The short answer
Never change payment details based on an email. Call the vendor or closing agent on a number you already had and confirm the account out loud. If a payment has already gone, call your bank's fraud line for a wire recall immediately and file at ic3.gov the same hour.
What does invoice and email compromise fraud look like?
It looks like business as usual. An invoice arrives from a supplier you actually use, for work that was actually done, in the format you always receive. The only difference is a line saying the banking details have changed, or an attached remittance form with a new account number. Everything else is authentic, because the document usually is.
The version that hits individuals is a home closing. You are expecting wiring instructions, they arrive from an address that looks like the title company or the attorney, and the amount matches your paperwork. The instructions come with a warning about fraud, which reads as diligence and is often part of the message.
Behind it sits access to someone's email — yours, your vendor's, or a third party in the thread. That access is why the message knows the project name, the invoice number, and the tone of the previous emails. This is not a stranger guessing; it is someone who has been reading the conversation.
Why does it get past careful people?
Because none of the usual checks apply. There is no misspelled company name, no implausible story, no stranger asking for a favor. The relationship is real, the debt is real, and the request is one that happens legitimately in ordinary business.
The pressure is also structural rather than theatrical. Closings have dates. Suppliers stop shipping. An accounts payable clerk who delays a payment to make a phone call is creating friction that the organization is not set up to reward. Fraud crews time the request for the busiest possible moment for exactly that reason.
Authority does the rest of the work. A second common form is a message that appears to come from an owner or a senior manager, asking a junior employee to handle something quickly and discreetly. Nobody in that position wants to be the person who questioned the boss over a payment, and the request is built to exploit exactly that reluctance.
The last piece is the reply channel. Messages are sent from an address that differs by a character, or from the genuine account with a mailbox rule quietly moving replies out of sight. Answering the email confirms with the person who sent it, which is no confirmation at all.
How do you verify payment details safely?
One rule stops nearly all of it: no payment detail ever changes on the strength of a message. Confirmation comes by voice, on a number you already held, before the money moves. Build it into the process so it does not depend on someone feeling suspicious.
- Call the vendor, title company, or closing attorney on the number from your existing records — a signed contract, a previous statement, or your own contact list.
- Read the account number and routing number aloud and have them read back, rather than asking "is this right?"
- Never use a phone number, link, or address contained in the message requesting the change.
- Require two people to approve any change to banking details, and any payment above a set threshold.
- Send a small test transfer first where the timeline allows it, and confirm receipt by phone.
- Treat urgency and secrecy as reasons to slow down, not to hurry.
If the account is compromised or the address is a near-match, your verification message reaches the same person who sent the instructions. They will confirm enthusiastically. Voice contact on a number you already had is the only check that works.
What do you do in the hours after a payment goes out?
Everything worth doing happens fast. A wire can sometimes be pulled back while the funds are still sitting in the receiving account, and almost never after they move. Call your bank's fraud department before you call anyone else, ask for a wire recall in those words, and get a case reference. The full sequence is in the answer on the first hours after a fraudulent wire.
Then file at ic3.gov the same hour. Complaints filed quickly, with the receiving bank details and the transfer reference, are the ones that can support a request that the receiving institution freeze the balance. A complaint filed a week later becomes data rather than a rescue.
Notify the insurer at the same time. Policies that cover this kind of loss commonly require prompt notice, and a delay while you try to sort it out privately is a standard reason claims are refused. Tell the broker what happened in writing on the first day, even before you know the full amount or how the access occurred.
In parallel, secure the mailbox. Change the password, turn on multifactor authentication, review forwarding rules and filters, and check sign-in history for unfamiliar locations. Do not delete anything. Then tell the counterparty by phone, because they may be compromised, and other customers of theirs may be receiving the same instructions right now.
What payment protections actually apply?
