Most people picture payment fraud as an email from a stranger with an obvious typo. The more dangerous version comes from a real supplier's real email account. The attacker has broken into the vendor's mailbox, read their conversations with you, and sends a convincing invoice, or a bank change notice, in the middle of an actual thread. The message passes spam filters, uses the correct address, and refers to a real project.
Because the sender really is your supplier's account, the usual advice to check the sender address is not enough. This article describes what to examine instead and the procedures that protect you even when the email itself looks perfect.
How These Attacks Unfold
The attacker takes over a vendor's email account, often through a phishing page or a reused password. They watch for conversations about invoices and payments. At the right moment, they insert themselves, sometimes creating hidden rules that move your replies out of sight, and send updated payment instructions or an altered invoice. If you pay, the money goes to an account they control. The real supplier may not discover it until they ask why they were not paid.
Note that your own company can be the compromised party in the same pattern, which is why protecting your mailboxes matters for your customers too.
Warning Signs on the Invoice or Message
None of these proves fraud alone, but together they justify a closer look.
- A new bank or a change of payment method. This is the strongest warning sign, especially a change to an account at a different bank or in a different name.
- An account name that does not match the vendor. The payee should match the legal name on your vendor record.
- Urgency or pressure, such as claims of an audit, a closing account, or late fees.
- Different formatting from earlier invoices, such as new fonts, layouts, or numbering.
- Unusual wording or a slightly different tone compared with earlier messages.
- A request to keep the change confidential or to avoid calling.
- Reluctance to take a call, or a suggestion to use a different number.
- Invoices for work you did not order or that do not match purchase orders.
Checks That Work Even When Email Is Compromised
Verify out of band
Call the supplier using a phone number already in your records, from a previous contract or your vendor file, not one in the suspect email. Speak to a person you know. Ask them to confirm the specific change and the account details.
Match against your own records
Compare the invoice to the purchase order, subcontract, pay application, or delivery receipt. Confirm amounts, dates, and references. An invoice with no matching commitment deserves scrutiny.
Require independent approval
Banking changes should require approval by someone other than the person who received the request. Document the verification steps in the vendor file.
Watch for delay tactics
Use a short hold on the first payment to new instructions where practical, and test with a small amount only if your policy allows and the vendor has confirmed by phone. Do not skip verification because the amount seems small.
Look at the details in your payment system
Check that the account name and bank match what is expected. Some banks offer payee verification services that can flag mismatches. Ask yours what is available.
Build Habits Into the Process
- Keep a central list of vendor contacts and phone numbers, maintained by finance, not by email.
- Keep vendor master data changes in one controlled workflow with logging.
- Train project managers to forward any payment-related request to accounts payable rather than acting on it.
- Encourage staff to question unusual requests, and thank them when they do.
- Reconcile payments regularly and watch for vendors reporting nonpayment.
If You Suspect a Problem
Act quickly. Stop any pending payment, contact the supplier by a trusted number, and notify your bank immediately if money has been sent, since early contact can improve the chance of recovery. Preserve the emails, report to the FBI's Internet Crime Complaint Center, and inform your insurer. Alert the supplier so they can secure their account and warn other customers.
Protect Your Side Too
Enable multi-factor authentication on your mailboxes, watch for suspicious inbox rules, and brief your team. A compromised account at your company can send fake requests to your customers.
A Final Word
The best defense is a process that does not depend on trusting email. Ironfield Cyber can help review your vendor payment workflow, set up mailbox protections, and train finance and project teams to spot these cases before money moves.