Cybersecurity
How Payment Fraud Actually Reaches Small Businesses
The attack that takes the money isn't technical — it's an email about changed bank details. Here's how it works, the two rules that stop it, and what to do in the first hour.
The attacks that actually take money from small businesses aren't technical. There's no malware, nothing to detect, and the email looks completely ordinary.
Someone emails your bookkeeper saying a supplier's bank details have changed. The invoice is real, the amount is right, and the payment goes to an account that isn't theirs.
The three that account for most of it
Supplier bank detail change. The most common and most costly. An email — sometimes from a genuinely compromised supplier mailbox, so it comes from the real address — says the account has changed. Attach a plausible-looking invoice and it clears every internal check you have.
Owner impersonation. An email appearing to be from you, to whoever handles payments, asking for an urgent transfer. Often timed for when you're visibly travelling or in meetings, which is public information from your own social accounts.
Fake invoices. A genuine-looking invoice for something plausible — a domain renewal, a directory listing, an equipment service — from a supplier nobody quite remembers approving. Small enough to pay without scrutiny, sent at volume.
Why it works
Not because people are careless. Because the attack is designed around the checks.
Urgency exists to prevent verification. "Before end of day", "the supplier is chasing", "I'm about to board" — the deadline isn't real, it's there to make checking feel like the delay rather than the prudent step.
Authority makes questioning feel awkward. If the request appears to come from the owner, a junior person querying it feels like an accusation.
It's plausible. Suppliers genuinely do change bank details. Owners genuinely do send urgent requests. Nothing about it is inherently suspicious.
The two rules
Almost all of it is stopped by two rules, applied without exception.
1. Every bank detail change is verified by phone, on a number you already had.
Not a number in the email. Not a number on the new invoice. A number from your existing records, or the one you've been calling for two years.
The email is the thing being questioned; you can't verify it using information from itself.
2. Every unexpected payment request is verified, however urgent.
If it wasn't expected, it gets a phone call. Including — especially — when it appears to come from you.
Say the awkward part explicitly
The rules only work if people feel able to apply them. So say this out loud, to whoever handles payments:
Verifying is never an insult and never a delay problem. If something claims to be from me and it's urgent, call me. If you can't reach me, it waits. You will never be in trouble for checking, and you will never be in trouble for a payment that was delayed by verification.
That paragraph is the control. Without it, the process exists on paper and someone approves a payment anyway because questioning the boss felt worse than the risk.
The supporting controls
Beyond the two rules:
Dual approval above a threshold. Any payment over an agreed amount needs two people. The threshold should be low enough to matter and high enough not to be constant friction — it's a decision rule like any other.
A supplier record with verified details, changed only through the phone verification process, with the change logged and who verified it.
Two-factor on email, because a compromised mailbox is how the most convincing version of this happens. Covered in the security basics.
Review outgoing payments monthly against expected suppliers. The fake-invoice version frequently runs for months precisely because each individual amount is unremarkable.
Spotting the signs
Not reliable on their own — the good ones have none of these — but worth knowing:
- A change of bank details, ever. Always verify, no exceptions.
- Urgency combined with unusual process
- A reply-to address that differs from the sender
- A domain that's subtly wrong — a letter swapped,
.coinstead of.com - Pressure not to discuss it with anyone
- A request that breaks your normal approval route
- An invoice for something nobody remembers ordering
Treat any of these as a reason to phone, not as proof of anything.
The first hour after a payment goes wrong
Speed matters enormously here. Recovery odds fall quickly.
- Call your bank immediately. Say it's a fraudulent payment and ask for a recall. Do this before investigating anything — funds can sometimes be stopped or recalled in the first hours and rarely afterward.
- Contact the receiving bank if you can identify it.
- Report it to whichever fraud reporting body covers your jurisdiction.
- Check your email for compromise — forwarding rules, unfamiliar sessions, changed recovery details.
- Warn the supplier, whose mailbox may be the compromised one.
- Then write down what happened and what would have caught it.
Don't spend the first hour working out how it happened. Call the bank. The investigation can wait; the recall cannot.
Afterward
Two things worth doing that most businesses skip:
Fix the process, not the person. These attacks are designed to defeat careful people. If someone approved a fraudulent payment, the gap is in the verification rule, not their judgement — and treating it otherwise guarantees the next one doesn't get reported quickly.
Check your insurance position. Whether this kind of loss is covered varies considerably by policy, and it's worth knowing before rather than after. That's a conversation with your broker.
The mistakes
- Trusting a number from the email. You can't verify a message using itself.
- Treating urgency as a reason to hurry. It's the technique.
- No stated permission to question the owner. The rule fails at the moment it matters.
- No verified supplier record. Nothing to check the change against.
- Investigating before calling the bank. Recovery odds fall by the hour.
- Blaming the person. Guarantees the next one gets reported late.
What to do next
Write the two rules on one page and go through them with whoever can make payments — today. Include the paragraph about verifying never being a problem, in those words.
Then put your bank's fraud line in your phone. In the hour it matters, you don't want to be searching for it.
The Newsletter
WealthLink Weekly
Business. Money. Marketing. Real Estate. Technology. One email.
One email a week. Unsubscribe anytime.