For a small business, invoice fraud does not always begin with an obviously fake message. Sometimes it looks like a normal email from a regular supplier: "Our bank details have changed — please use the new account for this month's payment."

For a small business, invoice fraud does not always begin with an obviously fake message. Sometimes it looks like a normal email from a regular supplier: "Our bank details have changed — please use the new account for this month's payment."
If the timing matches a real invoice, it is easy to make the change without a second thought. But if an attacker has taken over a mailbox, copied a supplier's branding or sent a convincing lookalike message, the money can go somewhere it was never meant to go.
For a Bolton or Bury SME, one incorrect payment can create more than a bank problem. It can mean a supplier is still unpaid, work is delayed, cash flow is squeezed and a busy team has to spend hours trying to recover funds. The safest habit is simple: never change payment details based on an email alone.
Fraudsters know that payment requests often involve urgency. A message might say the old account is closing today, a project will be delayed, or the sender is waiting for confirmation before the end of the day. That pressure is part of the trap.
The request may arrive after a genuine conversation, contain the correct invoice number and use a familiar signature. Those details are not proof that it is safe. A supplier's account may have been compromised, or the message may be a carefully imitated fake.
This is often called business email compromise: using a stolen or spoofed email identity to persuade someone to make a payment or change a process. You do not need a large finance department to be affected. In a 5–50 person business, the person raising an invoice, approving it and making the payment may be the same person.
Do not reply to the message to ask, "Is this correct?" If the mailbox is compromised, the attacker can simply confirm the request.
Do not click a link or use a phone number included in the email. Save the invoice and the original message, but put the payment on hold until the details have been checked another way.
Call the supplier using a telephone number already stored in your accounting system, supplier record or previous paperwork. Do not rely on a new number supplied in the bank-detail change request.
If you normally speak to a named contact, ask them to confirm the change verbally. For larger payments, consider a second channel as well, such as a known mobile number or an established supplier portal. The important point is that the verification route must be independent of the message asking for the change.
A simple two-person check makes it harder for one convincing message to become an irreversible payment. One person can contact the supplier; another can review the amount, account name and reason for the change before the details are updated.
This does not need to be bureaucratic. For a small team, it may be a short call or a message in an internal channel saying who verified the change and when. For higher-value payments, set a clear threshold where a second person must approve the release.
Once the supplier has confirmed the change, update the details in the accounting system rather than copying them from an email into the banking screen every time.
Record the date, the person who confirmed the change and the contact method used. If your process allows it, keep the previous details for a short period rather than overwriting them without trace. That creates a simple audit trail if someone later asks what happened.
Technical checks help, but they should not replace verification. Be cautious when a request includes:
Email security controls such as multi-factor authentication, anti-phishing protection and mailbox monitoring reduce the chance of an attacker taking over an account. Managed IT Support can also help review who has access to finance mailboxes, whether suspicious sign-in alerts are enabled and how staff should report unusual messages. These controls are valuable, but a clear payment process is still essential because no filter catches everything.
Imagine a North West engineering firm receives an email from a regular materials supplier on a Friday afternoon. The message includes a real purchase order number and asks the accounts administrator to use a new sort code and account number.
Instead of replying, the administrator calls the supplier's main office number from the company's records. The supplier confirms that no bank details have changed. The email account of one of the supplier's employees has been compromised.
The payment is stopped, the message is reported and the supplier is warned. The business avoids a loss because the team had agreed one simple rule: bank-detail changes must be verified outside email.
Write down your process before the next request arrives:
If a payment has already been sent to the wrong account, contact your bank immediately, preserve the emails and involve the relevant authorities and your IT provider. Speed matters.
A calm, repeatable process protects cash flow without making everyday payments difficult. It is one more practical way to keep your technology and business operations managed the right way.
Review one supplier record today and confirm that the contact number used for verification comes from a trusted source. If you are unsure whether your email security and payment process work together, Managed IT Support can help you review the gaps.
Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.
