How criminals get inside the conversation
The usual entry point is a compromised email account, either at the supplier or at the customer. Credentials are obtained through a phishing page, then the mailbox is monitored quietly for weeks while the criminal learns who pays whom, on what terms and in what tone.
When a large invoice is due, they act. Sometimes they reply within the real thread from the real account; sometimes they register a near-identical domain, swapping a letter or adding a word, so the reply looks right at a glance. A mailbox rule often hides their messages from the legitimate owner.
- A compromised mailbox watched silently for weeks
- A lookalike domain differing by one character
- A reply inside a genuine, ongoing email thread
- Hidden mailbox rules concealing the criminal's messages
- Timing aligned to a real, expected large payment
The three common variants
Supplier bank-detail changes are the classic form: an invoice arrives with new account details, or a follow-up email corrects the details on an invoice already sent. The CEO or executive variant asks a finance employee for an urgent confidential transfer, usually while the executive is supposedly travelling and unreachable by phone.
The third targets individuals in high-value transactions, most damagingly conveyancing. A homebuyer receives 'updated' account details for a deposit or completion payment from what appears to be their solicitor. These are among the largest single-transaction losses reported anywhere.
- Supplier: 'our bank details have changed, please update'
- Executive: an urgent, confidential transfer requested by email
- Payroll: an employee's salary account 'updated' by email
- Conveyancing: new completion or deposit account details
- Any of these can arrive from a genuine, compromised address
The one control that stops it
Verify every change of bank details by voice, on a number you already hold, never a number in the email requesting the change. This single rule prevents the great majority of losses and costs a two-minute phone call against a five- or six-figure risk.
Make it a written policy rather than a habit, because the scam targets junior staff under time pressure who do not feel able to question an executive or delay a supplier. Staff must know that delaying a payment to verify it is always the correct decision and will never be criticised.
- Call back on a number from your own records, not the email
- Require dual authorisation above a set payment threshold
- Verify all detail changes in writing and by phone
- Confirm a new account with a small test payment first
- Make 'delay to verify' explicitly safe for every employee
Technical defences worth having
Enforce multi-factor authentication on every business mailbox, ideally with phishing-resistant methods such as passkeys or hardware keys, since mailbox compromise is the root cause. Monitor for mailbox rules that forward or auto-delete messages, a reliable indicator of an intruder.
Register lookalike domains where feasible, configure SPF, DKIM and DMARC so spoofed mail is rejected, and tag external email visibly in the client so a message that appears to come from a colleague is obviously outside. Our small business security checklist covers the wider set-up.
- Multi-factor authentication on every mailbox, no exceptions
- Alerting on new or hidden mailbox forwarding rules
- SPF, DKIM and DMARC configured and enforced
- External-sender tags visible in the email client
- Bank payee confirmation services enabled where offered
If a payment has already gone
Call your bank within minutes rather than hours and ask for an immediate recall, then contact the receiving bank's fraud team as well. Money is usually moved onward quickly, so the recovery window is measured in hours.
Then treat it as an intrusion, not just a payment error. Reset passwords and revoke sessions on the affected mailboxes, remove unauthorised rules, check who else in the thread may be compromised, and warn the counterparty. Report to Action Fraud in the UK, IC3 in the US, ReportCyber and Scamwatch in Australia, the Canadian Anti-Fraud Centre, or 1930 and cybercrime.gov.in in India.
- Call your bank immediately and request a recall
- Contact the receiving bank's fraud team directly
- Reset credentials and revoke sessions on affected mailboxes
- Remove hidden forwarding rules and review sign-in logs
- Warn the counterparty: their mailbox may be the compromised one
