Cys Infotech

Smarter sites, safer businesses — no strings attached.

Home / Blog

What Is Invoice Fraud, and How Does It Actually Work?

Short answer: Invoice fraud is an email, sometimes from a vendor's real but compromised account, claiming their bank details changed so you send a real payment to the wrong account. Transfers generally can't be reversed, so verify any bank-detail change by phone, using a number you already had.

Invoice fraud doesn't need a hacker, malware, or a stolen password. It needs one email, at the right moment, about something you were already expecting to pay. That's what makes it different from phishing or ransomware — there's often nothing technical to detect at all. It's sometimes called Business Email Compromise, or BEC, in more formal write-ups; the plain-English version is simpler: someone convinces you to pay the right amount, for a real invoice, to the wrong bank account.

What's actually happening

The setup is always the same shape: a business is already expecting to pay a real invoice to a real vendor — a supplier, a contractor, a software provider, anyone they've paid before. Right around when that payment is due, a message arrives claiming the vendor's bank account has changed, and asking that this payment (and future ones) go to a new account instead.

The message usually comes one of two ways:

Either way, once the payment goes out — usually by wire transfer or ACH — it's gone. Those payment methods aren't like a credit card charge; there's generally no reversing it once it's sent. The business finds out something's wrong only when the real vendor eventually asks why their invoice still hasn't been paid.

The invoice is real — it's the "updated" bank details that aren't

A local business scenario

(A composite, illustrative pattern — not one specific business's story.)

A small contracting business gets materials from the same supplier every month, paid by bank transfer against a monthly invoice — a routine that's run smoothly for two years. One month, right on schedule, an email arrives from the supplier's actual accounts email address: a brief note explaining they've switched banks, with the new account details attached, asking this month's payment (already due) go to the new account.

Nothing about the email looks unusual — same sender, same tone, same invoice amount as always. The bookkeeper updates the payment details and sends the transfer as normal. Three weeks later, the actual supplier calls asking why their invoice is overdue. The money — sent to an account that had nothing to do with the supplier at all — is already gone.

Why "just check the email" isn't enough here

The advice that works well against phishing — check the sender's real address, hover the link — doesn't fully apply here, because in the compromised-account version of this scam, the email genuinely is from the real vendor. No amount of scrutinizing the message itself catches that. The only thing that reliably does: verifying the change through a separate channel you already trust — calling a phone number you already had on file (not one in the email, which could be fake too) and asking directly, "did you just send us new bank details?" That one phone call, every time bank details change, is the entire defense.

Best practices

  1. Never change payment details based on an email alone, no matter how legitimate it looks or where it appears to come from. Verify by phone, using a number you already had — not one provided in the message asking for the change.
  2. Treat "our bank account changed" as a red flag by default, especially right before or during a real payment cycle — that timing isn't a coincidence, it's the attack working as designed.
  3. Set up a simple internal rule: any change to a vendor's payment details requires a phone verification before the next payment goes out, no exceptions for regular vendors or small amounts.
  4. Double-check new wire/ACH details specifically — these payment methods are fast and generally can't be reversed, unlike a credit card charge, which is exactly why they're the target here.
  5. If a payment does go to the wrong account, act immediately. Contact your bank and the receiving bank the same day — there's a narrow window where a transfer can sometimes still be recalled or frozen before the funds move further; waiting even a few days usually closes that window entirely.

Helpful, free resources

A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.