This one costs small businesses more than most malware, and there is nothing technical to detect. A supplier emails to say their bank details have changed. The invoice is real, the amount is right, the sender looks correct. The account number belongs to someone else.
The FBI's Internet Crime Complaint Center logged $3.04 billion in reported business email compromise losses in its 2025 Internet Crime Report — from under 25,000 complaints, which works out to roughly $123,000 per incident. That average is not made of big corporations. It is made of businesses like yours paying one wrong invoice.
How the scam actually works
Usually the attacker has been reading email for weeks — either your supplier's mailbox or yours, opened with a password taken in an earlier phishing email. They know who invoices you, for how much, and when. They wait for a genuine invoice and then step in at exactly the right moment, in the right tone, referencing the right project.
The email itself arrives one of three ways:
- A lookalike domain. acme-supply.com becomes acrne-supply.com or acme-supply.co — registered that morning for a few dollars. Your eye reads the name it expects to see, which is the entire trick.
- A hijacked reply chain. The message lands as a reply inside a genuine thread, quoting real earlier messages, because the thread was stolen along with the mailbox. Nothing about it reads like a cold approach, because it is not one.
- The genuine account. Sometimes it comes from the supplier's real mailbox, because that mailbox is compromised — in which case every technical check passes, because nothing is being faked.
That last point is why security software sits this one out. There is no malware and often no link — just a clean PDF and a new routing number.
The one control that stops it
Any change to bank details gets verified by phone, on a number you already had. Not the number in the email. Not the number in the signature. The number in your records, or on the original contract.
That is the whole defense, and it works because it moves verification off the channel the attacker controls. Everything else is secondary to it.
Make it written policy, not habit. Tell everyone who can send a payment, and allow no exceptions — not for your biggest vendor, not for the owner, not for anything marked urgent. Attackers probe for exceptions the way water probes for cracks.
When a vendor announces new bank details
- Stop the payment. Nothing goes to the new account until verification is done, whatever deadline the email claims.
- Call a number you already had — from your records or the vendor's website typed by hand. Never the one in the email, and never one helpfully supplied in the signature.
- Reach a person you know and read the new account number back to them. If they know nothing about a change, you have just caught the fraud — and probably discovered their email is compromised, so tell them that too.
- Note who verified it, when, and on which number. Thirty seconds of record-keeping, and the next person in the job inherits a routine instead of a habit.
- Treat the first payment as a test. Send a small amount, confirm by phone that it arrived, then release the balance.
Run the same five steps for a brand-new vendor's first invoice. "New supplier" and "changed details" are the same trick in different clothes.
Controls that cost nothing
- Two people for payments above a threshold you choose. Fraud relies on one person acting alone under time pressure.
- Treat urgency as suspicious in itself. "Before end of day" is a technique, not a business requirement.
- Be skeptical of a request that avoids the phone. "I'm in meetings all day, just email me" is a line, not a schedule.
- Turn on two-factor authentication for every mailbox. Most of these frauds start with an inbox somebody else can read.
- Check mailboxes for forwarding rules every quarter. Attackers add a rule that quietly copies invoices out to themselves, and it survives a password change.
All of it fits on one page, and none of it needs new software. The wider version — patching, backups, offboarding — is in the small business cybersecurity checklist, but these five lines are the ones that keep the money in the account.
If the money has already gone
Speed decides most of what follows. A wire can be forwarded out of the destination account within hours, and once it hops through a second bank the odds fall fast. ACH settles more slowly, which sometimes buys you a day — sometimes.
- Call your bank's fraud department immediately — the moment the payment looks wrong, not after a meeting about it. Ask them to attempt a recall and to contact the receiving bank to freeze the account.
- File a complaint at ic3.gov the same day. For international wires of $50,000 or more reported within 72 hours, the FBI's Recovery Asset Team can trigger its Financial Fraud Kill Chain and ask banks to freeze the money before it moves on. In 2025 that team froze $679 million and succeeded in 58% of the incidents it took on, per the same FBI report. Smaller and domestic cases don't qualify for the kill chain, but file anyway — the same team helps banks freeze domestic transfers, and the report feeds the pattern that catches mule accounts.
- Tell the real supplier by phone. If their mailbox is the compromised one, you are not the only customer being invoiced from it this month.
- Have both mailboxes checked. Look for forwarding rules, unfamiliar sign-ins and connected apps; if yours was the one broken into, work through the first-hour steps for a hacked email account. A technician on Koadi can sweep a mailbox for rogue rules over a screen-share in under an hour.
- Keep everything. The original email with full headers, the invoice, the payment record. Your bank, your insurer and the FBI will all ask for them.
Putting the defenses in place without becoming an IT person
Two-factor on every mailbox, forwarding-rule audits, a payment policy people will actually follow — a technician who does this weekly can set it all up in a morning. Post the job free at Koadi in plain words, and vetted, identity-verified technicians will pick it up. You set a fixed price or take bids, and payment sits in escrow until you approve the work. Remote help covers every US state, evenings and weekends included; on-site visits are available through local technicians. If money has already moved, post it now and say so — the first hours are the ones that count.