"Our bank details have changed": how fake invoice scams work
The email arrives in a thread you already know. It's from the supplier you've paid every month for two years, written in their usual friendly tone, with their normal signature. It says they've moved to a new bank and asks you to use the new account details for this month's invoice, attached as usual.
Nothing about it looks like a scam. There are no spelling mistakes, no strange links and no threats. And that's exactly why this type of fraud, known as business email compromise (BEC), is one of the most expensive crimes on the internet. The FBI's internet crime reports put losses from it in the billions of dollars every year, far more than ransomware.
Why it works so well
Most scam emails try to trick you into clicking or logging in. This one doesn't need you to do anything unusual. Paying invoices is your normal job. The scam simply changes where the money goes, and it arrives at the most believable moment, often in a real email conversation.
The three main versions
1. The hijacked supplier
Criminals break into a real email account at one of your suppliers, usually through a phishing email or a reused password. Then they read. For weeks, they watch conversations, learn who pays whom, how invoices are sent and when the next big payment is due. At the right moment, they reply in an existing thread with "updated" bank details.
Because the email genuinely comes from your supplier's account, it passes every technical check. Spam filters and the SPF, DKIM and DMARC checks we explain in this guide can't catch it, because nothing is forged. The account is real; the person typing isn't.
2. The lookalike domain
If they can't get into a real account, criminals register a domain that looks almost identical, like brightline-consulting.co instead of brightlineconsulting.co.uk, or northwlnd.com with an "l" instead of an "i". They copy the supplier's signature and join the conversation from there, sometimes copying a real email thread so the history looks right.
3. The fake boss
An email that looks like it's from your CEO or finance director asks you to make an urgent, confidential payment: a secret acquisition, a supplier who must be paid today, or gift cards for a "client thank-you". It's usually timed for when the real executive is travelling or hard to reach, which scammers can often work out from social media.
Warning signs
- Any change of bank details by email. This alone should trigger a check, however normal the email looks.
- Urgency and secrecy: "must be paid today", "please keep this between us", "I'm in a meeting, just get it done".
- A new bank in a different country from the supplier, or an account in a person's name rather than the company's.
- A slightly different address: check the domain letter by letter. Our guide on checking whether an email is real shows how.
- A different Reply-To address: press Reply and see where your answer would actually go.
- The sender resists a phone call: "I can't talk right now, email is best".
- Small changes in tone: a supplier who always writes "Hi Sam" suddenly writes "Dear Samuel".
The one rule that stops it
Never change payment details based on an email alone. Confirm every change by phone, using a number you already had on file, not the one in the email, and speak to someone you've dealt with before.
This single habit defeats all three versions of the scam, including the hijacked-account version that no technology can catch. A criminal can control an email account; they can't answer your supplier's office phone.
Controls for businesses
If you run a business, or handle payments in one, a few simple processes make you a much harder target:
- Written call-back procedure. Make phone verification of bank-detail changes a formal rule, so staff never feel they're being rude by checking.
- Two people for new payees. One person sets up or changes a payee, a second approves it.
- A small test payment to new account details, confirmed by the supplier by phone before the full amount is sent.
- Two-step verification on every email account, so a stolen password isn't enough to get in.
- DMARC on your own domain, so criminals can't send email that appears to come from your exact address.
- Mark external emails with a banner, so an email "from the CEO" that came from outside is obvious.
- Watch for forwarding rules. Criminals who get into an account often add hidden rules that forward or hide emails. Check mailbox rules regularly (see signs your email has been hacked).
- Talk about it. A five-minute team conversation about this exact scam is one of the best-value security measures there is.
If you've already paid
Speed matters more than anything else. Banks can sometimes freeze or recall transfers, but only in the first hours or days.
- Call your bank immediately and ask them to recall the payment and contact the receiving bank. Use the word "fraud".
- Report it to your national fraud reporting service. In the US, the FBI's IC3 (ic3.gov) has a team that works with banks to freeze funds.
- Tell the real supplier, using a phone number you trust. Their email may be compromised, and other customers could be targeted next.
- Secure your own email: change passwords, check for forwarding rules, and turn on two-step verification, in case the breach was on your side.
- Keep everything: emails with full headers, invoices and payment confirmations. Your bank and the police will need them.
It isn't only businesses
The same trick targets individuals at the most expensive moments of their lives. People buying a house receive an email "from their lawyer" with new account details for the deposit, just days before completion. People renovating get "updated details" from a builder. The rule is the same: call someone you know, on a number you already have, before any large payment goes anywhere new.
It feels awkward to question an ordinary-looking email. It's far less awkward than explaining why the money went to a stranger.