How the scam runs
The attacker learns who your suppliers are — often from a compromised mailbox somewhere in the chain — and sends an invoice that matches your real billing cycle. The only difference is the bank account. Nothing is technically hacked on your side; the message simply looks routine.
The tell-tale signs
- A supplier's bank details 'have changed' — the single most reliable red flag
- Urgency or a threatened service cut-off on an otherwise normal invoice
- A reply-to address that differs subtly from the sender address
- An attachment or link where that supplier normally sends plain text
- An amount close to, but not exactly, your usual figure
The two-step process that stops it
First, no bank detail change is ever actioned from an email. Second, any change is confirmed by calling the supplier on a number you already hold — never a number contained in the message. Write both rules into your payments procedure so a junior member of staff is never the one making the judgement call.