Think Build Implement Repeat
SaaS & Product

How Invoice Fraud Actually Happens, and How to Stop It

Last updated:

The attack, step by step

  1. An attacker gains access to a mailbox, often through a reused password, or simply spoofs a familiar address.
  2. They watch for a real invoice or a real project, learning the tone and the timing.
  3. They send a message that fits the context: an invoice for work you genuinely commissioned, or a note that bank details have changed.
  4. Payment goes to their account. Recovery after the fact is difficult and frequently impossible.

The reason it works is not carelessness. It works because the message is contextually correct and arrives when a payment was expected.

The one rule that stops it

Any change to bank details is verified by telephone, to a number you already hold, before any payment is made. Not a number in the email. Not a reply to the email. A number from your own records.

Write it down, tell everyone with payment authority, and apply it without exception including when the request appears to come from a director in a hurry. That urgency is a deliberate part of the attack.

Protect the mailbox

  • Multi-factor authentication on all email accounts, without exception
  • Alerting on mailbox rule creation — attackers create rules to hide their replies
  • Review of forwarding rules periodically
  • Prompt password rotation when anyone leaves

A mailbox rule that quietly forwards and deletes messages is the classic sign of compromise and is invisible unless someone looks.

Make your own domain harder to spoof

SPF, DKIM and DMARC configured properly make it substantially harder for anyone to send convincing email pretending to be you. That protects your customers as well as you.

A DMARC policy that instructs receivers to reject unauthenticated mail is the endpoint; get there gradually by starting in monitoring mode and fixing what it reports.

Train by example, not by lecture

Annual security training is largely forgotten. What works better is circulating the actual attempts you receive, with what gave them away, so people recognise the pattern in context.

Also make it safe to report a mistake immediately. The damage from a clicked link multiplies with every hour it goes unreported, and a culture that punishes reporting delays it.

Frequently asked questions

What do we do if a payment has already gone?

Contact your bank immediately — speed genuinely matters for any chance of recall — then report it to the relevant fraud authority, and check whether the mailbox involved was compromised.

Can technology stop this entirely?

Filtering helps and will not catch a well-crafted message from a genuinely compromised account of someone you know. The verification rule is what catches those.

Should we tell our customers about the risk?

Yes. A line on your invoices stating that your bank details never change without a phone call protects them and you.

Is this covered by insurance?

Sometimes, with conditions that often include the controls above. Read the policy before you need it.

Keep reading

No written rule about bank detail changes?

That is a ten-minute fix that prevents the most expensive thing likely to happen to you. Worth doing today.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

SaaS DevelopmentCustom Software Development