Skip to content

Business email compromise: invoice fraud red flags

BEC scams change bank details or rush payments through email. Spot the red flags, add out-of-band verification and harden accounts against takeover.

Koltrix Team4 min read
A fishing hook hanging from the side of a boat
Photo by Kaptured by Kasia on Unsplash
On this page(7 sections)
  1. What business email compromise looks like
  2. How attackers get in position
  3. Red flags in the message
  4. The process controls that stop it
  5. Out-of-band verification for bank changes
  6. Cooling-off periods
  7. Dual approval for payments above a threshold
  8. No exceptions for urgency or seniority
  9. Technical controls that support the process
  10. Harden mailboxes against takeover
  11. Make impersonation visible
  12. Authenticate your own domain
  13. Ask suppliers to do the same
  14. If it happens anyway
  15. Key takeaways

Business email compromise rarely involves malware or a clever exploit. It involves a believable email asking someone in finance to pay a real-looking invoice into a different bank account.

The defenses that work are mostly process, with a few technical controls that make the process easier to follow.

What business email compromise looks like

The FBI's Internet Crime Complaint Center has for years ranked business email compromise among the most costly categories of reported cybercrime. The common patterns are:

  • Vendor payment diversion. A supplier's "accounts team" writes to say their bank details have changed. Future invoices should be paid to the new account.
  • Executive impersonation. A message that appears to come from the CEO or CFO asks for an urgent, confidential wire transfer.
  • Payroll diversion. An "employee" asks HR to update the bank account their salary goes to.
  • Invoice hijacking inside a real thread. An attacker who has compromised a mailbox, yours or a supplier's, replies within an existing conversation about a real invoice, with altered payment details attached.

The last pattern is the hardest to spot, because everything around the request is genuine: the thread history, the people, the invoice amount and often the sending mailbox itself.

How attackers get in position

Three techniques supply almost every BEC attempt:

  1. Spoofing your exact domain, which DMARC at enforcement largely blocks at receivers that honor it.
  2. Lookalike or display-name impersonation, which passes authentication because the attacker's domain or mailbox is real.
  3. Account takeover, typically through phished credentials or password reuse, which gives the attacker a genuine mailbox to send from and the ability to read ongoing conversations.

Account takeover is the most dangerous, because authentication, reputation and context all check out. Attackers with mailbox access commonly create inbox rules that hide replies from the real owner, such as moving any message containing "invoice" or "bank" into an obscure folder.

Red flags in the message

Train finance and procurement staff to slow down when they see any of these:

Red flag Why it matters
Any change to bank details, by email The single most common BEC goal
Urgency plus secrecy ("today, keep this between us") Designed to bypass normal checks
A sender address that differs subtly from usual Lookalike domains and free mailboxes
Reply-To pointing somewhere else Moves the conversation to the attacker
New contact person at a known supplier Often an invented "new accounts manager"
A request to bypass the usual approval path Undermines your existing controls
Unusual payment destination country or bank Diverted funds often move abroad
Slight changes to invoice templates or PDFs Edited copies of genuine invoices
Executive writing from a personal account "I'm traveling, use this address"

No single flag proves fraud. Two or more together, especially combined with a bank detail change, should always trigger verification.

The process controls that stop it

Out-of-band verification for bank changes

This is the control that matters most. Any request to add or change payment details is confirmed by calling the supplier or employee on a phone number already in your records, from before the request arrived. Never use contact details from the email making the request; the attacker wrote them.

Document the call: who verified, with whom, when, and what number was used.

Cooling-off periods

Hold first payments to new or changed bank details for a short period, and notify the original contact at the supplier through a known channel that the change happened. If the change was fraudulent, the real supplier usually notices.

Dual approval for payments above a threshold

Two people, separately, approve payments over a set amount or any payment to new details. Attackers rarely deceive two people through two channels at once.

No exceptions for urgency or seniority

Make it policy, communicated by leadership, that nobody, including the CEO, can ask finance to skip verification. When executives publicly support the process, staff feel safe saying "I'll just call you to confirm."

Technical controls that support the process

Harden mailboxes against takeover

  • Require multi-factor authentication for every mailbox, ideally phishing-resistant methods such as security keys or passkeys for finance and executive accounts.
  • Block legacy authentication protocols that bypass multi-factor authentication.
  • Alert on new inbox forwarding rules, especially external forwarding, and on rules that move or delete messages containing payment-related keywords.
  • Alert on sign-ins from unusual locations or new devices for high-risk roles.

Make impersonation visible

  • Tag external mail, so a message from "your CEO" that came from outside stands out.
  • Flag inbound mail whose display name matches an executive but whose address is external.
  • Flag mail from newly registered domains or near-matches to your own and your key suppliers' domains.

Authenticate your own domain

Publish SPF, DKIM and DMARC at p=reject for every domain you own, including parked domains. This does not stop lookalikes or compromised accounts, but it removes the easiest attack: spoofing your exact domain to your own staff, customers and suppliers.

Ask suppliers to do the same

You can check any supplier's DMARC policy with a single DNS query:

dig +short TXT _dmarc.supplier.example

A supplier at p=none or with no record can be spoofed more easily. That is worth raising during vendor onboarding, and it is a reason to apply extra verification to payment requests from that supplier.

If it happens anyway

Speed matters. Funds sent by wire are hardest to recover after the first few days.

  1. Contact your bank immediately and ask them to initiate a recall with the receiving bank.
  2. Report the incident to law enforcement; in the United States, that includes the IC3.
  3. Preserve the emails, headers and any inbox rules; do not delete the attacker's messages.
  4. If a mailbox was compromised, reset credentials, revoke sessions, remove malicious rules and review what else the attacker could read.
  5. Notify the affected supplier or customer through a verified channel.

Key takeaways

  • BEC aims at payment and bank detail changes and often uses real, compromised mailboxes.
  • Out-of-band verification on a known phone number is the single most effective control.
  • Dual approval, cooling-off periods and a no-exceptions culture back it up.
  • Multi-factor authentication and alerts on suspicious inbox rules reduce account takeover.
  • DMARC at enforcement removes exact-domain spoofing but not lookalikes or compromised accounts.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn