Business Email Compromise: The Invoice Fraud Playbook Your Finance Team Should Know
Business email compromise, or BEC, is one of the most financially damaging forms of cybercrime because it does not always look like a cyberattack.
There may be no suspicious attachment, obvious malware warning or badly written phishing message. Instead, the finance team receives what appears to be a normal request from a supplier, director, solicitor or colleague.
The email may sit inside a genuine conversation. It may refer to a real invoice, use the correct names and match an expected payment date. The only meaningful change is the bank account receiving the money.
That is the core of invoice fraud:
The attacker does not need to create a fake transaction. They redirect a real one.
The FBI describes BEC as a sophisticated scam that exploits trusted business communications, while the UK National Cyber Security Centre warns that criminals may impersonate a regular contact and request payment to a different account.
This guide explains the invoice fraud playbook, the warning signs finance teams should recognise and the payment controls that can stop one compromised mailbox from becoming a major financial loss.
What Is Business Email Compromise?
Business email compromise is a social-engineering attack designed to make an employee send money or sensitive information to a criminal.
Attackers may impersonate:
- A supplier
- A managing director
- A finance colleague
- A solicitor
- A customer
- A payroll provider
- An external accountant
- A property agent
- A senior executive
Some attacks use a lookalike domain or spoofed sender address. More advanced attacks begin with the compromise of a genuine Microsoft 365 or Google Workspace account.
Once inside a mailbox, the attacker may quietly monitor conversations until they find:
- An unpaid invoice
- A large supplier payment
- A property transaction
- A company acquisition
- A payroll run
- A refund
- A deposit
- A recurring transfer
Microsoft describes payment-diversion fraud as attackers gaining access to email, monitoring active conversations and intervening when a payment is expected so the funds can be redirected.
Why Invoice Fraud Is So Convincing
A generic phishing email asks the victim to trust a stranger.
Invoice fraud often asks them to trust information they already recognise.
The message may include:
- A genuine invoice number
- The correct supplier name
- A real project reference
- The expected amount
- Previous email history
- Familiar signatures
- Correct payment dates
- Genuine contact details copied from earlier messages
The attacker may have spent days or weeks reading the compromised mailbox before sending anything.
That preparation allows them to imitate:
- Writing style
- Approval language
- Normal response times
- Job titles
- Internal procedures
- Supplier terminology
Microsoft has documented attackers hijacking existing finance-related email threads and using fake invoices or altered payment instructions to divert funds.
The Invoice Fraud Playbook
Although every incident is different, many attacks follow a recognisable sequence.
Stage 1: Research the Business
The attacker collects information from:
- Company websites
- Social media
- Public tenders
- Press releases
- Job adverts
- Supplier information
- Data breaches
- Previous phishing campaigns
They want to identify:
- Who authorises payments
- Who processes invoices
- Who manages suppliers
- Which executives travel
- When the business is busiest
- Which companies regularly receive payments
Even public job titles can reveal useful information.
A criminal may search for employees with titles such as:
- Accounts Payable
- Finance Assistant
- Credit Controller
- Financial Controller
- Payroll Manager
- Procurement Manager
- Chief Financial Officer
Stage 2: Compromise or Imitate an Account
The attacker may use:
- Password phishing
- Adversary-in-the-middle phishing
- Session token theft
- MFA fatigue
- OAuth consent attacks
- Malware
- A lookalike domain
- Display-name impersonation
A lookalike domain might replace one character:
supplier-company.co.uk
suppIier-company.co.uk
In some fonts, a capital I can resemble a lowercase l.
Compromising a genuine account is more dangerous because messages come from the correct address and may appear inside authentic conversations.
Stage 3: Monitor Email Silently
The attacker may not act immediately.
They search for terms such as:
invoice
payment
bank details
deposit
balance
purchase order
remittance
completion
urgent transfer
They may also inspect:
- Sent items
- Deleted items
- Calendar appointments
- Supplier contacts
- Mailbox rules
- Shared mailboxes
- Previous invoices
This surveillance helps the attacker understand how payments are approved.
Stage 4: Choose the Right Moment
The attacker waits until a payment is:
- Expected
- Large enough to be worthwhile
- Time sensitive
- Connected to a real supplier
- Due before a weekend or holiday
- Being handled by a busy employee
- Less likely to receive close scrutiny
Periods of staff absence, year-end processing and senior-management travel can create especially useful opportunities.
Stage 5: Change the Payment Instructions
The attacker sends a message such as:
We have recently changed banks. Please use the attached account details for all future payments.
Other explanations may include:
- The old account is under audit.
- The supplier has changed payment provider.
- The account is temporarily unavailable.
- The invoice must be paid to a parent company.
- A revised invoice has been issued.
- The finance director has approved an urgent exception.
