How Invoice Fraud Actually Happens, and How to Stop It
Last updated:
The attack, step by step
- An attacker gains access to a mailbox, often through a reused password, or simply spoofs a familiar address.
- They watch for a real invoice or a real project, learning the tone and the timing.
- They send a message that fits the context: an invoice for work you genuinely commissioned, or a note that bank details have changed.
- Payment goes to their account. Recovery after the fact is difficult and frequently impossible.
The reason it works is not carelessness. It works because the message is contextually correct and arrives when a payment was expected.
The one rule that stops it
Any change to bank details is verified by telephone, to a number you already hold, before any payment is made. Not a number in the email. Not a reply to the email. A number from your own records.
Write it down, tell everyone with payment authority, and apply it without exception including when the request appears to come from a director in a hurry. That urgency is a deliberate part of the attack.
Protect the mailbox
- Multi-factor authentication on all email accounts, without exception
- Alerting on mailbox rule creation — attackers create rules to hide their replies
- Review of forwarding rules periodically
- Prompt password rotation when anyone leaves
A mailbox rule that quietly forwards and deletes messages is the classic sign of compromise and is invisible unless someone looks.
Make your own domain harder to spoof
SPF, DKIM and DMARC configured properly make it substantially harder for anyone to send convincing email pretending to be you. That protects your customers as well as you.
A DMARC policy that instructs receivers to reject unauthenticated mail is the endpoint; get there gradually by starting in monitoring mode and fixing what it reports.
Train by example, not by lecture
Annual security training is largely forgotten. What works better is circulating the actual attempts you receive, with what gave them away, so people recognise the pattern in context.
Also make it safe to report a mistake immediately. The damage from a clicked link multiplies with every hour it goes unreported, and a culture that punishes reporting delays it.
Frequently asked questions
What do we do if a payment has already gone?
Can technology stop this entirely?
Should we tell our customers about the risk?
Is this covered by insurance?
No written rule about bank detail changes?
That is a ten-minute fix that prevents the most expensive thing likely to happen to you. Worth doing today.
Related services
What we build for problems like this one