Skip to main content

Business Email Compromise: The Invoice Fraud Playbook Your Finance Team Should Know

Media Business Email Compromise The Invoice Fraud Playbook Your Finance Team Should Know

Business email compromise, or BEC, is one of the most financially damaging forms of cybercrime because it does not always look like a cyberattack.

There may be no suspicious attachment, obvious malware warning or badly written phishing message. Instead, the finance team receives what appears to be a normal request from a supplier, director, solicitor or colleague.

The email may sit inside a genuine conversation. It may refer to a real invoice, use the correct names and match an expected payment date. The only meaningful change is the bank account receiving the money.

That is the core of invoice fraud:

The attacker does not need to create a fake transaction. They redirect a real one.

The FBI describes BEC as a sophisticated scam that exploits trusted business communications, while the UK National Cyber Security Centre warns that criminals may impersonate a regular contact and request payment to a different account. 

This guide explains the invoice fraud playbook, the warning signs finance teams should recognise and the payment controls that can stop one compromised mailbox from becoming a major financial loss.

What Is Business Email Compromise?

Business email compromise is a social-engineering attack designed to make an employee send money or sensitive information to a criminal.

Attackers may impersonate:

  • A supplier
  • A managing director
  • A finance colleague
  • A solicitor
  • A customer
  • A payroll provider
  • An external accountant
  • A property agent
  • A senior executive

Some attacks use a lookalike domain or spoofed sender address. More advanced attacks begin with the compromise of a genuine Microsoft 365 or Google Workspace account.

Once inside a mailbox, the attacker may quietly monitor conversations until they find:

  • An unpaid invoice
  • A large supplier payment
  • A property transaction
  • A company acquisition
  • A payroll run
  • A refund
  • A deposit
  • A recurring transfer

Microsoft describes payment-diversion fraud as attackers gaining access to email, monitoring active conversations and intervening when a payment is expected so the funds can be redirected. 

Why Invoice Fraud Is So Convincing

A generic phishing email asks the victim to trust a stranger.

Invoice fraud often asks them to trust information they already recognise.

The message may include:

  • A genuine invoice number
  • The correct supplier name
  • A real project reference
  • The expected amount
  • Previous email history
  • Familiar signatures
  • Correct payment dates
  • Genuine contact details copied from earlier messages

The attacker may have spent days or weeks reading the compromised mailbox before sending anything.

That preparation allows them to imitate:

  • Writing style
  • Approval language
  • Normal response times
  • Job titles
  • Internal procedures
  • Supplier terminology

Microsoft has documented attackers hijacking existing finance-related email threads and using fake invoices or altered payment instructions to divert funds. 

The Invoice Fraud Playbook

Although every incident is different, many attacks follow a recognisable sequence.

Stage 1: Research the Business

The attacker collects information from:

  • Company websites
  • LinkedIn
  • Social media
  • Public tenders
  • Press releases
  • Job adverts
  • Supplier information
  • Data breaches
  • Previous phishing campaigns

They want to identify:

  • Who authorises payments
  • Who processes invoices
  • Who manages suppliers
  • Which executives travel
  • When the business is busiest
  • Which companies regularly receive payments

Even public job titles can reveal useful information.

A criminal may search for employees with titles such as:

  • Accounts Payable
  • Finance Assistant
  • Credit Controller
  • Financial Controller
  • Payroll Manager
  • Procurement Manager
  • Chief Financial Officer

Stage 2: Compromise or Imitate an Account

The attacker may use:

  • Password phishing
  • Adversary-in-the-middle phishing
  • Session token theft
  • MFA fatigue
  • OAuth consent attacks
  • Malware
  • A lookalike domain
  • Display-name impersonation

A lookalike domain might replace one character:

supplier-company.co.uk

suppIier-company.co.uk

In some fonts, a capital I can resemble a lowercase l.

Compromising a genuine account is more dangerous because messages come from the correct address and may appear inside authentic conversations.

Stage 3: Monitor Email Silently

The attacker may not act immediately.