- The payment must be split between two accounts.
The story only needs to be credible enough to prevent independent verification.
Stage 6: Suppress Warnings
When a genuine supplier replies, the attacker may use mailbox rules to:
- Delete the response
- Move it into an obscure folder
- Mark it as read
- Forward it elsewhere
- Hide payment-related messages
- Prevent the victim seeing security alerts
The finance employee may therefore believe the altered thread is still legitimate.
Stage 7: Pressure the Employee
Urgency is often introduced near the end.
Examples include:
- “Payment must clear today.”
- “The director is waiting.”
- “This is commercially sensitive.”
- “Do not contact the supplier yet.”
- “We will lose the order.”
- “Complete this before the bank closes.”
- “I am in a meeting, so email only.”
Urgency, secrecy and authority are deliberately combined to bypass normal controls.
Stage 8: Move the Money Quickly
Once the transfer arrives, criminals may:
- Move it through several accounts
- Convert it into cryptocurrency
- Send it abroad
- Withdraw it
- Split it into smaller transactions
- Use money-mule networks
The recovery window may be very short. Microsoft notes that stolen funds may be moved within seconds, and the FBI advises victims to contact their financial institution immediately.
Common Types of BEC Invoice Fraud
Supplier Account Change Fraud
A criminal impersonates a genuine supplier and requests that future payments go to a new account.
This is one of the most common patterns because the payment itself is legitimate.
Invoice Substitution
The attacker replaces a genuine invoice with an altered copy containing different banking information.
The invoice may otherwise be identical.
Executive Payment Fraud
A criminal impersonates a director or senior manager and requests an urgent payment.
The message may refer to:
- A confidential acquisition
- Legal fees
- A new supplier
- An emergency purchase
- A customer refund
Vendor Email Compromise
A supplier’s genuine mailbox is compromised and used to target its customers.
Microsoft distinguishes vendor email compromise as the hijacking of a supplier relationship to redirect legitimate outstanding payments.
One compromised supplier can therefore expose many organisations at once.
Solicitor and Property Fraud
Attackers target property purchases, settlements and legal transactions because the payment values are high and deadlines are strict.
Payroll Diversion
The criminal impersonates an employee and asks payroll to change the bank account used for salary payments.
Refund Fraud
An attacker claims a customer was overcharged and requests a refund to a new account.
Warning Signs Finance Teams Should Recognise
No single sign proves fraud, but several together should stop the payment.
Bank Details Have Changed
Any change to bank details should trigger independent verification.
It does not matter whether:
- The email appears genuine
- The sender is familiar
- The invoice looks correct
- The message is in an existing thread
A bank-detail change is a financial security event.
Unusual Urgency
Be cautious when the sender:
- Demands same-day payment
- Discourages questions
- Claims senior management approval
- Insists normal procedures be bypassed
- Warns of immediate penalties
Secrecy
Statements such as these are major warning signs:
- “Keep this confidential.”
- “Do not call the supplier.”
- “Do not discuss this with the team.”
- “I will explain later.”
Small Changes in Email Addresses
Check the complete address, not only the display name.
Look for:
- Extra characters
- Missing letters
- Different domain endings
- Hyphens
- Subdomains
- Substituted characters
Changes in Tone or Process
The email may:
- Use unusual language
- Avoid a normal purchase-order reference
- Request a different payment method
- Bypass the regular approver
- Arrive at an unusual time
- Include an unexpected attachment format
The Sender Avoids Telephone Verification
A criminal may claim:
- They are travelling.
- Their phone is unavailable.
- They are in a meeting.
- The matter must remain on email.
- The normal contact has left.
Refusing independent verification should increase suspicion, not reduce it.
A New or Revised Invoice Appears Unexpectedly
The revised invoice may contain:
- Different payment details
- A slightly different company name
- A changed address
- New contact information
- Unusual formatting
Do not compare only the total. Compare the supplier data too.
The Most Important Control: Call Back Using a Trusted Number
Every new bank account or bank-detail change should be confirmed through a trusted channel.
Do not use:
- The telephone number in the change request
- The number on the revised invoice
- A contact provided by the sender
- A link inside the message
Use a number taken from:
- The existing supplier master record
- A previous verified invoice
- The supplier’s official website found independently
- A signed contract
- An established contact directory
The NCSC recommends confirming payment requests through a second communication channel, particularly when bank details have changed.
Use Dual Approval for Payments
No single employee should be able to:
- Create or edit a supplier
- Change bank information
- Approve the invoice
- Release the payment
Separate these duties.
A strong process may require:
- One person to enter the supplier information
- Another to verify the bank details
- An authorised approver to approve the invoice
- A separate person to release the payment
This makes one compromised account less useful to the attacker.
