How the perfect fake invoice happens
The most expensive email a small business ever receives usually looks completely normal. Business email compromise works like this: a criminal gets into an email account — yours, or more often a vendor's — and reads quietly for weeks. They learn who invoices whom, for how much, in what format, with what signature.
Then, at the right moment, they act. Sometimes they reply inside a genuine existing invoice thread from the vendor's real hacked mailbox, attaching the real invoice with one change: the bank account number. Sometimes they register a look-alike domain, one letter off, and continue the conversation from there. The invoice is real. The project is real. The amount is right. Only the destination of the money is wrong.
Why your eyes cannot catch it
Owners tell me they would spot a scam, and with old-style scams they are right. This is different, because everything you would check checks out. The sender knows the project details. The thread history is genuine. The tone matches, because the criminal has read months of this person's writing. There is no misspelled urgency, no gift cards — just a routine note that the firm has changed banks and future payments should go to the new account.
The uncomfortable conclusion is that no amount of squinting at an email can verify where money should go, because the email channel itself is what got compromised. Verification has to leave that channel entirely. That is the whole trick, and it fits in one sentence: confirm by phone, on a number you already had.
The call-back rule, written down
Here is the rule to adopt, word for word if you like: any request to change payment details, and any first payment to a new payee, is confirmed by a phone call to a number we already have on file — never a number from the email or the invoice itself.
The last clause is the one people miss. Criminals expect call-backs, so the fraudulent invoice helpfully includes a phone number, and someone at the other end will cheerfully confirm the new account. Your protection is calling the number from your existing contact record, a past contract, or the vendor's official website that you typed in yourself.
The call takes two minutes. Read back the account number and ask the person you know to confirm it. Write the rule down, put it in your payment procedure, and tell every vendor at the start of a relationship that you work this way — real vendors are glad to hear it.
Dual approval for new payees and changed details
The call-back rule needs a partner: no single person should be able to send money to a new destination alone. Dual approval means one person sets up a payment and a different person approves it, and it applies to new payees and to any change in an existing payee's details.
In practice this is a checkbox in most bank and accounting platforms — dual control, or two-to-approve — and it costs nothing. In a company of five, the second approver can be you. The point is not distrust of your bookkeeper; it is that the fraud now has to fool two people on two channels, and the second person is looking at the payment cold, without the persuasive email thread in front of them. Pair the two controls and you have closed the path that the large majority of these losses travel down.
The first hour after a wrong transfer
If money has already gone to a fraudulent account, speed matters more than anything else you do.
- Call your bank immediately and ask for a wire fraud recall. Banks can sometimes freeze or claw back funds if the money has not moved on, and the odds fall by the hour.
- File a complaint at ic3.gov, the FBI internet crime center. For larger transfers, their recovery process has pulled money back when notified fast.
- Call the real vendor on a known number so both companies can figure out whose mailbox is compromised.
- Preserve everything — the emails, headers, invoices. Do not delete or tidy.
- Change passwords and revoke active sessions on the email accounts involved, because the criminal is often still reading.
Every hour of delay costs recovery odds, so this list belongs printed near whoever pays the bills.
Put this in place this week
- Write the call-back rule into your payment procedure today — it is one sentence, and a printed copy near accounts payable counts.
- Turn on dual approval for new payees and detail changes in your bank and accounting platform.
- Build a verified phone list for every vendor you pay regularly, from records you already trust, not from recent emails.
- Brief whoever pays bills, and make it safe to be slow: nobody ever gets in trouble here for delaying a payment to verify it.
- Run one drill: send a fake change-of-bank email internally and see what happens.
This is the highest-return security work I know of — two free controls against the most expensive scam in small business. At HashWhales we walk DMV clients through this exact setup, but you can genuinely do the whole thing yourself before Friday.