They search for terms such as:

invoice

payment

bank details

deposit

balance

purchase order

remittance

completion

urgent transfer

They may also inspect:

  • Sent items
  • Deleted items
  • Calendar appointments
  • Supplier contacts
  • Mailbox rules
  • Shared mailboxes
  • Previous invoices

This surveillance helps the attacker understand how payments are approved.

Stage 4: Choose the Right Moment

The attacker waits until a payment is:

  • Expected
  • Large enough to be worthwhile
  • Time sensitive
  • Connected to a real supplier
  • Due before a weekend or holiday
  • Being handled by a busy employee
  • Less likely to receive close scrutiny

Periods of staff absence, year-end processing and senior-management travel can create especially useful opportunities.

Stage 5: Change the Payment Instructions

The attacker sends a message such as:

We have recently changed banks. Please use the attached account details for all future payments.

Other explanations may include:

  • The old account is under audit.
  • The supplier has changed payment provider.
  • The account is temporarily unavailable.
  • The invoice must be paid to a parent company.
  • A revised invoice has been issued.
  • The finance director has approved an urgent exception.
  • The payment must be split between two accounts.

The story only needs to be credible enough to prevent independent verification.

Stage 6: Suppress Warnings

When a genuine supplier replies, the attacker may use mailbox rules to:

  • Delete the response
  • Move it into an obscure folder
  • Mark it as read
  • Forward it elsewhere
  • Hide payment-related messages
  • Prevent the victim seeing security alerts

The finance employee may therefore believe the altered thread is still legitimate.

Stage 7: Pressure the Employee

Urgency is often introduced near the end.

Examples include:

  • “Payment must clear today.”
  • “The director is waiting.”
  • “This is commercially sensitive.”
  • “Do not contact the supplier yet.”
  • “We will lose the order.”
  • “Complete this before the bank closes.”
  • “I am in a meeting, so email only.”

Urgency, secrecy and authority are deliberately combined to bypass normal controls.

Stage 8: Move the Money Quickly

Once the transfer arrives, criminals may:

  • Move it through several accounts
  • Convert it into cryptocurrency
  • Send it abroad
  • Withdraw it
  • Split it into smaller transactions
  • Use money-mule networks

The recovery window may be very short. Microsoft notes that stolen funds may be moved within seconds, and the FBI advises victims to contact their financial institution immediately. 

Common Types of BEC Invoice Fraud

Supplier Account Change Fraud

A criminal impersonates a genuine supplier and requests that future payments go to a new account.

This is one of the most common patterns because the payment itself is legitimate.

Invoice Substitution

The attacker replaces a genuine invoice with an altered copy containing different banking information.

The invoice may otherwise be identical.

Executive Payment Fraud

A criminal impersonates a director or senior manager and requests an urgent payment.

The message may refer to:

  • A confidential acquisition
  • Legal fees
  • A new supplier
  • An emergency purchase
  • A customer refund

Vendor Email Compromise

A supplier’s genuine mailbox is compromised and used to target its customers.

Microsoft distinguishes vendor email compromise as the hijacking of a supplier relationship to redirect legitimate outstanding payments. 

One compromised supplier can therefore expose many organisations at once.

Solicitor and Property Fraud

Attackers target property purchases, settlements and legal transactions because the payment values are high and deadlines are strict.

Payroll Diversion

The criminal impersonates an employee and asks payroll to change the bank account used for salary payments.

Refund Fraud

An attacker claims a customer was overcharged and requests a refund to a new account.

Warning Signs Finance Teams Should Recognise

No single sign proves fraud, but several together should stop the payment.

Bank Details Have Changed

Any change to bank details should trigger independent verification.

It does not matter whether:

  • The email appears genuine
  • The sender is familiar
  • The invoice looks correct
  • The message is in an existing thread

A bank-detail change is a financial security event.