Treat Bank-Detail Changes Separately From Invoice Approval
Approving an invoice should not automatically approve new bank information.
Use separate workflows for:
- Supplier onboarding
- Bank-detail changes
- Invoice approval
- Payment release
A genuine invoice can still contain fraudulent bank details.
Create a Supplier Verification Record
When a supplier’s details are verified, record:
- Date
- Employee performing verification
- Supplier contact spoken to
- Telephone number used
- Source of that telephone number
- Bank details confirmed
- Second approver
- Supporting evidence
This creates accountability and helps during audits.
Use Small Test Payments Carefully
Some organisations send a small test payment before a major transfer.
This can add assurance, but it is not sufficient by itself.
The attacker may control the fraudulent account and confirm receipt of the test amount.
A test payment should follow—not replace—independent supplier verification.
Require Purchase Orders
A valid payment request should normally connect to:
- An approved purchase order
- A recognised supplier
- An agreed service
- A known department
- A recorded contract
- A confirmed goods receipt
Purchase-order matching will not stop every BEC attack, but it reduces opportunities for fabricated payments.
Use Payment Limits
Set thresholds requiring additional approval.
For example:
- Routine low-value payments: normal approval
- Medium-value payments: two approvers
- High-value or new-account payments: senior approval and telephone verification
- Bank-detail changes: mandatory second-channel confirmation regardless of value
A fraudster may deliberately request an amount just below the normal approval threshold. Review repeated transfers and split payments too.
Remove Urgency From the Process
A good payment policy should clearly state:
No email, regardless of sender, can override the verification process.
Employees should know that they will not be criticised for delaying a suspicious payment.
Attackers succeed when staff believe that stopping to verify will upset senior management.
Executives must actively support the controls.
Protect Finance and Executive Accounts
Finance employees and senior executives are high-value BEC targets.
Protect their accounts using:
- Phishing-resistant MFA
- Conditional Access
- Managed devices
- Strong endpoint protection
- Separate administrator accounts
- Restricted browser extensions
- Sign-in monitoring
- Rapid token revocation
Traditional MFA remains important, but attackers may steal authenticated sessions through adversary-in-the-middle phishing.
Passkeys and FIDO2 security keys provide stronger resistance to credential-phishing attacks.
Configure Email Authentication
Implement and maintain:
- SPF
- DKIM
- DMARC
These controls can reduce direct domain spoofing.
However, they do not stop:
- Compromised genuine mailboxes
- Lookalike domains
- Supplier account compromise
- Social engineering from legitimate accounts
DMARC is an important layer, not a complete BEC defence.
Add External Sender Indicators
Clearly label messages originating outside the organisation.
This can help users recognise when a person claiming to be an internal executive is actually contacting them externally.
The warning should not become so visually noisy that staff ignore it.
Protect Against Lookalike Domains
Use domain monitoring and impersonation protection to detect:
- Newly registered lookalike domains
- Executive-name impersonation
- Supplier impersonation
- Display-name spoofing
- Similar domain spellings
Microsoft has documented BEC campaigns using typo-squatted domains that appeared similar to legitimate senders.
Monitor Mailbox Rules and Forwarding
Attackers frequently create mailbox rules to hide replies and alerts.
Monitor for:
- External forwarding
- Rules deleting messages
- Rules moving finance-related email
- Rules hiding replies from suppliers
- Newly created unusual folders
- Changes made soon after a risky sign-in
A mailbox rule does not need to contain obviously malicious words to be dangerous.
Review Sign-In Logs
Finance and executive sign-ins should be reviewed for:
- Unfamiliar countries
- Unknown devices
- Unusual IP addresses
- High-risk events
- Token anomalies
- Unexpected applications
- New authentication methods
- Impossible or atypical travel
A successful sign-in can still be malicious.
The attacker may be operating through a stolen token or compromised device.
Train Finance Staff With Real Examples
Generic phishing training is not enough.
Finance teams should practise scenarios involving:
- Changed bank details
- A director requesting urgent payment
- A compromised supplier thread
- A revised invoice
- Payroll bank changes
- Confidential legal payments
- A request arriving before a holiday
- A familiar sender refusing telephone verification
Training should focus on the procedure, not merely visual clues.
A perfect-looking email should still fail when the payment process is strong.
Create a Safe Escalation Route
Employees need to know:
- Who to contact
- How to pause a payment
- How to verify a supplier
- How to report a suspicious email
- Who can approve an exception
- What information to preserve
The process must remain available when the finance manager or director is absent.
What to Do After a Fraudulent Payment
Speed matters.
1. Contact the Bank Immediately
Tell the bank that the payment was fraudulent and request:
- A transfer recall
- A freeze request
- Contact with the receiving bank
- Escalation to the fraud team
The FBI advises contacting the financial institution immediately and asking it to contact the institution that received the payment.
