Invoice fraud and BEC prevention for small teams
The most expensive email a small business ever receives doesn't look like a hack. It looks like accounting work: an invoice, a "kindly note our bank details have changed," a reply on an existing thread. Business email compromise and invoice fraud work precisely because they arrive dressed as routine — no attachments, no broken grammar, no suspicious links. Just a request your payables process handles every week. The FBI's loss figures for BEC run into the billions a year, and small companies are the preferred target for exactly one reason: no payment controls between the inbox and the bank.
This is the control set that closes the gap. It costs nothing to run, adds minutes to each payment, and it works even when every other defense fails — because its core move is refusing to act on email alone.
1. Know the four frauds that arrive looking like accounting work
Everything else in this checklist is a defense against these four plays:
- CEO fraud ("the urgent payment"). An email or chat from the boss's real address (or a lookalike) asks for a quiet, urgent transfer — "supplier settlement," "confidential acquisition," "don't loop anyone in, I'm in a meeting." The secrecy is the tell: real deadlines survive being verified.
- The vendor bank-change email. A known vendor emails updated account details, usually with a plausible reason (new bank, "our old bank closed the account"). Payment lands in the attacker's account; the real vendor eventually calls asking why they haven't been paid.
- The fake invoice from a real name. An invoice arrives from a supplier you actually use — maybe one whose mailbox was compromised — with altered banking details or an invented charge. It matches a real vendor relationship, so it clears review.
- Thread hijacking (payment diversion). An attacker gets into a real mailbox, reads the actual invoice thread, and replies inside it from your vendor — or you — with new payment details. No forged domain anywhere; the context is real because it is real.
Note what they have in common: not one of them defeats a callback. That's why the next section is the whole game.
2. The one rule that stops most of it: bank details change by voice, never by email
Institute a single, non-negotiable control: a change of payment details is confirmed by calling the vendor on the phone number you already have — from the vendor ledger, not from the email signature or the invoice. Attackers control the whole paper trail when they're inside an email conversation; the signature block, the letterhead, the "call me to confirm" number are all attacker-controlled. The only channel they don't control is the phone number your ledger recorded last year.
- Callback on the known number. If the ledger number goes to voicemail, the payment waits. "I couldn't reach them on the recorded number" is a complete sentence; "the invoice had the new number" is a hole in the hull.
- Make it a script, not a judgment call. "Hi, we received banking changes on this invoice — please confirm your account details for our records." Legitimate vendors never object; they're used to it, because their bank asks them the same questions.
- Same rule for "verify by replying." Replying to the same thread verifies nothing — the attacker reads the thread. Verification must leave the compromised channel entirely.
- First payment to a new vendor gets the full treatment too. Verify the entity's registration (company registry lookup), confirm bank details by voice, and make the first payment small — a trial transaction that proves the rails before real money moves.
Write the rule on the wall if you have to: "We never change bank details because an email said so." It's the cheapest fraud control in existence and it would have stopped most of the headline losses.
3. Make payments boring
Fraud needs urgency and improvisation. Payables should offer neither. The change-management principle applies to money the same way it applies to production: changes to payment rails go through a defined path, with review, not through whoever happened to open the inbox:
- Two-person rule above a threshold. Any payment over an amount you set (for many small teams, one day's revenue is a good line) requires the maker and a second approver — different people, and the second person confirms vendor and amount against the ledger, not against the email.
- No "urgent" bypass. The exception process for urgent payments is... a faster version of the normal process. If a payment can only go out by skipping verification, the fraudster has already designed your process for you.
- Match three things before paying. Invoice matches a purchase order or contract, invoice matches the vendor ledger entry, bank details match the last verified details. A mismatch in any one stops the payment.
- Keep the vendor ledger current. Every vendor row has: verified contact number, verified bank details, who verified it, and when. This ledger is the reference the callback in section 2 depends on — garbage ledger, useless control. Vendor screening on entry belongs in the vendor security review.
- Amounts just under the threshold are a signal, not a coincidence. Fraudsters probe approval limits. One invoice at $4,900 against a $5,000 line is nothing; three in a month is a pattern. Track it.
4. Learn the tells (and the one that matters most)
Tells are weak defenses alone — but they cost nothing to teach:
- Display name vs. domain. "CFO Michael" can display over
michael@cfo-legacycapltal.com(lookalike: capltal). Train eyes to check the actual domain on every payment-related email, not the display name. - Reply-to mismatch. From: shows the vendor's real domain; the hidden Reply-To goes elsewhere. Show full headers for anything payment-related.