Unusual Urgency

Be cautious when the sender:

  • Demands same-day payment
  • Discourages questions
  • Claims senior management approval
  • Insists normal procedures be bypassed
  • Warns of immediate penalties

Secrecy

Statements such as these are major warning signs:

  • “Keep this confidential.”
  • “Do not call the supplier.”
  • “Do not discuss this with the team.”
  • “I will explain later.”

Small Changes in Email Addresses

Check the complete address, not only the display name.

Look for:

  • Extra characters
  • Missing letters
  • Different domain endings
  • Hyphens
  • Subdomains
  • Substituted characters

Changes in Tone or Process

The email may:

  • Use unusual language
  • Avoid a normal purchase-order reference
  • Request a different payment method
  • Bypass the regular approver
  • Arrive at an unusual time
  • Include an unexpected attachment format

The Sender Avoids Telephone Verification

A criminal may claim:

  • They are travelling.
  • Their phone is unavailable.
  • They are in a meeting.
  • The matter must remain on email.
  • The normal contact has left.

Refusing independent verification should increase suspicion, not reduce it.

A New or Revised Invoice Appears Unexpectedly

The revised invoice may contain:

  • Different payment details
  • A slightly different company name
  • A changed address
  • New contact information
  • Unusual formatting

Do not compare only the total. Compare the supplier data too.

The Most Important Control: Call Back Using a Trusted Number

Every new bank account or bank-detail change should be confirmed through a trusted channel.

Do not use:

  • The telephone number in the change request
  • The number on the revised invoice
  • A contact provided by the sender
  • A link inside the message

Use a number taken from:

  • The existing supplier master record
  • A previous verified invoice
  • The supplier’s official website found independently
  • A signed contract
  • An established contact directory

The NCSC recommends confirming payment requests through a second communication channel, particularly when bank details have changed. 

Use Dual Approval for Payments

No single employee should be able to:

  1. Create or edit a supplier
  2. Change bank information
  3. Approve the invoice
  4. Release the payment

Separate these duties.

A strong process may require:

  • One person to enter the supplier information
  • Another to verify the bank details
  • An authorised approver to approve the invoice
  • A separate person to release the payment

This makes one compromised account less useful to the attacker.

Treat Bank-Detail Changes Separately From Invoice Approval

Approving an invoice should not automatically approve new bank information.

Use separate workflows for:

  • Supplier onboarding
  • Bank-detail changes
  • Invoice approval
  • Payment release

A genuine invoice can still contain fraudulent bank details.

Create a Supplier Verification Record

When a supplier’s details are verified, record:

  • Date
  • Employee performing verification
  • Supplier contact spoken to
  • Telephone number used
  • Source of that telephone number
  • Bank details confirmed
  • Second approver
  • Supporting evidence

This creates accountability and helps during audits.

Use Small Test Payments Carefully

Some organisations send a small test payment before a major transfer.

This can add assurance, but it is not sufficient by itself.

The attacker may control the fraudulent account and confirm receipt of the test amount.

A test payment should follow—not replace—independent supplier verification.

Require Purchase Orders

A valid payment request should normally connect to:

  • An approved purchase order
  • A recognised supplier
  • An agreed service
  • A known department
  • A recorded contract
  • A confirmed goods receipt

Purchase-order matching will not stop every BEC attack, but it reduces opportunities for fabricated payments.

Use Payment Limits

Set thresholds requiring additional approval.

For example:

  • Routine low-value payments: normal approval
  • Medium-value payments: two approvers
  • High-value or new-account payments: senior approval and telephone verification
  • Bank-detail changes: mandatory second-channel confirmation regardless of value

A fraudster may deliberately request an amount just below the normal approval threshold. Review repeated transfers and split payments too.

Remove Urgency From the Process

A good payment policy should clearly state:

No email, regardless of sender, can override the verification process.

Employees should know that they will not be criticised for delaying a suspicious payment.

Attackers succeed when staff believe that stopping to verify will upset senior management.

Executives must actively support the controls.

Protect Finance and Executive Accounts

Finance employees and senior executives are high-value BEC targets.

