← Writing

The invoice that changed your vendor's bank account

Picture a retail shop that has used the same supplier for three years. Every month, an invoice arrives by email, the bookkeeper pays it, everyone moves on. One Tuesday morning, an email arrives from the supplier with the usual invoice attached. At the bottom, in red text, a note: "Please note our bank details have changed effective immediately. Use the account information below for all future payments." New routing number, new account number, same supplier name. The bookkeeper updates the payment system and sends the wire. Two weeks later, the supplier calls asking where the payment is. The money went to a criminal. The email was not from the supplier.

That is business email compromise in its most common form. No malware, no obvious phishing link, just an email that looks legitimate and asks you to send money somewhere new. The email address may be spoofed, or it may come from a lookalike domain registered to impersonate the vendor. The invoice attachment is often a copy of a real invoice with the bank details altered. The tone is professional. The timing makes sense. There is nothing in the email itself that screams fraud, and that is the problem. An email is not proof of identity.

Why the email proves nothing

Email was not designed to verify sender identity. The "From" field in an email can say anything. If the sender's domain has weak or missing SPF, DKIM, and DMARC records, the email may land in your inbox even though it did not originate from the vendor's actual mail server. Even if those records are in place, an attacker can register a domain that looks similar (vendorr.com instead of vendor.com) and send mail that passes all the technical checks because it really did come from the domain in the From line. Your email client shows you "Vendor Supply Co." and you see what you expect to see.

The other version is a compromised email account. The attacker gains access to the vendor's actual email account, watches the message flow for a few weeks to learn the invoicing pattern, then sends a message from the real account at the right time. That email passes every technical test because it is coming from the legitimate account. The domain is correct, the sender history is there, and the message sits in the same thread as previous invoices. The only thing different is the bank account.

The phone call rule

The fix is simple and not technical. Any request to change payment details requires a phone call to verify, using a number you already have on file, not a number in the email. Call the main line for the vendor, ask for accounts receivable, and confirm the change. If the email was legitimate, the person on the phone will confirm it. If the email was fraudulent, the person on the phone will have no idea what you are talking about, and you just avoided sending money to a criminal.

This rule applies to any payment destination change: bank account, wire instructions, mailing address for checks, payment portal login. It also applies to invoices that arrive unexpectedly or that differ in format from previous invoices. If something feels off, make the call. The two minutes spent on the phone are cheaper than the hours spent trying to recover funds after a fraudulent transfer.

The same rule applies in reverse. If you need to change your own bank details and notify your customers, expect them to call and verify. Put a note on your website with a phone number they can use to confirm. Do not be offended when someone calls to check. That is the correct response.

What to do in the first hour

If you realize money has already gone out to the wrong account, speed matters. Contact your bank immediately and report the fraudulent transfer. If the transfer was a wire, ask the bank to issue a recall notice. Wires are not reversible in the same way ACH payments are, but a recall request asks the receiving bank to return the funds. Success is not guaranteed, especially if the receiving account has already been emptied, but the request needs to happen within hours, not days.

File a report with local law enforcement and with the FBI's Internet Crime Complaint Center at ic3.gov. Forward the fraudulent email with full headers to the FBI and to your email provider. If the email came from a lookalike domain, report that domain to the registrar. None of this will get your money back quickly, but it creates a paper trail and sometimes helps with insurance claims.

Contact the vendor whose identity was used and let them know their name is being used in a business email compromise scheme. They may not be aware, and they need to warn other customers.

Where this sits

Business email compromise is not a hosting problem or a server configuration problem. It is a process problem. Technical controls like DMARC help, but they do not stop lookalike domains or compromised accounts. The solution is procedural: verify payment changes with a phone call, every time. For clients on a Care plan, I include a quarterly review of payment workflows and email authentication settings, but the phone call rule is something every business can implement today, with no outside help required.


Need this kind of thinking applied to your own setup? Get in touch →