Invoice fraud rarely starts with a hacker stereotype. For many UK SMEs, the first sign is an email that looks completely normal, asking to update bank details before the next payment.

Invoice fraud rarely starts with a "hacker" stereotype. For many UK SMEs, the first sign is an email that looks completely normal:
"Hi — our bank details have changed. Please pay the next invoice to this new account."
Sometimes it's a "re-issued" invoice with a different account number. Sometimes it's a last-minute change request just before payday. Either way, it's designed to hit the moment when your team is busy and just wants to get payments out on time.
The UK's National Cyber Security Centre describes this family of scams as business payment fraud, often linked to Business Email Compromise, where criminals impersonate a legitimate contact to divert money to the wrong account.
The good news: you don't need a huge finance department to defend against it. You need a repeatable verification process, and a few sensible controls around email and access.
These attacks succeed because they target process and trust, not just technology.
Common ingredients include:
In many cases, the attacker has access to email threads (from a compromised mailbox) or is spoofing a domain that looks similar. That means the message can reference real invoices, real names, and real context.
For an SME, invoice fraud can create immediate problems:
Even when banks can recover funds, the process is stressful and time-consuming, and recovery is never guaranteed.
If you only implement one thing from this article, make it this: never accept bank detail changes by email alone.
Use the following workflow whenever a supplier, or anyone, asks to change payment details.
Treat any of these as high-risk events:
Create a short internal rule: "Bank detail changes require verification."
Call the supplier using a phone number you already trust:
Do not use the phone number in the email, a link in the email to "confirm details", or a forwarded message where the contact info could have been altered.
When you call, verify the person's name and role, that they did request the change, and the new bank details (read them back carefully).
Small teams often feel they can't do "segregation of duties". You can — it just needs to be proportional.
A simple rule works well: one person verifies the change, and a second person approves it before payment is made. This can be the owner or director for smaller businesses. The key is that it's not the same person doing everything in one go.
If the request isn't urgent, hold the first payment to the new account for 24 hours.
Why it helps: it breaks the attacker's timing pressure, it gives you time to spot anomalies, and it reduces "same day" losses. If you can't delay payment, increase scrutiny with extra verification and a second approver.
Create a lightweight record (a note in your accounting system, a checklist, or a short form) that captures who requested the change, who you spoke to and what number you called, the date and time of the call, and who approved it.
This protects your team, helps with audits, and makes it easier to respond if anything goes wrong.
Process is the first line of defence, but it's worth hardening the systems criminals rely on. Here are the most impactful steps for most UK SMEs using Microsoft 365.
If an attacker can access a mailbox, they can read invoice threads and write convincing messages.
Priorities: strong sign-in protection, where MFA is a baseline and passkeys are increasingly a better option where supported; Conditional Access to block sign-ins from unexpected countries, restrict legacy authentication, and require stronger authentication for high-risk sign-ins; and admin account hygiene, with separate admin accounts, least privilege, and tighter sign-in rules.
Even without a compromised mailbox, criminals may spoof your domain or a supplier's.
Practical actions: ensure SPF, DKIM and DMARC are configured and enforced for your domain, use free NCSC tooling to check and improve email security configuration, and review external email warnings and anti-phishing policies in Microsoft 365.
Generic "phishing awareness" isn't enough. Teach your team to recognise the payment-fraud pattern.
A 10-minute briefing for anyone who can initiate or approve payments should cover: bank detail changes are always high-risk, verification is by phone using a known number, urgency is a red flag rather than a reason to skip checks, and if unsure, pause and escalate.
Speed matters.
If you want to reduce invoice-fraud risk without slowing the business down, we can help you put a practical process in place and strengthen the Microsoft 365 controls around it.
That typically includes reviewing your current payment workflow and where verification is missing, hardening Microsoft 365 sign-ins and admin access, improving email security settings and domain protection, and helping you document a simple, repeatable procedure your team will actually follow.
If you'd like, we can run a short, non-technical review and give you clear next steps. Your Technology, Managed the Right Way.
Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.