Less than most business owners expect. The consumer rules that require banks to investigate and re-credit unauthorized electronic transfers apply to personal accounts, not to commercial ones. Business accounts operate under the account agreement and the commercial rules for funds transfers, and those generally place the loss on the party that authorized the payment.
| Payment route | Who typically bears a loss | Practical lever |
|---|---|---|
| Business wire | The sending business | Speed of the recall request; security procedures in the account agreement |
| Consumer wire | The consumer who sent it | Recall request, then a complaint about the bank's handling |
| ACH credit | The originator | Reversal is limited and time-bound; ask the bank immediately |
| Business check | Split, depending on alteration | Positive pay and prompt statement review |
| Card payment | Often the merchant or issuer | Chargeback rights, which is why card is safer for small purchases |
Home buyers sit in an uncomfortable middle. The account is personal, so consumer rules may apply to parts of the transaction, but a wire you sent yourself is still a wire you authorized. Closing agents increasingly confirm instructions by phone before funds move, and a buyer can insist on that call regardless of what the schedule says.
Because the loss usually stays where it landed, the return on prevention is unusually high here. So is the return on early legal advice when the amount is large: an attorney can send preservation demands to the receiving bank, seek an order identifying the account holder, and press for a freeze while there is still a balance. The wider comparison of reversal odds sits in the answer on which payments can be reversed.
How do you make it hard to happen again?
Fix the process rather than the person. Every one of these losses passes through a step where a single individual could act alone under time pressure, and that is the step to change. Written rules also matter after the fact, because insurers and banks ask what controls existed.
- Multifactor authentication on every email account, without exception for executives.
- A standing rule that banking details change only after voice verification on a stored number.
- Dual approval for new payees and for payments over a threshold you set.
- Vendor bank details stored in your accounting system and changed only by a named person.
- Regular review of mailbox forwarding rules across the organization.
- A short written incident plan naming who calls the bank, who calls the vendor, and who files at ic3.gov.
Tell staff explicitly that stopping to verify is welcome, including when the request appears to come from an owner. Fraud crews impersonate authority precisely because juniors do not challenge it, the same dynamic used in the answer on calls claiming to come from a government agency. A culture where a verification call is expected costs almost nothing and removes the mechanism the whole scheme depends on. Where the money is already gone, the reporting map in the answer on which agency does what shows where each part of the report belongs.
What to remember
- The fraud is not a fake company; it is a real invoice with the bank details replaced, which is why it survives scrutiny.
- Verification means a call to a number you already had on file, never a number or address supplied in the message itself.
- Business accounts do not carry the consumer error-resolution rights that apply to personal accounts.
- Home closings are targeted heavily because the amount is large and the wiring instructions arrive by email.
- A mailbox rule that hides replies is often how the compromise stays invisible for weeks, so check the rules after any incident.
Other questions people ask
Who bears the loss when a vendor's invoice was altered in transit?
It is usually disputed. The vendor says it was not paid; the payer says it paid the invoice it received. The answer turns on where the compromise happened, what each party's contract says, and which side ignored a warning sign. Expect the vendor to still demand payment, and expect the argument to be about allocation rather than about whether a loss occurred.
Does cyber insurance usually cover this?
Sometimes, and often under a specific social engineering or funds transfer fraud endorsement rather than the main cyber coverage. Many policies exclude losses where an employee authorized the transfer unless that endorsement was purchased. Report the incident to the insurer promptly, because late notice is a common reason claims are denied.
Should the compromised mailbox be deleted?
No. Preserve it. The mail logs, forwarding rules, and sign-in records are the evidence that shows when access began and what was read, and investigators, insurers, and the other party in the dispute will all want it. Secure the account with a password change and multifactor authentication instead of destroying the history.
Where this comes from
- FBI Internet Crime Complaint Center (IC3)Complaint route for business email compromise and possible freeze requests.
- FBI — Scams and SafetyDescriptions of business email compromise patterns.
- FTC — Report FraudFederal reporting portal, including for small businesses.
- FTC — Business GuidanceSecurity and payment practices for small organizations.
- Cybersecurity and Infrastructure Security Agency (CISA)Federal guidance on email account security and multifactor authentication.
- Consumer Financial Protection Bureau — Submit a ComplaintFor consumer account disputes with a bank.
Clear Justice is a publication, not a law firm. Reading this creates no attorney–client relationship, and nothing here is advice about your situation. Rules change and many of them differ by state — check the official source above or speak to a licensed attorney before you act.