The Invoice Is Real. The Bank Account Isn’t: A Field Guide to Payment-Redirection Fraud
The invoice may show the right supplier, the right amount and even the right project number. It may arrive in the middle of a genuine email thread. The sender may know that a deposit is due on Friday. Only one detail has changed: the bank account.
That small substitution is the center of payment-redirection fraud, sometimes called an invoice-change scheme. It is especially dangerous because the criminal does not need to invent an unbelievable story. Instead, the criminal borrows the history, timing and language of a real relationship, then redirects a legitimate payment at the moment the payer expects to send it.
The FBI treats many of these incidents as business email compromise, or BEC, a category that can affect both organizations and individuals making transfers. The agency’s current BEC guidance describes schemes that use compromised accounts, social engineering or computer intrusion to produce unauthorized transfers. In the FBI’s 2024 Internet Crime Report, complainants reported about $2.77 billion in BEC losses. Reported losses are not a measure of every incident, but the total shows why a changed account number deserves more than a quick glance.
A fraud built from mostly true information
A fake invoice for a service nobody ordered can be spotted during routine reconciliation. Payment redirection is subtler. The debt may be real. The invoice number may be valid. The criminal’s aim is to alter the destination rather than fabricate the entire transaction.
A typical operation develops in stages:
- Observation: An attacker gains access to a mailbox or studies information exposed through websites, social media, breached data and predictable business routines.
- Timing: The attacker identifies a transaction—a contractor’s progress payment, a supplier invoice, a property closing or a professional-services bill—that will move meaningful money.
- Impersonation: The attacker uses a compromised mailbox, a lookalike domain or a forged sender display name. In some cases, malicious inbox rules hide replies from the legitimate account owner.
- The switch: A message announces “updated banking details,” attaches a revised invoice or asks the payer to use a different beneficiary “just this once.”
- Pressure and delay: Urgency pushes the payment through, while excuses discourage a phone call. Afterward, the attacker may send reassuring replies to keep both real parties from comparing notes.
FinCEN, the U.S. Treasury bureau that receives financial institutions’ suspicious activity reports, has described email-compromise fraud as an exploitation of vulnerable business processes. Its BEC advisory makes an important distinction: the weak point is not always the payment system itself. It may be the human process that accepts new instructions.
Why an ordinary reply is not verification
Suppose an accounts-payable clerk replies, “Please confirm this account change.” A prompt “Yes” returns from the supplier’s address. That feels like a check, but it may only ask the attacker to confirm the attacker’s own lie. If the mailbox is compromised, the conversation never leaves the attacker’s control.
Verification must be out of band: it should use a channel and contact detail that did not come from the suspicious request. The FBI specifically recommends a secondary channel for changes in account information and says phone verification should use a previously known number, not a number supplied in the email. A familiar logo, signature block, caller ID or voice is not a substitute for that separation.
The strongest trigger is therefore simple: treat any new or changed payment destination as a new security event. The amount can be small. The message can be polite. The sender can appear familiar. The control activates because the financial destination changed, not because somebody successfully spotted bad grammar.
The Stop–Call–Compare–Approve–Confirm protocol
A household can use this protocol before paying a contractor or sending closing funds. A small organization can turn it into a written accounts-payable rule. The names of the steps matter less than making them consistent and auditable.
1. Stop the request, not the relationship
Do not pay from the message, click its links or open a replacement portal while verification is pending. Mark the request as a payment-detail change and apply a pre-set hold. For routine vendor changes, a business might choose one full business day; for a time-sensitive transaction, it can require live verification plus a second approver. The appropriate hold is a policy decision, but “urgent” should never be the reason the control disappears.
Tell legitimate vendors in advance that account changes always receive this treatment. A standard policy removes embarrassment: staff are not accusing a caller of fraud; they are following the same rule for everyone.
2. Call from a trusted directory
Find the contact number in a record created before the request: the signed contract, prior verified invoice, vendor-master file, official statement or internal directory. For a household, use the number saved when the professional was hired. For a business, the payment team should not copy a number from the new message, its attachment or a website link inside it.
