Invoice fraud and BEC prevention for small teams

The most expensive email a small business ever receives doesn't look like a hack. It looks like accounting work: an invoice, a "kindly note our bank details have changed," a reply on an existing thread. Business email compromise and invoice fraud work precisely because they arrive dressed as routine — no attachments, no broken grammar, no suspicious links. Just a request your payables process handles every week. The FBI's loss figures for BEC run into the billions a year, and small companies are the preferred target for exactly one reason: no payment controls between the inbox and the bank.

This is the control set that closes the gap. It costs nothing to run, adds minutes to each payment, and it works even when every other defense fails — because its core move is refusing to act on email alone.

1. Know the four frauds that arrive looking like accounting work

Everything else in this checklist is a defense against these four plays:

Note what they have in common: not one of them defeats a callback. That's why the next section is the whole game.

2. The one rule that stops most of it: bank details change by voice, never by email

Institute a single, non-negotiable control: a change of payment details is confirmed by calling the vendor on the phone number you already have — from the vendor ledger, not from the email signature or the invoice. Attackers control the whole paper trail when they're inside an email conversation; the signature block, the letterhead, the "call me to confirm" number are all attacker-controlled. The only channel they don't control is the phone number your ledger recorded last year.

Write the rule on the wall if you have to: "We never change bank details because an email said so." It's the cheapest fraud control in existence and it would have stopped most of the headline losses.

3. Make payments boring

Fraud needs urgency and improvisation. Payables should offer neither. The change-management principle applies to money the same way it applies to production: changes to payment rails go through a defined path, with review, not through whoever happened to open the inbox:

4. Learn the tells (and the one that matters most)

Tells are weak defenses alone — but they cost nothing to teach:

The honest caveat: a good attacker clears every tell above. That's why the tells are the last line — the callback rule is the first, and the drill in section 7 is what makes both survive a bad week.

5. Harden the mailbox layer

BEC gets easier when your own mailboxes leak. The email security checklist carries the full stack — SPF, DKIM, and DMARC enforcement, MFA, access review — and the payables-specific additions are:

6. If a payment already went out: the first hour

Money leaves fast; the recall window is minutes to hours, not days. If you find a fraudulent payment — or even a strong suspicion — the sequence matters:

For the wider blast radius (was data also taken? which systems saw that mailbox?), the first 24 hours of a breach picks up where this section stops.

7. Drill it quarterly

Controls decay into folklore unless tested. Once a quarter, run a fifteen-minute drill:

8. Write the one page

Close it out with a single-page payment controls policy — it's also what your bank, insurer, and any customer audit will ask for:

The whole document fits on one page and most of it fits on a sticky note: "Bank details change by voice. Payments need two people. Urgent means verify faster, not skip." Businesses lose wire-fraud money not because the attacks are clever — they're mostly patient and plausible — but because on the day it arrived, paying it was the normal path and checking it was the exception. Invert that, and the most profitable email in fraud history becomes just another thread nobody acted on.