Skip to content

The invoice that wasn't: how payment redirection fraud works

No malware, no hacking, just a convincing email and a changed bank account. Payment redirection is the fraud most likely to cost you real money.
Published
Updated
Reading time
4 min
Topic
Threats & Scams
On this page

A supplier you have paid for years sends their usual invoice. Same logo, same layout, same contact name at the bottom. The only difference is a short line partway down: “Please note our banking details have changed.”

Your accounts person updates the payee and pays it. Four weeks later the real supplier asks where their money is.

This is business email compromise, and Australian businesses report losing more to it than to ransomware. It involves no malware, exploits no software flaw, and defeats most technical controls, because from the outside it looks exactly like normal commerce.

How it actually unfolds

The attacker rarely starts with you. They start with whoever has weaker security in your supply chain, often a small supplier or a bookkeeper.

They get into one mailbox, usually through a reused password or a convincing login page. Then they wait. They read months of correspondence, learn who approves what, note the tone people use and the payment cycle. This quiet period is the whole trick: by the time they send anything, they know more about your commercial relationship than most of your staff do.

When a genuine invoice is due, they strike. Sometimes they send a fake from a near-identical domain. Sometimes, worse, they send the real thing from the real mailbox with only the bank details altered.

Why smart people fall for it

Because nothing is wrong with the email. It arrives in an existing thread. It references a real project and a real amount. It comes at the moment you were expecting it.

Every instinct we teach about phishing, check the sender, look for odd wording, beware of urgency, fails here. The sender is legitimate. The wording is normal, because the attacker copied it. There is often no urgency at all, because patience is what makes it work.

The control that stops it

There is one, and it is unglamorous: verify every change to bank details by voice, on a number you already had.

Not the number in the email signature. Not a number in the new invoice. The number in your own records, or one you look up independently. Call the person and ask them to confirm the change.

That single habit defeats the entire fraud, because the attacker controls the email thread and nothing else. Make it a rule that applies without exception, including when the request appears to come from a director, and especially when the amount is large.

The supporting layers

Turn on MFA everywhere, particularly email. Most of these incidents begin with a mailbox someone else can log into.

Publish DMARC properly. It stops criminals sending mail that appears to come from your domain, which protects your customers as much as you. Our guide to SPF, DKIM and DMARC covers how to do it without breaking your legitimate mail.

Flag external mail. A banner marking messages from outside the organisation makes a lookalike domain far more obvious.

Set a second approver above a threshold. Pick an amount that would hurt, and require two people for any new payee above it.

Watch for mailbox rules you did not create. Attackers commonly add a rule that files supplier replies into an obscure folder, so the real supplier’s “we never got paid” email is never seen. Auditing inbox rules is a five-minute check that finds real compromises.

If it has already happened

Move quickly, because the first few hours matter more than anything else.

Call your bank immediately and ask them to attempt a recall. Report it to Scamwatch and to ReportCyber. Change the password and revoke sessions on any mailbox that may be involved. Then work out whose mailbox was actually compromised, yours or theirs, because until you know that, you do not know what else the attacker has read.

The honest summary

This fraud targets your processes, not your technology, which is why buying a product will not fix it. A phone call to a known number, made every single time bank details change, is worth more than any tool you could buy.


Want your email authentication and payment approval process reviewed together, so a convincing invoice cannot quietly become a real loss? Get in touch and we will work through both.

Want help putting this into practice?

Tell us what you are trying to solve and we will tell you what it would take.

Get in touch