Ask for a known contact in finance or ownership. If that person is unavailable, leave the payment on hold. An incoming call from “the vendor” does not complete the check; caller ID can be spoofed. Place the call yourself.
3. Compare the complete destination
Read back and compare the beneficiary name, bank name, routing or sort code, account number or final digits, and—where relevant—the country. Confirm the effective date and reason for the change. Do not reveal all the new details first and ask the other person to agree. Let the verified contact state enough information to demonstrate that the change exists in the vendor’s own records.
Also compare the business facts: purchase order, scope, invoice total, tax treatment and prior payments. Those checks can expose a wholly fake invoice, although they cannot by themselves validate a bank account. A criminal inside a real email chain may already know them.
4. Approve with a second person
For a new beneficiary or changed account, the person who enters the bank details should not be the only person who releases the payment. A second person reviews the independent call record and the account comparison, then approves through the organization’s normal system. Small teams can define an owner, board treasurer or outside bookkeeper as the backup rather than abandoning separation of duties.
Dual approval is a process control, not two people reading the same email. Both approvers should be able to see where the trusted phone number came from, who was called, when the call occurred and what was verified.
5. Confirm through the established channel
After release, send a confirmation to a previously verified contact and reconcile receipt promptly. For a large or unusual payment, ask the receiving party to confirm arrival through that channel. Some organizations also use a small test payment, but a test is useful only if the recipient confirms it independently; an attacker controlling the email can falsely “confirm” the test too.
Build the call-back directory before an emergency
A call-back rule fails when nobody can find a trusted number. Create a restricted vendor-master record with the legal name, normal remittance destination, verified finance contact, phone source, verification date and approval history. Do not allow a payment-instruction email to overwrite that record automatically.
When a vendor genuinely changes banks, use a separate change form or ticket. Record the original request, the independent call, the employee who entered the change and the second approval. Then notify an established contact that the master record changed. These steps create useful friction exactly where an attacker wants speed and ambiguity.
| Situation | Unsafe shortcut | Safer control |
|---|---|---|
| “Our bank changed” email | Reply for confirmation | Call a number stored before the email |
| Executive requests an urgent wire | Rely on display name or tone | Use known contact details and a second approver |
| Revised PDF invoice | Compare only amount and invoice number | Compare beneficiary and full remittance details |
| Vendor calls to chase payment | Trust caller ID | End the call and dial the directory number |
| Small test transfer | Accept confirmation by the same email | Confirm receipt through the verified channel |
Red flags are clues, not the whole defense
Lookalike domains, a slightly altered reply-to address, an unexpected personal account, secrecy, an unusual bank country and last-minute urgency all justify stopping. So do subtle changes in writing style or a request to bypass a colleague. On mobile screens, expand the sender address rather than trusting the display name.
Yet a polished message from the exact address can still be fraudulent if the mailbox is compromised. Conversely, a real vendor can change banks and write an awkward email. A durable protocol does not attempt to read the sender’s mind. It validates the destination through independent evidence.
The FTC’s 2026 warning on fake invoices targeting small businesses advises clear approval procedures and close invoice review. Those practices complement, but do not replace, destination verification. One catches bills that were never owed; the other catches real obligations redirected to the wrong account.
Controls a small organization can actually maintain
- Protect email accounts: Require multi-factor authentication, unique passwords and prompt removal of former users. Review forwarding rules, delegated access and recovery details after suspicious activity.
- Authenticate the domain: Work with the email provider to configure SPF, DKIM and DMARC. The FTC’s business email imposter guidance recommends email-authentication technology. These controls reduce some spoofing; they do not prove that an already compromised mailbox is safe.
- Separate vendor maintenance from payment release: Limit who can edit beneficiary data. Alert an owner or finance lead when those fields change.
- Use bank controls: Ask the financial institution what dual-control, transaction-alert, beneficiary-management and transfer-limit options it offers. Available features and responsibilities differ by bank, account and payment rail.
- Write escalation into the job: Staff should know that pausing an unusual request is expected. Attackers benefit when employees fear upsetting a boss or vendor.
