Phishing aims to steal credentials or money through deception — usually by email pretending to be from a trusted source: the bank, a supplier, sometimes even your own boss. Invoice fraud is a particularly effective variant, because it goes straight for the goal: getting money wired to the wrong account.

The classic: the "changed" bank details

A common pattern: a known supplier (supposedly) writes that their bank details have changed, often with a convincing-looking signature and a deceptively similar email address. The next regular invoice then actually gets paid to the new, fraudulent account — until the real supplier gets in touch because the payment never arrived.

How to spot a fake email

The most reliable protection: a second channel

The single most effective measure is remarkably simple: for any change in bank details or unusually large payments, make a quick phone call to confirm with the sender — using a number you already know, not the one given in the suspicious email. It costs five minutes and stops almost every one of these fraud attempts.

Why this can happen to anyone

Phishing emails are getting increasingly professional and are sometimes tailored to specific companies (spear phishing) — often based on information sitting right there on your own website or social media. Vigilance is therefore not a matter of company size, but a matter of habit within the team.

A quick confirmation call costs five minutes. A wrong transfer is usually gone for good.

Prepare your team for the real thing

Whether technical safeguards (spam filtering, SPF/DKIM/DMARC for your own domain) or a short team briefing — both are straightforward to put in place.

Get in touch