Protect their accounts using:

  • Phishing-resistant MFA
  • Conditional Access
  • Managed devices
  • Strong endpoint protection
  • Separate administrator accounts
  • Restricted browser extensions
  • Sign-in monitoring
  • Rapid token revocation

Traditional MFA remains important, but attackers may steal authenticated sessions through adversary-in-the-middle phishing. 

Passkeys and FIDO2 security keys provide stronger resistance to credential-phishing attacks.

Configure Email Authentication

Implement and maintain:

  • SPF
  • DKIM
  • DMARC

These controls can reduce direct domain spoofing.

However, they do not stop:

  • Compromised genuine mailboxes
  • Lookalike domains
  • Supplier account compromise
  • Social engineering from legitimate accounts

DMARC is an important layer, not a complete BEC defence.

Add External Sender Indicators

Clearly label messages originating outside the organisation.

This can help users recognise when a person claiming to be an internal executive is actually contacting them externally.

The warning should not become so visually noisy that staff ignore it.

Protect Against Lookalike Domains

Use domain monitoring and impersonation protection to detect:

  • Newly registered lookalike domains
  • Executive-name impersonation
  • Supplier impersonation
  • Display-name spoofing
  • Similar domain spellings

Microsoft has documented BEC campaigns using typo-squatted domains that appeared similar to legitimate senders. 

Monitor Mailbox Rules and Forwarding

Attackers frequently create mailbox rules to hide replies and alerts.

Monitor for:

  • External forwarding
  • Rules deleting messages
  • Rules moving finance-related email
  • Rules hiding replies from suppliers
  • Newly created unusual folders
  • Changes made soon after a risky sign-in

A mailbox rule does not need to contain obviously malicious words to be dangerous.

Review Sign-In Logs

Finance and executive sign-ins should be reviewed for:

  • Unfamiliar countries
  • Unknown devices
  • Unusual IP addresses
  • High-risk events
  • Token anomalies
  • Unexpected applications
  • New authentication methods
  • Impossible or atypical travel

A successful sign-in can still be malicious.

The attacker may be operating through a stolen token or compromised device.

Train Finance Staff With Real Examples

Generic phishing training is not enough.

Finance teams should practise scenarios involving:

  • Changed bank details
  • A director requesting urgent payment
  • A compromised supplier thread
  • A revised invoice
  • Payroll bank changes
  • Confidential legal payments
  • A request arriving before a holiday
  • A familiar sender refusing telephone verification

Training should focus on the procedure, not merely visual clues.

A perfect-looking email should still fail when the payment process is strong.

Create a Safe Escalation Route

Employees need to know:

  • Who to contact
  • How to pause a payment
  • How to verify a supplier
  • How to report a suspicious email
  • Who can approve an exception
  • What information to preserve

The process must remain available when the finance manager or director is absent.

What to Do After a Fraudulent Payment

Speed matters.

1. Contact the Bank Immediately

Tell the bank that the payment was fraudulent and request:

  • A transfer recall
  • A freeze request
  • Contact with the receiving bank
  • Escalation to the fraud team

The FBI advises contacting the financial institution immediately and asking it to contact the institution that received the payment. 

2. Contact Law Enforcement and Reporting Services

For a UK organisation, follow the appropriate reporting routes advised by law enforcement, Action Fraud and the NCSC.

US organisations should report BEC through the FBI’s Internet Crime Complaint Center.

Rapid reporting can improve the chance of fund recovery. 

3. Preserve the Email Evidence

Retain:

  • Original messages
  • Message headers
  • Attachments
  • Invoices
  • Bank instructions
  • Supplier correspondence
  • Telephone records
  • Payment timestamps
  • Bank reference numbers

Do not simply forward the message and delete the original.

4. Secure the Email Accounts

When compromise is suspected:

  • Disable or restrict the account
  • Revoke active sessions
  • Reset credentials
  • Review MFA methods
  • Remove malicious inbox rules
  • Remove external forwarding
  • Review OAuth applications
  • Inspect delegated mailbox access

Microsoft’s compromised-mailbox guidance recommends reviewing forwarding, inbox rules, account access and other methods attackers use to retain control. 

