The email comes from a vendor you have paid every month for six years. The tone is right. It references the correct invoice number. It says their bank was acquired, or that they are consolidating accounts, and asks that this month’s payment go to a new account. It arrives on a Thursday afternoon while your bookkeeper is trying to get the run out before the weekend.
Everything about it looks fine, and that is the point. This fraud does not work by finding careless people. It works by exploiting a reasonable assumption: that an email from a familiar address, referencing real business, is from who it says it is. That assumption is the vulnerability. Here is the pattern, and the ritual that defeats it.
The pattern, in the order it usually happens
The FBI’s Internet Crime Complaint Center calls this business email compromise and describes it as a sophisticated scam targeting both businesses and individuals performing a transfer of funds. IC3 explains that it is typically carried out when perpetrators compromise legitimate business email accounts through social engineering or computer intrusion techniques, resulting in an unauthorized transfer of funds. Note the word “legitimate.” The account is often real.
- Somebody’s mailbox gets opened first. Usually at the vendor, not at you, often through a phishing message weeks or months earlier.
- Then they read quietly. They learn your billing cycle, your invoice format, who approves payments, and how your vendor writes.
- Then the request lands at the right moment. Just before a scheduled payment, with a mild plausible reason rather than a dramatic one.
- The pressure is polite. A deadline, a closing, a discount expiring, a boss on a plane. Rarely a threat. Threats make people suspicious.
- Sometimes it comes from inside. The same trick runs as an executive asking for an urgent transfer, or an employee changing their direct deposit before payroll closes.
For scale: the Internet Crime Complaint Center published a public service announcement dated September 11, 2024 reporting 305,033 domestic and international business email compromise incidents and $55,499,915,582 in exposed dollar loss for the period from October 2013 through December 2023. That same 2024 announcement states the scam has been reported in all 50 states and 186 countries. Your bank will not be shocked when you call.
Why the address looking right proves nothing
There are two versions, and both defeat the “check the sender” advice people have been given for twenty years. The first is a lookalike address where one character is off. IC3 recommends verifying the email address used to send emails, especially on a mobile device, by ensuring the sender’s address appears to match who it is coming from, and recommends showing full email extensions so a spoofed address is visible. Good advice, and it catches the lazy version.
The second version is the one that ends careers. The email genuinely comes from the vendor’s real account, because a criminal is sitting inside it. There is no typo to spot. The signature is correct because it is the real signature. Any procedure that ends with “make sure the email address is right” will approve this payment. That is why the address cannot be your control. We wrote about how these compromises start in the surge in phishing attacks and why blocking them remains a challenge.
The callback rule, stated precisely
IC3’s guidance here is short and specific: use secondary channels or two factor authentication to verify requests for changes in account information with the intended recipient. Turn that into something a bookkeeper can follow without thinking. Any request to change where money goes gets verified by voice, on a number that came from your own records, before anything changes. Every word is load bearing.
- By voice, not by email. Replying to the message to confirm is asking the criminal whether the criminal is legitimate.
- On a number from your records. Not the number in the email, the signature, or the new invoice. The one in your accounting system or on last year’s contract.
- Reach a person you can identify. Ideally someone you have spoken to before. Have them confirm out loud, including the last four digits of the new account.
- Before anything changes. Not before the payment goes out. Before the record is edited. Once the banking details are updated, the next payment leaves on its own.
- Every time, including for people you like. The rule is worthless with exceptions for familiar vendors, because familiar vendors are exactly who gets impersonated.
Dual approval, and writing the verification down
A callback is one control, and it fails when one person is having a bad day. The second control is that no single human can complete a payee change alone. NIST’s small business security guidance is direct: do not allow a single individual to both initiate and approve a transaction, financial or otherwise, and it states plainly that this includes executives and senior managers. That last clause is the one small businesses skip, and the one criminals count on.
Treat a banking change like a brand new vendor: same verification, same second approver. Then write down what you did, in four fields on the vendor record.
- Who called and who answered. Names of both humans on the phone.
- What number was dialed and where it came from. “Number from the signed 2023 agreement,” not “their number.”
- Date, time, and what was confirmed. Including the last four digits verbally confirmed.
- Who approved it. The second person, by name.
That record proves the control exists rather than being something you talk about, and it gives your bank and your insurer something concrete if you ever have to make a claim. While you are at it, ask your banker what happens if a fraudulent transfer goes out and how fast you must call.
Nobody gets in trouble for slowing a payment down
This is the most important paragraph here, and it costs nothing. Say it to your finance staff out loud, then say it in writing: no one at this company will ever be criticized, disciplined, or made to feel foolish for pausing a payment to verify it. Not if the vendor is annoyed. Not if it turns out to have been legitimate. Not if the person they questioned was the owner.
Every one of these frauds succeeds through social pressure, and in a small business the strongest pressure is not the criminal’s fake urgency. It is a bookkeeper’s rational fear of looking paranoid or insubordinate. If you have not explicitly removed that fear, your policy is decoration. Owners who want this control should demonstrate it by being cheerfully verified themselves, in front of other people, at least once.
The bottom line
You cannot filter your way out of this one. No software reliably distinguishes a genuine payment change request from a fraudulent one sent from a genuine account, because at the level of the email there is often no difference. What defeats it is a boring human ritual: verify by voice on a number you already had, require two people for any payee change, write it down, and make it culturally safe to slow down. Technical controls still matter, and our article on why cybersecurity is no longer optional for mid sized businesses covers the rest of the picture, but this specific fraud is stopped by a phone call.
Harrison Ward Technology helps small and mid sized businesses in Denton County put these controls in place and make them stick: hardening the email accounts that get compromised in the first place, making a stolen password less useful, watching for the hidden mailbox rules attackers create, and helping you write a verification procedure your team will follow. If your business moves money on emailed instructions, and nearly every business does, this is worth an hour. Contact us today
Sources:
Comments are closed