2. Contact Law Enforcement and Reporting Services
For a UK organisation, follow the appropriate reporting routes advised by law enforcement, Action Fraud and the NCSC.
US organisations should report BEC through the FBI’s Internet Crime Complaint Center.
Rapid reporting can improve the chance of fund recovery.
3. Preserve the Email Evidence
Retain:
- Original messages
- Message headers
- Attachments
- Invoices
- Bank instructions
- Supplier correspondence
- Telephone records
- Payment timestamps
- Bank reference numbers
Do not simply forward the message and delete the original.
4. Secure the Email Accounts
When compromise is suspected:
- Disable or restrict the account
- Revoke active sessions
- Reset credentials
- Review MFA methods
- Remove malicious inbox rules
- Remove external forwarding
- Review OAuth applications
- Inspect delegated mailbox access
Microsoft’s compromised-mailbox guidance recommends reviewing forwarding, inbox rules, account access and other methods attackers use to retain control.
5. Investigate Both Organisations
The compromise may exist in:
- Your organisation
- The supplier
- Both organisations
- A third-party email system
Do not assume the supplier is responsible simply because the message came from its mailbox.
6. Warn Other Potential Targets
The attacker may use the same compromised thread to target:
- Other customers
- Other suppliers
- Additional finance employees
- Senior managers
- Payroll teams
Contact relevant parties through trusted channels.
7. Review Data Exposure
The attacker may have read more than the payment conversation.
Review whether they accessed:
- Customer details
- Contracts
- Personal information
- Employee data
- Legal documents
- Additional invoices
- Future payment schedules
The incident may therefore involve a reportable data breach as well as financial fraud.
What Not to Do
Do Not Wait for the Supplier to Reply
The attacker may control or filter that mailbox.
Do Not Continue Using the Same Email Thread
Move to a verified communication channel.
Do Not Change Only the Password
Active sessions, OAuth permissions and mailbox rules may remain.
Do Not Blame the Employee Immediately
A blame-driven culture discourages rapid reporting.
Speed and evidence matter more than finding fault during the first response.
Do Not Assume the Money Is Gone
Contact the bank and authorities immediately. Some funds can be frozen or recovered when action is fast.
A Finance Team Invoice Fraud Checklist
Before paying:
- Is the supplier known?
- Does the invoice match a valid purchase order?
- Is the amount expected?
- Have the bank details changed?
- Was the change independently verified?
- Was a trusted telephone number used?
- Has a second person approved the payment?
- Is the request unusually urgent or confidential?
- Does the sender refuse verbal confirmation?
- Is the payment going to the expected country and account name?
After changing supplier details:
- Record who requested the change.
- Confirm through a trusted contact.
- Require two-person approval.
- Notify the supplier through its established channel.
- Review the first payment carefully.
- Retain verification evidence.
A Practical Payment Verification Policy
A useful policy can be stated simply:
No new supplier, bank-detail change or unusual payment instruction will be accepted solely by email.
Require independent verification for:
- New bank accounts
- Changed account numbers
- Changed sort codes
- Changed IBANs
- Changed beneficiary names
- Changed payment countries
- Requests to split payments
- Urgent transfers outside normal procedures
The rule should apply equally to:
- Suppliers
- Directors
- Customers
- Solicitors
- Internal colleagues
Authority does not replace verification.
Final Thoughts
Business email compromise succeeds because it hides inside ordinary business activity.
The invoice may be genuine. The supplier may be real. The conversation may be authentic. The attacker only needs to change where the money is sent.
Technology can reduce the risk through stronger authentication, email filtering, domain protection, sign-in monitoring and endpoint security.
But the most dependable control remains a well-designed finance process.
Verify every bank-detail change through a trusted communication channel. Separate supplier maintenance from payment approval. Require more than one person for significant transfers. Give employees permission to pause suspicious payments regardless of who appears to be requesting them.
The essential rule is simple:
Never trust new payment instructions solely because they arrived in a familiar email thread.
A two-minute independent telephone check can prevent a six-figure loss.
Worried About Business Email Compromise and Invoice Fraud?
Hamilton Group can help your organisation strengthen Microsoft 365 security and payment-fraud controls.
Our experts can help you:
- Protect finance and executive accounts
- Deploy phishing-resistant MFA
- Configure Microsoft Defender for Office 365
- Improve impersonation and lookalike-domain protection
- Monitor mailbox forwarding and inbox rules
- Review Microsoft Entra sign-in activity
- Investigate compromised mailboxes
- Build a BEC incident-response plan
- Deliver targeted finance-team security training
- Review supplier and payment-verification processes
Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to strengthen your protection against invoice fraud and business email compromise.