5. Investigate Both Organisations

The compromise may exist in:

  • Your organisation
  • The supplier
  • Both organisations
  • A third-party email system

Do not assume the supplier is responsible simply because the message came from its mailbox.

6. Warn Other Potential Targets

The attacker may use the same compromised thread to target:

  • Other customers
  • Other suppliers
  • Additional finance employees
  • Senior managers
  • Payroll teams

Contact relevant parties through trusted channels.

7. Review Data Exposure

The attacker may have read more than the payment conversation.

Review whether they accessed:

  • Customer details
  • Contracts
  • Personal information
  • Employee data
  • Legal documents
  • Additional invoices
  • Future payment schedules

The incident may therefore involve a reportable data breach as well as financial fraud.

What Not to Do

Do Not Wait for the Supplier to Reply

The attacker may control or filter that mailbox.

Do Not Continue Using the Same Email Thread

Move to a verified communication channel.

Do Not Change Only the Password

Active sessions, OAuth permissions and mailbox rules may remain.

Do Not Blame the Employee Immediately

A blame-driven culture discourages rapid reporting.

Speed and evidence matter more than finding fault during the first response.

Do Not Assume the Money Is Gone

Contact the bank and authorities immediately. Some funds can be frozen or recovered when action is fast.

A Finance Team Invoice Fraud Checklist

Before paying:

  • Is the supplier known?
  • Does the invoice match a valid purchase order?
  • Is the amount expected?
  • Have the bank details changed?
  • Was the change independently verified?
  • Was a trusted telephone number used?
  • Has a second person approved the payment?
  • Is the request unusually urgent or confidential?
  • Does the sender refuse verbal confirmation?
  • Is the payment going to the expected country and account name?

After changing supplier details:

  • Record who requested the change.
  • Confirm through a trusted contact.
  • Require two-person approval.
  • Notify the supplier through its established channel.
  • Review the first payment carefully.
  • Retain verification evidence.

A Practical Payment Verification Policy

A useful policy can be stated simply:

No new supplier, bank-detail change or unusual payment instruction will be accepted solely by email.

Require independent verification for:

  • New bank accounts
  • Changed account numbers
  • Changed sort codes
  • Changed IBANs
  • Changed beneficiary names
  • Changed payment countries
  • Requests to split payments
  • Urgent transfers outside normal procedures

The rule should apply equally to:

  • Suppliers
  • Directors
  • Customers
  • Solicitors
  • Internal colleagues

Authority does not replace verification.

Final Thoughts

Business email compromise succeeds because it hides inside ordinary business activity.

The invoice may be genuine. The supplier may be real. The conversation may be authentic. The attacker only needs to change where the money is sent.

Technology can reduce the risk through stronger authentication, email filtering, domain protection, sign-in monitoring and endpoint security.

But the most dependable control remains a well-designed finance process.

Verify every bank-detail change through a trusted communication channel. Separate supplier maintenance from payment approval. Require more than one person for significant transfers. Give employees permission to pause suspicious payments regardless of who appears to be requesting them.

The essential rule is simple:

Never trust new payment instructions solely because they arrived in a familiar email thread.

A two-minute independent telephone check can prevent a six-figure loss.

Worried About Business Email Compromise and Invoice Fraud?

Hamilton Group can help your organisation strengthen Microsoft 365 security and payment-fraud controls.

Our experts can help you:

  • Protect finance and executive accounts
  • Deploy phishing-resistant MFA
  • Configure Microsoft Defender for Office 365
  • Improve impersonation and lookalike-domain protection
  • Monitor mailbox forwarding and inbox rules
  • Review Microsoft Entra sign-in activity
  • Investigate compromised mailboxes
  • Build a BEC incident-response plan
  • Deliver targeted finance-team security training
  • Review supplier and payment-verification processes

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to strengthen your protection against invoice fraud and business email compromise.