- Rehearse one scenario: Run a short drill in which a known supplier “changes” accounts. Confirm that the directory, second approver, bank contact and incident sheet are usable.
A household version for contractors and closings
Households face the same pattern during renovations, tuition payments, legal matters and property transactions. Before money is due, save trusted phone numbers and ask how payment instructions will be delivered. Agree that no emailed change will be honored without a call to the known professional.
If an email changes wiring instructions days before a home closing, stop and call the title, settlement or legal professional at the number already in your records. The Consumer Financial Protection Bureau’s mortgage-closing scam guidance likewise tells consumers to use saved numbers and to contact the bank or wire-transfer company immediately if victimized.
Do not assume that a payment labeled “authorized” is easy to recover. Rights and error-resolution procedures depend on the account, transaction type and facts. Ask the financial institution directly, and seek qualified legal advice when the stakes warrant it.
If the payment has already moved
Speed matters, but recovery is never certain. Use a parallel response: pursue the money, preserve evidence and secure the communications channel.
- Call the originating financial institution immediately. Use the number on an official statement, card or authenticated banking session. Ask for the fraud or wire department, explain that the destination resulted from email compromise or payment-redirection fraud, and request whatever recall, reversal, freeze or recipient-bank contact is available. The FBI’s BEC page specifically advises contacting the originating institution as soon as fraud is recognized and asking about a recall or reversal and supporting indemnity documentation.
- Create a precise timeline. Record when instructions arrived, who communicated, when credentials or invoices changed, when the payment was authorized, the amount, transaction reference, receiving institution and every bank contact. Note time zones.
- Preserve original evidence. Keep the original email in its native format with full headers, not only screenshots or forwarded copies. Save attachments, URLs without opening them, text messages, voicemail, call logs, invoices, bank confirmations and internal approvals. Restrict access to the evidence and avoid editing originals.
- Secure affected accounts. From a known-clean device, coordinate with the email administrator to reset credentials, revoke active sessions and tokens, enforce multi-factor authentication, and inspect forwarding rules, delegates, recovery methods and recent sign-ins. Do not delete the compromised mailbox before evidence is preserved.
- Contact the real counterparty independently. Warn the vendor or customer using the trusted directory. Their mailbox may be affected, and other invoices may be at risk. Review recent and pending transactions for similar changes.
- Report promptly. File with the FBI at IC3.gov and include email addresses, domains and transaction details. Report the scam to the FTC at ReportFraud.ftc.gov. A bank, insurer or attorney may also recommend a local police report or other notices. Reporting creates a record and can help responders connect cases, but it does not guarantee reimbursement or recovery.
A composite example: the six-minute message and the 20-minute pause
Imagine a landscaping company owes a nursery $18,600. On Thursday afternoon, the bookkeeper receives a reply inside the real purchasing thread: the nursery has “moved banking partners,” and Friday’s payment must use the attached details. The amount, invoice and delivery dates all match. The sender says the old account will reject the transfer.
Under the company’s protocol, the bookkeeper does not reply. She opens the vendor-master record, calls the nursery’s long-standing office number and asks for its controller. The controller says no account changed. A second employee reviews the message and notices a new reply-to address that was hidden in the mail view. Payment remains directed to the previously verified account, while both companies preserve the message and investigate their mailboxes.
The decisive control was not exceptional technical intuition. It was a routine that made a convincing email insufficient. Six minutes of pressure met a 20-minute pause and an independent phone number.
The 15-minute setup
You do not need a large security department to begin. In the next 15 minutes:
- Write one rule: no new or changed payment destination is accepted from a single message or call.
- Choose the independent source for vendor and professional phone numbers.
- Name a second approver and a backup.
- Save the bank’s authenticated fraud contact route.
- Create an incident sheet for transaction details, timestamps and evidence.
- Tell staff, household members and regular vendors how verification will work.
Payment-redirection fraud succeeds by turning trust into momentum. The answer is not to distrust every invoice. It is to separate the message that requests a change from the evidence that authorizes one. Stop, call, compare, approve and confirm—before the bank account becomes the most expensive line on an otherwise genuine invoice.
