Smarter sites, safer businesses — no strings attached.
Short answer: Invoice fraud is an email, sometimes from a vendor's real but compromised account, claiming their bank details changed so you send a real payment to the wrong account. Transfers generally can't be reversed, so verify any bank-detail change by phone, using a number you already had.
Invoice fraud doesn't need a hacker, malware, or a stolen password. It needs one email, at the right moment, about something you were already expecting to pay. That's what makes it different from phishing or ransomware — there's often nothing technical to detect at all. It's sometimes called Business Email Compromise, or BEC, in more formal write-ups; the plain-English version is simpler: someone convinces you to pay the right amount, for a real invoice, to the wrong bank account.
The setup is always the same shape: a business is already expecting to pay a real invoice to a real vendor — a supplier, a contractor, a software provider, anyone they've paid before. Right around when that payment is due, a message arrives claiming the vendor's bank account has changed, and asking that this payment (and future ones) go to a new account instead.
The message usually comes one of two ways:
Either way, once the payment goes out — usually by wire transfer or ACH — it's gone. Those payment methods aren't like a credit card charge; there's generally no reversing it once it's sent. The business finds out something's wrong only when the real vendor eventually asks why their invoice still hasn't been paid.
(A composite, illustrative pattern — not one specific business's story.)
A small contracting business gets materials from the same supplier every month, paid by bank transfer against a monthly invoice — a routine that's run smoothly for two years. One month, right on schedule, an email arrives from the supplier's actual accounts email address: a brief note explaining they've switched banks, with the new account details attached, asking this month's payment (already due) go to the new account.
Nothing about the email looks unusual — same sender, same tone, same invoice amount as always. The bookkeeper updates the payment details and sends the transfer as normal. Three weeks later, the actual supplier calls asking why their invoice is overdue. The money — sent to an account that had nothing to do with the supplier at all — is already gone.
The advice that works well against phishing — check the sender's real address, hover the link — doesn't fully apply here, because in the compromised-account version of this scam, the email genuinely is from the real vendor. No amount of scrutinizing the message itself catches that. The only thing that reliably does: verifying the change through a separate channel you already trust — calling a phone number you already had on file (not one in the email, which could be fake too) and asking directly, "did you just send us new bank details?" That one phone call, every time bank details change, is the entire defense.
A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.
An "urgent" text from the boss, asking for gift cards. How gift card scams actually work, why the payment method itself is the giveaway, and the one habit that stops it.
Security awarenessAll sectorsA voice that sounds exactly right is no longer proof of anything. How AI voice-cloning scams actually work, and why the old "I recognized the voice" test has stopped working.
Security awarenessAll sectorsIt's not about symbols and capital letters. Why password reuse is the actual danger, what current official guidance really recommends, and the one tool that makes it easy.
Security awareness