Invoice Fraud and 'Change of Bank Details' Emails: A Practical Payment-Verification Process for UK SMEs

Invoice fraud rarely starts with a hacker stereotype. For many UK SMEs, the first sign is an email that looks completely normal, asking to update bank details before the next payment.

Blog Main Image

Invoice fraud rarely starts with a "hacker" stereotype. For many UK SMEs, the first sign is an email that looks completely normal:

"Hi — our bank details have changed. Please pay the next invoice to this new account."

Sometimes it's a "re-issued" invoice with a different account number. Sometimes it's a last-minute change request just before payday. Either way, it's designed to hit the moment when your team is busy and just wants to get payments out on time.

The UK's National Cyber Security Centre describes this family of scams as business payment fraud, often linked to Business Email Compromise, where criminals impersonate a legitimate contact to divert money to the wrong account.

The good news: you don't need a huge finance department to defend against it. You need a repeatable verification process, and a few sensible controls around email and access.

Why "Change of Bank Details" Scams Work

These attacks succeed because they target process and trust, not just technology.

Common ingredients include:

  • A believable sender: a supplier, accountant, solicitor, contractor, or even someone internal.
  • A realistic reason: "new banking provider", "audit", "new account for overseas payments", "please use this from now on".
  • Timing pressure: end of month, payroll week, a big delivery due, or "we need this paid today".
  • A small change: often just the bank details — everything else looks familiar.

In many cases, the attacker has access to email threads (from a compromised mailbox) or is spoofing a domain that looks similar. That means the message can reference real invoices, real names, and real context.

The Outcome for an SME

For an SME, invoice fraud can create immediate problems:

  • Cashflow shock: a payment that was meant to settle a supplier account disappears.
  • Operational disruption: suppliers put accounts on hold because they haven't been paid.
  • Reputational strain: awkward conversations with suppliers, customers, and accountants.
  • Time cost: urgent bank calls, internal investigations, and sometimes legal advice.

Even when banks can recover funds, the process is stressful and time-consuming, and recovery is never guaranteed.

A Simple, Practical Verification Workflow (Use This Every Time)

If you only implement one thing from this article, make it this: never accept bank detail changes by email alone.

Use the following workflow whenever a supplier, or anyone, asks to change payment details.

Step 1: Stop and Label It

Treat any of these as high-risk events:

  • A new supplier bank account
  • A change to existing bank details
  • A "re-issued" invoice with different account details
  • A request to split a payment across accounts

Create a short internal rule: "Bank detail changes require verification."

Step 2: Verify Out-of-Band (Use a Known Good Contact Route)

Call the supplier using a phone number you already trust:

  • From your finance system
  • From a signed contract
  • From a previous invoice you have on file (not the new one)
  • From the supplier's official website (typed manually, not clicked from the email)

Do not use the phone number in the email, a link in the email to "confirm details", or a forwarded message where the contact info could have been altered.

When you call, verify the person's name and role, that they did request the change, and the new bank details (read them back carefully).

Step 3: Two-Person Approval for Changes

Small teams often feel they can't do "segregation of duties". You can — it just needs to be proportional.

A simple rule works well: one person verifies the change, and a second person approves it before payment is made. This can be the owner or director for smaller businesses. The key is that it's not the same person doing everything in one go.

Step 4: Add a Cooling-Off Window (When Possible)

If the request isn't urgent, hold the first payment to the new account for 24 hours.

Why it helps: it breaks the attacker's timing pressure, it gives you time to spot anomalies, and it reduces "same day" losses. If you can't delay payment, increase scrutiny with extra verification and a second approver.

Step 5: Record the Verification

Create a lightweight record (a note in your accounting system, a checklist, or a short form) that captures who requested the change, who you spoke to and what number you called, the date and time of the call, and who approved it.

This protects your team, helps with audits, and makes it easier to respond if anything goes wrong.

Strengthen the Email Side

Process is the first line of defence, but it's worth hardening the systems criminals rely on. Here are the most impactful steps for most UK SMEs using Microsoft 365.

1) Make Account Takeover Harder

If an attacker can access a mailbox, they can read invoice threads and write convincing messages.

Priorities: strong sign-in protection, where MFA is a baseline and passkeys are increasingly a better option where supported; Conditional Access to block sign-ins from unexpected countries, restrict legacy authentication, and require stronger authentication for high-risk sign-ins; and admin account hygiene, with separate admin accounts, least privilege, and tighter sign-in rules.

2) Reduce Impersonation and Spoofing

Even without a compromised mailbox, criminals may spoof your domain or a supplier's.

Practical actions: ensure SPF, DKIM and DMARC are configured and enforced for your domain, use free NCSC tooling to check and improve email security configuration, and review external email warnings and anti-phishing policies in Microsoft 365.

3) Train for the Specific Scam

Generic "phishing awareness" isn't enough. Teach your team to recognise the payment-fraud pattern.

A 10-minute briefing for anyone who can initiate or approve payments should cover: bank detail changes are always high-risk, verification is by phone using a known number, urgency is a red flag rather than a reason to skip checks, and if unsure, pause and escalate.

What to Do If You Suspect You've Paid the Wrong Account

Speed matters.

  1. Call your bank immediately — the sooner you report it, the better the chance of stopping or recalling the transfer.
  2. Preserve evidence: keep the emails, headers, and any attachments.
  3. Report the incident via the UK's official channels, using NCSC guidance on reporting cyber incidents and suspicious messages.
  4. Assume email compromise is possible and get your Microsoft 365 sign-in logs and mailbox rules checked.

A Quick "This Week" Checklist

  • Agree the rule: bank detail changes must be verified out-of-band
  • Create a two-person approval step for changes
  • Add a simple verification record (template or checklist)
  • Review Microsoft 365 sign-in controls (MFA/passkeys + Conditional Access)
  • Confirm SPF/DKIM/DMARC are in place and enforced

How Managed Technology Group Can Help

If you want to reduce invoice-fraud risk without slowing the business down, we can help you put a practical process in place and strengthen the Microsoft 365 controls around it.

That typically includes reviewing your current payment workflow and where verification is missing, hardening Microsoft 365 sign-ins and admin access, improving email security settings and domain protection, and helping you document a simple, repeatable procedure your team will actually follow.

If you'd like, we can run a short, non-technical review and give you clear next steps. Your Technology, Managed the Right Way.

Ready to Work With an IT Company That Actually Gives a Damn?

Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.

IT Review Consultation