An invoice can look routine and still be dangerous. A familiar supplier name, a real project reference, a correct amount, and a polished PDF do not prove that the payment details are safe. Business email compromise works because attackers often imitate normal business conversations rather than sending obvious spam.
The FBI describes business email compromise as a financially damaging online crime that abuses trust in email. IC3 reporting has tracked losses across every U.S. state and many countries, and the pattern is not limited to large companies. Freelancers, landlords, nonprofits, schools, professional services firms, online sellers, and families making major payments can all be targeted.
The safest approach is simple: treat payment details as something to verify independently, not something to accept because an email says so.
The Problem
Invoice fraud usually succeeds at the handoff between communication and payment. A criminal may compromise a supplier’s email account, create a lookalike domain, join an existing email thread, send a fake invoice, or announce that bank details have changed. The request may be calm and professional, or it may create pressure with words such as urgent, overdue, confidential, final notice, or today only.
This is why normal spam awareness is not enough. Some fraudulent requests contain no suspicious link, no malware attachment, and no spelling mistakes. The risk sits in the instruction: send money to this account, update this vendor profile, pay this invoice, change this payroll route, or release funds before the usual approver is available.
Verification gives you a pause point before the money moves.
Step 1: Match the Invoice to a Real Obligation
Start with the basic business question: do you actually owe this money?
Match the invoice to a purchase order, signed quote, contract, delivery note, subscription record, lease, service agreement, or written approval. Check the supplier name, invoice number, date, amount, tax treatment, currency, bank country, due date, and description of work. If the invoice refers to a project no one recognizes, stop.
For a small team, the matching evidence may be simple: an email approval from the owner, a completed job ticket, a delivery receipt, or a client file. The point is not bureaucracy. The point is to avoid paying a document that only looks official.
If the invoice is unexpected, ask the requester to explain what it covers before discussing payment details.
Step 2: Verify the Sender, Not Just the Display Name
Display names are weak evidence. An inbox may show “Accounts Team” or a supplier’s name while hiding the actual address. Open the full sender details and compare the domain character by character. Watch for extra hyphens, swapped letters, unusual country domains, free email accounts, and addresses that are close to the real one but not identical.
Also check the reply-to address. A message may appear to come from one account while replies go somewhere else.
If the email continues an old thread, remain cautious. Attackers can use compromised inboxes or stolen thread content to make a request look legitimate. A real conversation history does not automatically validate a new bank account.
Step 3: Confirm Bank Details Through a Separate Channel
Any new bank account, changed routing number, different payment app, new wallet address, or altered beneficiary name deserves independent confirmation. Do not verify by replying to the same email thread. Do not use the phone number printed on the suspicious invoice. Do not trust a new contact card attached to the message.
Use a contact method you already had before the change request arrived: a saved vendor phone number, a number from the signed contract, a verified supplier portal, a known account manager, or the organization’s official website. If possible, call and read back only the last few digits of the account details rather than sending the full details over email.
For higher-value payments, require two confirmations: one from the person requesting the change and one from someone else at the supplier or inside your organization.
Step 4: Separate Vendor Setup From Payment Release
A good payment process has two decisions, not one. First, someone approves or updates the vendor record. Second, someone releases the payment. If the same person can receive a bank-change email, update the supplier, and send the transfer alone, the process has no meaningful brake.
Small businesses can still build separation without expensive software. One person can enter the details, and another can review the invoice, proof of work, confirmation notes, and payee information before release. For sole proprietors, the separation can be time-based: save the payment as a draft, step away, and recheck the invoice against verified records before approving it.
Never let urgency become the reason to skip the only control that would have caught the fraud.
Step 5: Keep a Verification Trail
Document the checks before payment. Save the invoice, approval, purchase reference, confirmation date, verified contact method, name of the person who confirmed the details, and the person who released the funds. This record helps if a dispute, audit, insurance claim, bank recall, or law-enforcement report becomes necessary.
The trail does not need to be complicated. A note in accounting software, a shared spreadsheet, a ticket, or a PDF stored with the invoice can work. What matters is that someone can later see why the payment was considered legitimate.
For recurring suppliers, record the approved bank details in one controlled place. Staff should compare new invoices against that record rather than treating each email as a fresh source of truth.
Best Practices
Use multi-factor authentication on email and accounting systems, especially for accounts that can approve invoices or change supplier records.
Limit who can edit vendor bank details.
Require a call-back for every payment-detail change.
Use saved contacts or official websites, not contact details supplied inside the payment request.
Set value thresholds. A small office-supply invoice may need one approval; a large transfer should need more.
Review mailbox rules and forwarding if you suspect an email account was compromised.
Train staff to slow down when a request combines payment, secrecy, pressure, and changed details.
Common Mistakes
The first mistake is trusting a familiar thread. If a supplier’s inbox is compromised, the attacker may reply inside a real conversation.
The second mistake is verifying by email. If the email channel is the problem, staying inside that channel does not solve it.
The third mistake is treating a PDF as proof. A professional invoice template is easy to create.
The fourth mistake is assuming small payments are safe. Criminals may test a process with a smaller amount before attempting a larger transfer.
The fifth mistake is waiting too long after a suspected fraud. If money was sent to the wrong account, contact the bank immediately and report the incident quickly. Recovery chances drop as funds move.
FAQ
Should every invoice require a phone call?
Not every routine invoice needs a call if the supplier, amount, bank details, and approval path are unchanged. But every new supplier, new bank account, payment-route change, unusual amount, rushed request, or unexpected invoice should be verified through a separate channel.
What if the supplier says they cannot take calls?
That is a warning sign when money is involved. Use another verified route, such as an official portal, known account manager, or previously saved number. Do not accept a major bank-detail change from email alone.
Is a payment link safer than a bank transfer?
Only if the link is genuinely from the supplier’s verified system. Open the supplier portal from a bookmark or official website instead of clicking a payment link in an unexpected email.
What should I do after sending money to the wrong account?
Contact your bank immediately, ask about recall or fraud procedures, preserve the emails and invoice, change compromised passwords if needed, and report the incident through the appropriate fraud-reporting channel in your country.
Summary
Invoice payment safety is mostly a process problem. The strongest habit is independent verification before payment details change. Match the invoice to a real obligation, inspect the sender, confirm bank details through a trusted channel, separate setup from release, and keep a record of the checks.
That short pause can prevent a routine invoice from becoming an expensive loss.


