Skip to content
Digital Security Consulting

Controller or finance manager

“Accounting nearly paid an invoice that turned out to be fake”

Request a consultation Typical timeline: Mailbox audit within days, controls in the same engagement

Does this sound familiar?

  • A supplier emailed new banking details that turned out not to be theirs
  • An urgent payment request appeared to come from the owner or CEO
  • Staff received replies inside a real email thread they had been having
  • Someone noticed a mailbox rule nobody created
  • A payment went out and the real supplier is still chasing the invoice

What it costs to ignore

Business email compromise costs organisations more than ransomware does, and it rarely involves malware — so antivirus never sees it. Wire transfers are often unrecoverable after 24 to 48 hours. Insurers frequently treat authorised-but-deceived payments differently from theft, so coverage is far from guaranteed.

How the engagement runs

  1. 1

    Determine whether a mailbox is actually compromised

    Sign-in logs, geography, forwarding and inbox rules, OAuth app grants. Attackers commonly create a rule hiding replies from the real supplier so the conversation continues undetected.

  2. 2

    Lock down the accounts

    Rotate credentials, revoke sessions and app passwords, remove malicious rules, and enforce multi-factor authentication on every mailbox — not just the executives.

  3. 3

    Fix email authentication

    SPF, DKIM and DMARC configured and enforced, so impersonating your domain becomes materially harder and attempts become visible to you.

  4. 4

    Put a payment control in place

    Out-of-band verification for any change of banking details, using a phone number you already had on file — never one supplied in the email requesting the change.

  5. 5

    Train the people who pay invoices

    Short, specific, and aimed at the handful of staff who actually move money. Generic annual training does not change behaviour; a concrete rule does.

The attack that antivirus cannot see

There is no malware. There is no attachment. There is a real person, logged into a real mailbox with a valid password, reading your email and waiting for the right moment.

Then a reply arrives inside a thread you have genuinely been having, from an address you genuinely recognise, mentioning an invoice that genuinely exists — with updated banking details.

Nothing looks wrong because almost nothing is wrong, technically speaking.

Why it is usually the supplier’s problem first

Frequently the compromised mailbox is not yours. Your supplier gets breached, and the attacker uses their account to redirect payments from all their customers. You receive a genuine email from a genuine account, and there is nothing in the headers to catch.

Which is exactly why the control cannot be technical alone. It has to be procedural: banking details never change on the strength of an email. Confirmed by phone, on a number you had beforehand.

What we fix

Whether a mailbox of yours is currently compromised, with evidence rather than reassurance. Multi-factor everywhere. SPF, DKIM and DMARC configured so impersonating your domain is harder and attempts become visible. And a written payment-verification rule the finance team can actually follow.

The technical work takes days. The procedural rule takes one meeting and prevents most of the loss.

What you get

  • A determination of whether any mailbox was compromised, with evidence
  • Malicious forwarding and inbox rules removed
  • Multi-factor authentication enforced across all mailboxes
  • SPF, DKIM and DMARC configured and monitored
  • A written payment-verification procedure for banking changes
  • Targeted briefing for finance staff

Frequently asked questions

How does this attack actually work?

Usually an attacker gets into one mailbox — often through a reused password with no multi-factor — and then simply reads. They learn your suppliers, your tone, your payment cycle. Then they reply inside a genuine thread at a plausible moment with new banking details. Nothing about the message looks wrong, because almost nothing about it is fake.

Our antivirus did not flag anything. Why not?

Because there is no malware to flag. The attacker is using a legitimate login and sending ordinary email. Endpoint security has nothing to detect. The controls that work here are authentication, mailbox monitoring and a payment process that does not rely on email.

Can we get the money back?

Sometimes, if you move within hours. Contact your bank immediately and ask them to initiate a recall, then report it to police. Past roughly 24 to 48 hours, recovery becomes unlikely because the funds have been moved onward through intermediary accounts.

What single control helps most?

Out-of-band verification for any change of banking details. Any such request gets confirmed by phone, on a number you already held before the request arrived. This one rule defeats the overwhelming majority of invoice fraud, and it costs nothing.

Do we need multi-factor on every mailbox?

Yes. Attackers do not target the CEO's mailbox first — they target whichever account is easiest, then pivot. An unprotected reception or accounts-payable mailbox is a perfectly good vantage point for learning how your company pays its bills.

Services involved

Cybersecurity

Incident response, ransomware recovery, and hardening that holds up under audit.

Learn more

Infrastructure & Backup

Servers, clusters and backups designed so that failure is survivable and boring.

Learn more

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.