How it actually works
Someone gets into a mailbox — often at your supplier, not at your business. They don't do anything dramatic. They read. They wait until an invoice is about to be sent, then send their own version: same letterhead, same amounts, same email thread, different account number. Sometimes they add a polite line explaining the change.
It works because almost everything about it is real. The invoice is real, the job was real, the person is real. The only thing that changed is four lines of bank details near the bottom.
The tell
Any change of payment details, ever. A supplier changing accounts is rare. A scammer changing accounts is the entire scheme. Treat the change itself as the warning, regardless of how the message reads.
The process that stops it
None of that is technical, and that's why it works. The technical controls — multi-factor authentication, email filtering, domain authentication — make the compromise harder. The phone call is what catches the one that gets through.
If you've already paid one
Call your bank immediately, before anything else. Recovery is sometimes possible in the first hours and rarely possible after that. Then report it to ReportCyber, tell the supplier so they can check their own mailbox, and get someone to look at whether the compromise was at your end. Then change the passwords and turn on MFA on everything.
What we do about it
For plan clients we set up email filtering and domain authentication, roll out MFA, and run a short session with whoever pays the bills — twenty minutes, real examples, no lecture. The session is the part that reliably prevents money leaving.