Guides

Business Email Compromise and Invoice Fraud: How to Stop It

Business email compromise (BEC) explained for small firms: how invoice fraud and fake bank-detail changes work, the warning signs, and controls that stop them.

Business email compromise does not need malware, a virus, or a broken password. It needs one convincing email asking your bookkeeper to pay a real invoice to a new bank account. Because the invoice is genuine and the sender looks genuine, standard spam filters see nothing wrong. Here is how the fraud actually unfolds and the handful of process controls that defeat it.

Quick answer

Business email compromise (BEC) is fraud carried out by impersonating, or taking over, a trusted email account to trigger a payment or data transfer. Invoice fraud is its most common form: the attacker sends a real-looking invoice, or a "we have changed banks" notice, and your money goes to them. The single strongest control is a rule that every change of payment details is confirmed by phone on a number you already hold.

How an invoice fraud actually unfolds

  1. Reconnaissance. The attacker learns who your suppliers are and who pays invoices, often from your website, LinkedIn, or a previous breach of the supplier.
  2. Access or imitation. Either they compromise the supplier's real mailbox (often through a phishing page), or they register a lookalike domain such as yoursupplier-invoices.com and copy the supplier's signature.
  3. Patience. If they are inside the supplier's mailbox, they set a rule to hide replies from you and wait for a real invoice to be sent.
  4. The switch. They resend the invoice, or a follow-up, with new bank details and a plausible reason: an audit, a new banking partner, a merger.
  5. Pressure. A polite reminder arrives a few days later, often just before a weekend or holiday when the person who could verify is unavailable.
  6. The payment clears, and the account is emptied within hours. Recovery through banks is possible only if reported very quickly.

Warning signs on the email itself

  • Bank details in the body or a PDF that differ from the ones on file, even slightly.
  • A reply that continues an old thread but arrives from a subtly different address. Compare character by character: rn versus m, a zero for an o, an extra letter.
  • A change to the Reply-To header so that your answer goes somewhere other than the visible From address.
  • Requests to keep the change confidential, or to skip the usual purchase-order step "just this once".
  • A message from "the CEO" asking for a transfer while travelling and unable to take calls.

The controls that stop it

  1. Verify every bank-detail change by phone, using the number already in your accounts system, not the one in the email. Make this a written rule with no exceptions for size or seniority.
  2. Separate duties. The person who approves a payment should not be the person who enters it, even in a three-person team; the founder and the bookkeeper is enough.
  3. Set a threshold above which two people must approve, and a second threshold above which the payment waits until the next business day.
  4. Turn on two-factor authentication for every mailbox that touches invoices, purchase orders, or banking.
  5. Check your own mailboxes monthly for forwarding rules and filters you did not create. Attackers hide inside these for weeks.
  6. Publish SPF, DKIM, and DMARC with a quarantine or reject policy so nobody can send mail that appears to be from your domain to your own staff or your customers.

Protecting your customers from fraud in your name

Attackers also impersonate you to your customers, sending "updated bank details" on your letterhead. Two things reduce this: authentication on your domain, and a standing note on every invoice that you will never change bank details by email and that customers should phone to confirm any such request. OquMail sets up SPF, DKIM, and DMARC with live DNS verification when you connect a domain, and its per-message delivery logs show you exactly what your domain sent, which is useful evidence if a customer ever asks whether an email was genuinely yours.

If a payment has already gone

  1. Call your bank immediately and ask for a recall. Minutes matter.
  2. Call the supplier on a known number and tell them their account may be compromised.
  3. Preserve the emails with full headers; do not delete anything.
  4. Report to your national fraud reporting service and, where relevant, your insurer.
  5. Reset passwords and review rules on the mailbox that received the fraudulent message, in case it was the entry point.

Common questions

Our supplier confirmed the change by email. Is that enough?

No. If their mailbox is compromised, the attacker is answering your confirmation request. Verification must use a channel the email did not provide: a phone call to a number you already had, or a visit.

Would a paid email security gateway have caught this?

Sometimes. Gateways are good at lookalike domains and poor at mail from a genuinely compromised supplier account, which passes every authentication check. Process controls are what protect you in that case.

Are small businesses really targeted?

Yes. Smaller firms are attractive precisely because they often have one person handling payments and no formal verification step. The controls above cost nothing but a phone call.

Free business email on your own domain

OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.

Get started free

Ready for business email on your domain?

Up to 15 free mailboxes, guided DNS, webmail, and a transactional API — start in minutes.

Create your free workspace