment is due suggests someone has been reading the thread.

If the money has already gone

Speed matters more than anything else here. Funds are recoverable while they're still sitting in the receiving account, and that window is short.

  • Call your bank now and use the words payment fraud or wire fraud. Ask them to attempt a recall and to contact the receiving bank.
  • Report it at ic3.gov, the FBI's Internet Crime Complaint Center. Reports filed quickly can help freeze funds that haven't been moved on yet. Outside the US, report to your national fraud reporting service and your bank in parallel.
  • Contact the real counterparty by phone. One of the two mailboxes in the exchange is usually compromised, and they need to know before the next customer is hit.
  • Preserve the emails. Keep the originals with their full headers. Deleting them removes the evidence investigators and your insurer will ask for.
  • Check the mailbox for rules. Attackers add forwarding rules and filters that hide replies, so the conversation can continue in your name. Remove anything nobody created deliberately, then reset the password and revoke active sessions.
  • Tell your insurer. If you hold cyber or crime cover, notification deadlines are often measured in days.

Summary

  • Business email compromise redirects a real payment rather than breaking into a system, so there's often nothing for a filter to catch.
  • A genuine sender proves nothing — the compromised mailbox may be your supplier's, not yours.
  • Confirm every change to payment details by voice, on a number you already had, before the payment goes out.
  • Urgency plus secrecy is the signature of the executive-impersonation version.
  • If money has left, act in hours: bank recall, ic3.gov, call the counterparty, keep the evidence.

Got an invoice or a payment request in front of you right now that you're not certain about? Paste it into a free Quick Check with Carmen for a read in seconds, or get help if a payment has already gone out.

Frequently asked questions

What is business email compromise?

Business email compromise is fraud that uses email to redirect a legitimate payment rather than to break into a system. The attacker either takes over a real mailbox or imitates a familiar sender, then sends a request that fits normal business — an invoice, a change of bank details, a payroll update, wire instructions for a closing. There is usually no malware and no attachment, which is why it passes security tools that are looking for one.

How do I verify a change to a supplier's bank details?

Call the supplier on a phone number you already had before the request arrived, taken from your own records or an existing contract, and confirm the change with a person you can identify. Never use a phone number, link, or address supplied in the email itself, because if the request is fraudulent so is the contact detail inside it. Treat every change of payment details as unverified until that call happens, no matter how routine the request looks.

What should I do if the payment has already gone out?

Act within hours rather than days. Call your bank immediately, say the words payment fraud or wire fraud, and ask them to attempt a recall. Report it at ic3.gov, the FBI's Internet Crime Complaint Center, which can help freeze funds still sitting in the receiving account. Then contact the real counterparty directly, because one of the two mailboxes involved is usually compromised, and keep the original emails with their full headers instead of deleting them.

Who inside a company is usually targeted?

Whoever can move money or change where it goes. That means accounts payable, bookkeepers, office managers, payroll administrators, and anyone handling a property closing or a large one-off purchase. Attackers also imitate executives to pressure those people, so seniority is not protection — the target is the process, not the person.

Stay one step ahead of scams

Spot red flags early and protect yourself, your family, and your business

Try for free