- Urgency plus secrecy. "Wire today," "don't discuss with accounts," "I'm boarding a flight" — pressure aimed at bypassing exactly the two-person rule in section 3. That combination is the classic BEC signature.
- Style drift. A thread-hijacker writes differently from the vendor you've emailed for two years. Slightly-off greetings, different sign-off, new footer. Notice and check.
- Domain age. A vendor "you've worked with for years" emailing from a domain registered three weeks ago is not a vendor. WHOIS lookup takes thirty seconds.
The honest caveat: a good attacker clears every tell above. That's why the tells are the last line — the callback rule is the first, and the drill in section 7 is what makes both survive a bad week.
5. Harden the mailbox layer
BEC gets easier when your own mailboxes leak. The email security checklist carries the full stack — SPF, DKIM, and DMARC enforcement, MFA, access review — and the payables-specific additions are:
- External-sender banners. Every external email gets a visible tag in the client. Half of BEC defense is just making "this is from outside" impossible to miss.
- Quarantine rule-change alerts. Mailbox rules that auto-forward, auto-delete, or redirect — a classic post-compromise move to keep a thread hijack alive — should trigger an alert to admin, not happen silently.
- Watch for lookalike domains in your logs. If
yourcompany-payments.comgets registered and starts sending you mail, that's a campaign aimed at you. DMARC reports will show the senders; see the SPF/DKIM/DMARC checklist. - Phish handling is pre-decided. When the fake bank-change email arrives (and one eventually will), nobody improvises: the phishing response checklist is the drill.
6. If a payment already went out: the first hour
Money leaves fast; the recall window is minutes to hours, not days. If you find a fraudulent payment — or even a strong suspicion — the sequence matters:
- Call your bank immediately. Ask for a recall/freeze on the transfer. Say the words "fraudulent transfer" — that routes you somewhere different from "I made a mistake." Speed here is the difference between recovery and a write-off.
- Ask the receiving bank to freeze via your bank. Your bank can contact the beneficiary bank; if funds are still in the account, they can be frozen. Every hour of delay drops the odds.
- Report it. In the US, file with the FBI's IC3 the same day (their RAT process exists precisely to freeze wire fraud funds); note your local equivalent elsewhere. This also creates the paper trail your cyber insurance claim will want.
- Treat the mailbox as compromised until proven otherwise. If a thread was hijacked, the attacker is still reading it. Rotate the mailbox credentials, revoke sessions and tokens, kill suspicious forwarding rules — the credential-leak runbook logic applies to mailboxes too.
- Tell the team the boring truth. "We paid a fraudster; here's the email; here's what we changed" recruits your team into the defense. Silence guarantees a repeat, because the same play works twice on the same target.
For the wider blast radius (was data also taken? which systems saw that mailbox?), the first 24 hours of a breach picks up where this section stops.
7. Drill it quarterly
Controls decay into folklore unless tested. Once a quarter, run a fifteen-minute drill:
- Send yourselves the attack. A fake "updated bank details" email from a lookalike domain, or a "CEO urgent payment" note. Did the recipient callback on the ledger number, or did they start typing a transfer?
- Walk one real payment end to end. Invoice in, three-way match, callback if anything changed, two-person approval, payment out. Time it. If verification makes the process take three days, fix the process — controls that are too slow get bypassed the first time a real deadline arrives.
- Re-run the drill when finance changes. A new bookkeeper, a new approver, a new bank — each is a reset of the human control layer. Ten minutes of drill on day one is cheaper than any fraud loss.
8. Write the one page
Close it out with a single-page payment controls policy — it's also what your bank, insurer, and any customer audit will ask for:
- Rules: bank changes verify by callback on ledger number; two-person approval above $X; three-way match before every payment; no urgent bypass.
- Roles: who enters, who approves, who owns the vendor ledger (and who it's reviewed by at the annual security review).
- Drills: last drill date, what it caught, what changed because of it.
The whole document fits on one page and most of it fits on a sticky note: "Bank details change by voice. Payments need two people. Urgent means verify faster, not skip." Businesses lose wire-fraud money not because the attacks are clever — they're mostly patient and plausible — but because on the day it arrived, paying it was the normal path and checking it was the exception. Invert that, and the most profitable email in fraud history becomes just another thread nobody acted on.