The Fake Invoice Scam That Drains Small Companies, And How To Stop It
Business email compromise relies on a convincing message and a rushed payment. These are the controls that stop it, and what to do if money has already left.

The most expensive email a small company receives often looks routine: a supplier saying its bank details have changed, or an executive asking for an urgent wire before the end of the day.
This is business email compromise, and it works because it does not need sophisticated malware. It needs one convincing message, one person under time pressure and a payment process without a second check. The FBI has repeatedly ranked it among the costliest categories of cybercrime reported to its Internet Crime Complaint Center.
How the scheme works
Most attacks follow a few patterns. In vendor impersonation, criminals pose as a real supplier and send an invoice or a request to update payment details, redirecting legitimate payments to an account they control. In executive impersonation, they pose as the CEO or CFO and ask finance staff for an urgent, confidential transfer. Payroll diversion requests ask HR to change an employee's direct deposit account. Gift card requests, often framed as a quick favor for a senior executive, are a cruder version of the same idea.
The emails come from one of two places. Some use lookalike domains that differ from the real one by a single character or a different ending. Others come from a genuinely compromised mailbox, which is far harder to spot because the message is sent from the real account, often inside an existing thread.
Compromised mailboxes are the more dangerous case. Attackers who get in often read correspondence quietly for weeks, learn who pays whom and when, and set up inbox rules that hide replies from the real account holder. When they finally strike, the timing and tone are right.
The control that matters most
Verify every change to payment details by phone, using a number you already have on file, never one supplied in the request. This single rule defeats most vendor impersonation and payroll diversion attempts, because the attacker controls the email but not the supplier's phone line.
Write it into policy and make it non-negotiable, including for requests that appear to come from the CEO. Executives should tell finance staff explicitly that nobody will be penalized for delaying a payment to verify it. Urgency and secrecy are the attacker's main tools, and a culture where people feel unable to question senior staff hands them both.
Pair verification with dual approval for payments above a set threshold and for any new payee. Then two people have to be fooled instead of one.
Technical controls worth turning on
Enforce multifactor authentication on every email account, starting with finance, executives and administrators. A stolen password is the usual way into a mailbox, and multifactor authentication blocks most of those attempts. Phishing-resistant methods such as hardware security keys offer stronger protection than codes sent by text message.
Publish email authentication records for your domain, known as SPF, DKIM and DMARC, and move your DMARC policy toward enforcement. These make it harder for criminals to send mail that appears to come from your exact domain.
Have your email administrator alert on new forwarding and inbox rules, especially rules that forward mail externally or delete messages. Add a visible banner to messages from outside the organization, and consider monitoring for newly registered domains that resemble yours.
If money has already gone
Speed matters more than anything else. Call your bank immediately, ask it to recall or freeze the transfer, and ask it to contact the receiving bank. The chance of recovering funds drops quickly as time passes and the money moves on.
File a complaint with the FBI's Internet Crime Complaint Center with the transaction details. Then treat the incident as a possible account compromise: reset passwords, revoke active sessions, review mailbox rules and check whether the attacker reached other systems or data.
Notify your cyber insurer early if you have coverage, since policies often require prompt notice and may provide response help. Check whether the policy covers social engineering losses, which are sometimes excluded or subject to a lower limit.
What to do this week
Write a one-paragraph payment verification rule and send it to everyone who can move money or change bank details.
Confirm that multifactor authentication is enforced, not merely available, on every mailbox, and turn on dual approval in your banking platform for new payees and large transfers.
Check your domain's DMARC status and fix it if no policy is published.
Run a short drill: send a realistic fake bank-change request to your finance team and see what happens. Then fix whatever the drill exposes, without blaming whoever fell for it.
Sources
FBI — Internet Crime Complaint Center (IC3)




