Business payment fraud

A familiar invoice can carry unfamiliar bank details.

Compromised or imitated business accounts redirect real payments by changing bank details, creating executive urgency or taking over an existing email thread.

10 minute readPublished 23 August 2026Reviewed 23 August 2026Workplaces

What is changing now

The current pattern.

Business email compromise can use a lookalike address or a genuinely compromised mailbox. Official guidance highlights executive payment requests, changed supplier bank details, payroll diversion and real invoice threads taken over by an attacker. AI can improve the language or imitate a voice, but process controls—not perfect detection—provide the stronger defence.

How it works

Confidence first, then pressure.

An attacker studies public roles, suppliers, payment timing and internal language, or gains access to a real mailbox. They wait for a plausible transaction and then introduce a new account, urgent payment or confidential executive request.

Because the surrounding conversation may be genuine, staff can see correct order numbers, signatures and prior messages. The fraudulent element may be only one changed attachment, reply-to address or sentence directing payment to a different account.

The best control sits outside email: dual approval, a known supplier contact, a documented call-back procedure and a rule that bank-detail changes cannot be authorised by the same message that requests them. A workplace should make early reporting safe even when money has already moved.

Worked example

A realistic pattern, separated into evidence.

This composite example is educational. It does not describe a real person or reproduce a live malicious message.

Composite scenario

A real supplier thread announces new bank details

  1. 01
    The opening

    Accounts receives a reply inside an existing invoice conversation. It references the correct project and amount and says the supplier has changed banks after a merger.

  2. 02
    The escalation

    A revised invoice contains new account details. The sender says the finance director needs settlement today and that the usual supplier contact is travelling. A follow-up call appears to come from the supplier’s number.

  3. 03
    The decision point

    Thread history and caller ID may both be compromised or imitated. The material change is the destination account, and the request attempts to bypass the organisation’s normal verification process.

Warning signs

Reasons to stop and verify.

  • New bank details or a changed payee introduced only by email
  • An executive request that bypasses ordinary approval or procurement controls
  • Confidentiality, unusual urgency, threats or flattering appeals to senior trust
  • A subtle change in sender, reply-to domain or email routing
  • A supplier who is suddenly unavailable through the normal contact person
  • Payroll, gift-card or invoice instructions sent outside the established workflow

Independent verification

Test the request without using its evidence.

These checks deliberately move the decision away from the person, link, number or account that introduced the request.

  1. 01

    Verify the material change

    Treat a new account, payee, amount, timing or approver as a new transaction even when the surrounding email history is genuine.

  2. 02

    Use the approved vendor record

    Call a known supplier contact from the organisation’s existing records. Never use the contact details in the change request.

  3. 03

    Require separation of duties

    The person receiving or entering a changed payment instruction should not be the only person authorising it.

  4. 04

    Check the mailbox and business process

    Report suspicious messages to IT or security. Review sign-ins, forwarding rules and delegated access if an account may be compromised.

Safer response

Move the decision outside the contact.

  1. 01

    Pause the payment

    A legitimate supplier can tolerate a documented verification step for changed banking details.

  2. 02

    Call back independently

    Use an established phone number and speak to a known contact or switchboard.

  3. 03

    Follow dual control

    Apply the organisation’s approval threshold and separation-of-duties rules without making an exception for urgency or seniority.

  4. 04

    Make reporting safe

    Escalate suspected or completed fraud immediately. Blame delays the bank and security response.

If you already acted

Protect access and contact the real provider.

  • Contact the sending bank immediately and request its fraud or payment-recall process.
  • Alert the recipient bank, supplier and relevant law-enforcement reporting channel where appropriate.
  • Preserve full email headers, mailbox logs, invoices, approval records and payment details.
  • Secure affected mailboxes, remove malicious forwarding or delegation and reset compromised access.
  • Review adjacent supplier, payroll and customer conversations for further changed instructions.

Sources

Official guidance used for this article.

Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.