Kosmos IT
Menu

Security · 3 min read

The invoice email that catches small businesses

How business email compromise actually works, why it doesn't look like a scam, and the one process change that stops it.

By Jass Singh · Published · Last reviewed

The short answer

Invoice fraud works by compromising a mailbox, watching for a real invoice, then sending a near-identical copy with different bank details. It doesn't look like a scam because most of it is genuine. The reliable defence is a phone call to a known number before any change of bank details is paid.

How it actually works

Someone gets into a mailbox — often at your supplier, not at your business. They don't do anything dramatic. They read. They wait until an invoice is about to be sent, then send their own version: same letterhead, same amounts, same email thread, different account number. Sometimes they add a polite line explaining the change.

It works because almost everything about it is real. The invoice is real, the job was real, the person is real. The only thing that changed is four lines of bank details near the bottom.

The tell

Any change of payment details, ever. A supplier changing accounts is rare. A scammer changing accounts is the entire scheme. Treat the change itself as the warning, regardless of how the message reads.

The process that stops it

  • Any new or changed bank details get verified by phone, on a number you already had — never a number in the email.
  • Payments over a threshold you set need two people. The person who enters it isn't the person who approves it.
  • Staff know they can pause a payment to check, without anyone being annoyed at them for it.
  • New supplier details are recorded once, in your accounting system, not carried forward from an email.

None of that is technical, and that's why it works. The technical controls — multi-factor authentication, email filtering, domain authentication — make the compromise harder. The phone call is what catches the one that gets through.

If you've already paid one

Call your bank immediately, before anything else. Recovery is sometimes possible in the first hours and rarely possible after that. Then report it to ReportCyber, tell the supplier so they can check their own mailbox, and get someone to look at whether the compromise was at your end. Then change the passwords and turn on MFA on everything.

What we do about it

For plan clients we set up email filtering and domain authentication, roll out MFA, and run a short session with whoever pays the bills — twenty minutes, real examples, no lecture. The session is the part that reliably prevents money leaving.

Related service: Cybersecurity · Available across the Redlands, Brisbane, Logan and the Gold Coast.

Paying per callout? Clients on a monthly plan don't wait for things to break.

See our plans
Call 07 3824 6117Book a callout