What changes in an invoice scam?
The aim is to send money intended for a real business partner to a different account. An attacker may imitate a supplier or introduce altered details into an existing conversation. An invoice can therefore list the correct goods, amount and deadline alongside the wrong payment account.
This lesson concerns cyber fraud affecting overseas invoice payments. The same payment diversion mechanism can also affect domestic business partners.
An account change needs checking
A new account, an unexpected change of instructions and pressure over a supposedly delayed shipment require extra attention. None proves fraud on its own. The practical consequence is the same: pause execution until you have verified the change.
Do not check only the logo, signature or invoice format. Compare the instruction with the partner’s previously approved details and establish exactly what changed.
Keep confirmation separate from the suspicious message
- Find the supplier’s contact in previously verified records, not in an amended signature or new attachment.
- Use that channel to confirm that the supplier really requested an account change and check the details for the particular payment.
- Record the check and obtain approval under your internal procedure before updating details and paying.
- If the contact is unavailable or confirmation is unclear, keep the payment on hold and involve the responsible person in your organisation.
A reply in the same email conversation is not independent confirmation if the account has been compromised. Our business email compromise guide explains how an attacker can misuse a genuine business account.
If the payment has already been sent
Contact the bank that made the payment immediately. Have the amount, currency, time, transaction reference and recipient details from the instruction ready. Explain that you suspect payment diversion and follow the bank’s guidance. Stopping or recovering the money cannot be promised in advance.
Notify the responsible internal team and the real business partner through a verified channel. Preserve the original correspondence and both document versions, if available. Do not remove evidence or send an additional payment as a “test”.
When reporting the related cyber incident to FIN-CSIRT, include the steps you have already taken. That report does not replace urgent contact with the bank and your internal procedure.