Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

Business Email Compromise: The Invoice That Isn’t

Ransomware gets the headlines. Business email compromise takes more money out of UK businesses, and it does it without any malware at all.

There is nothing to detect, because nothing malicious is sent. Just an email, from an address that looks right, asking for something reasonable. It is the most successful attack against businesses of ten to two thousand people, and it works on competent, careful people.

The three forms it takes

Impersonation of someone senior. A message that appears to come from a director asking for an urgent payment or a change to payroll details. It relies on the reluctance to question someone senior, and on the absence of that person from the room.

Invoice redirection. A supplier emails to say their bank details have changed. The invoice is correct, the branding is right, the amount matches something genuinely owed. Only the account number has changed.

Thread hijacking. The most difficult. An attacker has access to a real mailbox — your supplier’s, or occasionally yours — and replies inside an existing conversation. There is no spoofing to spot because the email genuinely is from the person you think.

Quick check

Four inboxes, four decisions

Each one is based on something that has actually happened to a UK business.

1. Your MD emails from their usual address asking you to pay a new supplier today, and says they are in meetings so cannot take calls. What is the strongest signal?
Urgency is common in real life too. The tell is the attacker closing off verification before you think of it. Any message that explains in advance why you cannot check deserves more checking, not less.
2. A long-standing supplier sends an invoice from the correct address, with correct amounts, and new bank details. What has probably happened?
This is thread hijacking, and it is the hardest version to spot because everything is genuine except the account number. The email really is from them. Only an out-of-band phone call to a number you already held catches it.
3. You receive an invoice from a supplier you use, but the domain is easylifelT.com rather than easylifeIT.com. What happened?
In many fonts a capital I and a lowercase l are identical. Lookalike domains also use rn for m, or add a hyphen. This is why verification should never rely on reading an address carefully.
4. Payment has already gone out to a fraudulent account. What matters most in the first hour?
Speed is everything. Funds can sometimes be recalled if the bank is told within hours, and almost never after a few days. Report to Action Fraud too — but call the bank first.
Score: 0 of 4

Why intelligent people fall for it

Because it does not look like an attack. It looks like a Tuesday.

The message arrives in the middle of a busy afternoon, from someone you know, about something you were expecting. It is plausible, specific, and often follows genuine correspondence. Attackers frequently sit in a compromised mailbox for weeks, reading, learning the tone, and waiting for a real invoice to intercept.

Training helps people recognise the pattern. It does not reliably stop it, because the whole design of the attack is to look normal. Which is why the defence has to be process rather than vigilance.

The two rules that actually stop it

Rule one: any change to payment details is verified by phone, on a number you already held. Not a number in the email, not a number on the new invoice, and not by replying to the message. A number from your existing records, or from the supplier’s website typed in fresh.

This single rule defeats every variant above, including thread hijacking, because the attacker controls the email conversation but not your supplier’s switchboard.

Rule two: anyone can pause a payment without justifying it. Invoice fraud works on urgency and on the social cost of appearing obstructive. If the most junior person in accounts needs courage to question an email from a director, the control does not exist.

Say out loud, and in writing, that nobody will ever be criticised for checking. Then make sure the first time someone does, they are thanked.

Technical measures that help

They will not stop thread hijacking, but they reduce the volume considerably.

MFA on every mailbox, because a compromised mailbox is how the worst version begins. External sender warnings, so a message claiming to be internal but arriving from outside is visibly flagged. SPF, DKIM and DMARC configured properly on your own domain, which stops attackers spoofing you to your customers. And alerting on mailbox forwarding rules — one of the first things an attacker does is create a rule that hides their replies from the real owner.

If it has already happened

Call the bank immediately. Funds can sometimes be recalled within hours and almost never after a few days. Speed matters more than understanding what happened.

Then report it to Action Fraud, preserve the emails rather than deleting them, and check whether the compromise was at your end — look for forwarding rules and unexpected sign-ins. If personal data was exposed, the 72-hour ICO clock applies.

And resist the urge to find someone to blame. The person who processed the payment was doing their job, using the information they had. The failure was the absence of a verification step, and that is fixable.

Worth doing this week

Write the two rules down, tell everyone who handles payments, and check that mailbox forwarding alerts are switched on. It is an hour of work against the most expensive attack most businesses will face.

If you would like us to check your mail configuration and forwarding rules, it is a quick job and occasionally an eye-opening one.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading