Invoice Fraud and BEC: How to Protect Your Business
A practical guide to stopping invoice fraud and business email compromise before money leaves your account — the warning signs, the simple controls that work, and where technology helps.
How do you protect your business from invoice fraud and BEC?
You protect your business from invoice fraud and business email compromise by verifying payment changes through a second channel, and by locking down the email accounts that fraudsters target. Almost every one of these frauds succeeds because someone trusted an email and paid without picking up the phone — so a simple call-back rule, plus strong sign-in security on your mailboxes, stops the large majority before any money moves.
That is the short answer. The rest of this guide explains what these frauds actually look like, why they work on sensible people, and the handful of controls that make the biggest difference.
What invoice fraud and BEC actually are
Business email compromise (BEC) is when a criminal gets access to, or convincingly imitates, a business email account and uses it to trick someone into sending money or data. There is no virus to spot and no dodgy attachment — the email is just a message, often a very plausible one.
Invoice fraud is the most common form. It usually goes one of two ways:
- A fake or altered invoice arrives, asking you to pay a “new” bank account. The logo, the layout and the amount all look right — only the account number has changed.
- A real supplier’s mailbox has been broken into, and the fraudster watches genuine invoices go back and forth, then emails you at exactly the right moment with updated payment details.
The second version is the dangerous one, because the email genuinely comes from the supplier you expect, in a thread you recognise. Nothing looks wrong.
Why these frauds work on careful people
It is tempting to assume only careless businesses fall for this. In practice, the people who get caught are usually busy and doing their job well — that is the point. Fraudsters lean on ordinary workplace pressure:
- Authority. An email that looks like it is from the director, asking accounts to pay something urgently. Most staff are reluctant to challenge the boss.
- Urgency. “The account’s on hold, this needs paying today.” Rushing is the enemy of checking.
- Plausibility. Real supplier names, real amounts, real ongoing conversations. The request fits what you were expecting anyway.
- Routine. Paying invoices is normal work. A fraudulent one hides inside a task you do every day without a second thought.
None of that requires the victim to be foolish. It requires them to be trusting and under time pressure, which describes almost everyone.
The controls that actually stop it
You do not need anything exotic. A few habits and settings do most of the work.
1. Verify every change of bank details — by phone, out of band. This is the single most important rule. If a supplier emails new payment details, or an invoice shows an account you have not paid before, stop and confirm it by voice, using a phone number you already hold. Never use contact details from the email itself — a compromised thread will happily give you the fraudster’s number.
2. Add a second pair of eyes to payments. For anything above a sensible threshold, require two people to approve. A fraud that gets past one busy person often falls apart the moment a colleague asks, “did we check these details?”
3. Turn on multi-factor authentication everywhere. Most BEC starts with a stolen password. Multi-factor authentication means a password alone is not enough to get in, which blocks a huge share of account takeovers. If your email runs on Microsoft 365 or Google Workspace, this is built in and worth enforcing for every account — the way you set up business email matters as much as the email itself.
4. Watch for sneaky mailbox rules. A classic BEC trick is to log into a mailbox and quietly add a rule that hides or forwards certain emails, so the real owner never sees the fraud playing out. Reviewing forwarding and inbox rules is a standard part of good cyber security housekeeping.
5. Slow down on urgency and authority. Make it culturally fine to double-check a payment request, even one that appears to come from the top. A quick verifying call is never an insult. The staff who feel safe asking “is this real?” are your best defence.
Where technology helps — and where it doesn’t
Good email security genuinely reduces your exposure. Modern filtering can flag messages sent from outside your organisation, warn on look-alike sender domains, and catch many impersonation attempts before they reach an inbox. Properly configured sign-in protection, monitoring for unusual logins, and enforced multi-factor authentication all raise the bar. Sensible, well-run managed IT support keeps these protections switched on and up to date rather than assuming someone set them once and they still work.
But be honest about the limits. Technology cannot approve your payments for you. Because BEC often uses a real, legitimate email account, no filter will reliably catch every message — the final defence is a human deciding to verify before they pay. The businesses that stay safe treat technology and process as partners: the tools cut down what reaches people, and the call-back habit catches what slips through.
If you think you’ve been hit
Speed matters more than anything else. Phone your bank straight away and ask them to try to recall the payment — money can sometimes be stopped in the first hours. Report it to Action Fraud, secure the affected mailbox with a new password, check for unauthorised forwarding rules, and get your IT provider looking at how the account was reached so it cannot happen again.
A sensible next step
Most businesses are one clear rule and a few settings away from being far harder to defraud. If you would like a second opinion on how your email is protected — multi-factor authentication, sign-in monitoring, impersonation filtering and the payment habits around them — we are happy to take a look and tell you plainly what is solid and what needs tightening. No scare tactics, just a straight assessment. Get in touch whenever it suits you.
Frequently asked questions
A supplier has emailed us new bank details — is that normal?
It happens legitimately, but it is also the single most common way businesses lose money to fraud. Treat every change of bank details as suspicious until proven otherwise. Call the supplier on a number you already hold — never a number from the email requesting the change — and confirm the new account with a named person before you pay anything.
We think we've already paid a fraudulent invoice. What do we do first?
Move fast. Phone your bank immediately and ask them to attempt a recall of the payment — the first few hours matter most. Then report it to Action Fraud, change the password on the affected mailbox, and check whether email forwarding rules have been added without your knowledge. Tell your IT provider so they can look for how the account was accessed.
Does multi-factor authentication actually stop this?
It stops a large share of it. Most business email compromise starts with a stolen password, and multi-factor authentication blocks an attacker who has the password but not the second factor. It is not a complete answer on its own, but it is the highest-value single control most businesses can turn on this week.
Related services
Want a hand with any of this?
Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.
