Ransomware gets the headlines. Business email compromise takes more money out of UK businesses, and it does it without any malware at all.
There is nothing to detect, because nothing malicious is sent. Just an email, from an address that looks right, asking for something reasonable. It is the most successful attack against businesses of ten to two thousand people, and it works on competent, careful people.
The three forms it takes
Impersonation of someone senior. A message that appears to come from a director asking for an urgent payment or a change to payroll details. It relies on the reluctance to question someone senior, and on the absence of that person from the room.
Invoice redirection. A supplier emails to say their bank details have changed. The invoice is correct, the branding is right, the amount matches something genuinely owed. Only the account number has changed.
Thread hijacking. The most difficult. An attacker has access to a real mailbox — your supplier’s, or occasionally yours — and replies inside an existing conversation. There is no spoofing to spot because the email genuinely is from the person you think.
Four inboxes, four decisions
Each one is based on something that has actually happened to a UK business.
Why intelligent people fall for it
Because it does not look like an attack. It looks like a Tuesday.
The message arrives in the middle of a busy afternoon, from someone you know, about something you were expecting. It is plausible, specific, and often follows genuine correspondence. Attackers frequently sit in a compromised mailbox for weeks, reading, learning the tone, and waiting for a real invoice to intercept.
Training helps people recognise the pattern. It does not reliably stop it, because the whole design of the attack is to look normal. Which is why the defence has to be process rather than vigilance.
The two rules that actually stop it
Rule one: any change to payment details is verified by phone, on a number you already held. Not a number in the email, not a number on the new invoice, and not by replying to the message. A number from your existing records, or from the supplier’s website typed in fresh.
This single rule defeats every variant above, including thread hijacking, because the attacker controls the email conversation but not your supplier’s switchboard.
Rule two: anyone can pause a payment without justifying it. Invoice fraud works on urgency and on the social cost of appearing obstructive. If the most junior person in accounts needs courage to question an email from a director, the control does not exist.
Say out loud, and in writing, that nobody will ever be criticised for checking. Then make sure the first time someone does, they are thanked.
Technical measures that help
They will not stop thread hijacking, but they reduce the volume considerably.
MFA on every mailbox, because a compromised mailbox is how the worst version begins. External sender warnings, so a message claiming to be internal but arriving from outside is visibly flagged. SPF, DKIM and DMARC configured properly on your own domain, which stops attackers spoofing you to your customers. And alerting on mailbox forwarding rules — one of the first things an attacker does is create a rule that hides their replies from the real owner.
If it has already happened
Call the bank immediately. Funds can sometimes be recalled within hours and almost never after a few days. Speed matters more than understanding what happened.
Then report it to Action Fraud, preserve the emails rather than deleting them, and check whether the compromise was at your end — look for forwarding rules and unexpected sign-ins. If personal data was exposed, the 72-hour ICO clock applies.
And resist the urge to find someone to blame. The person who processed the payment was doing their job, using the information they had. The failure was the absence of a verification step, and that is fixable.
Worth doing this week
Write the two rules down, tell everyone who handles payments, and check that mailbox forwarding alerts are switched on. It is an hour of work against the most expensive attack most businesses will face.
If you would like us to check your mail configuration and forwarding rules, it is a quick job and occasionally an eye-opening one.





