Controller or finance manager
“Accounting nearly paid an invoice that turned out to be fake”
Does this sound familiar?
- A supplier emailed new banking details that turned out not to be theirs
- An urgent payment request appeared to come from the owner or CEO
- Staff received replies inside a real email thread they had been having
- Someone noticed a mailbox rule nobody created
- A payment went out and the real supplier is still chasing the invoice
What it costs to ignore
Business email compromise costs organisations more than ransomware does, and it rarely involves malware — so antivirus never sees it. Wire transfers are often unrecoverable after 24 to 48 hours. Insurers frequently treat authorised-but-deceived payments differently from theft, so coverage is far from guaranteed.
How the engagement runs
- 1
Determine whether a mailbox is actually compromised
Sign-in logs, geography, forwarding and inbox rules, OAuth app grants. Attackers commonly create a rule hiding replies from the real supplier so the conversation continues undetected.
- 2
Lock down the accounts
Rotate credentials, revoke sessions and app passwords, remove malicious rules, and enforce multi-factor authentication on every mailbox — not just the executives.
- 3
Fix email authentication
SPF, DKIM and DMARC configured and enforced, so impersonating your domain becomes materially harder and attempts become visible to you.
- 4
Put a payment control in place
Out-of-band verification for any change of banking details, using a phone number you already had on file — never one supplied in the email requesting the change.
- 5
Train the people who pay invoices
Short, specific, and aimed at the handful of staff who actually move money. Generic annual training does not change behaviour; a concrete rule does.
The attack that antivirus cannot see
There is no malware. There is no attachment. There is a real person, logged into a real mailbox with a valid password, reading your email and waiting for the right moment.
Then a reply arrives inside a thread you have genuinely been having, from an address you genuinely recognise, mentioning an invoice that genuinely exists — with updated banking details.
Nothing looks wrong because almost nothing is wrong, technically speaking.
Why it is usually the supplier’s problem first
Frequently the compromised mailbox is not yours. Your supplier gets breached, and the attacker uses their account to redirect payments from all their customers. You receive a genuine email from a genuine account, and there is nothing in the headers to catch.
Which is exactly why the control cannot be technical alone. It has to be procedural: banking details never change on the strength of an email. Confirmed by phone, on a number you had beforehand.
What we fix
Whether a mailbox of yours is currently compromised, with evidence rather than reassurance. Multi-factor everywhere. SPF, DKIM and DMARC configured so impersonating your domain is harder and attempts become visible. And a written payment-verification rule the finance team can actually follow.
The technical work takes days. The procedural rule takes one meeting and prevents most of the loss.
What you get
- A determination of whether any mailbox was compromised, with evidence
- Malicious forwarding and inbox rules removed
- Multi-factor authentication enforced across all mailboxes
- SPF, DKIM and DMARC configured and monitored
- A written payment-verification procedure for banking changes
- Targeted briefing for finance staff
Frequently asked questions
How does this attack actually work?
Usually an attacker gets into one mailbox — often through a reused password with no multi-factor — and then simply reads. They learn your suppliers, your tone, your payment cycle. Then they reply inside a genuine thread at a plausible moment with new banking details. Nothing about the message looks wrong, because almost nothing about it is fake.
Our antivirus did not flag anything. Why not?
Because there is no malware to flag. The attacker is using a legitimate login and sending ordinary email. Endpoint security has nothing to detect. The controls that work here are authentication, mailbox monitoring and a payment process that does not rely on email.
Can we get the money back?
Sometimes, if you move within hours. Contact your bank immediately and ask them to initiate a recall, then report it to police. Past roughly 24 to 48 hours, recovery becomes unlikely because the funds have been moved onward through intermediary accounts.
What single control helps most?
Out-of-band verification for any change of banking details. Any such request gets confirmed by phone, on a number you already held before the request arrived. This one rule defeats the overwhelming majority of invoice fraud, and it costs nothing.
Do we need multi-factor on every mailbox?
Yes. Attackers do not target the CEO's mailbox first — they target whichever account is easiest, then pivot. An unprotected reception or accounts-payable mailbox is a perfectly good vantage point for learning how your company pays its bills.
Services involved
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
Learn moreInfrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.