Business email compromise: what to do after a fake invoice payment
Respond to payment-redirection fraud, preserve original emails and verify changed bank details without relying on the compromised thread.

Contact the sending bank immediately, notify your organisation’s security team and verify the supplier through a previously trusted channel. Preserve original emails and payment records. An email from a familiar account can still be fraudulent if that account has been compromised.
Business email compromise can affect companies and individuals paying an invoice, deposit or property-related expense. Criminals impersonate a supplier or take over a genuine mailbox, then introduce a new bank account at a plausible point in the conversation.
The emergency response needs both a payment track and a security track. Asking the same email thread whether the account change was genuine can return the question to the criminal. Independent verification is essential.
Start the payment response now
Call the sending bank with the amount, recipient account, time and reference. Say that the payment may have been redirected through a compromised or impersonated email. Ask about stopping it, requesting a recall and notifying the recipient bank.
Within a business, notify the people who can prevent related payments and preserve logs. Do not assume only one invoice is affected. Look for scheduled transfers and recent bank-detail changes. Document each action and reference so the response is coordinated rather than duplicated.
Preserve the original message chain
Retain the original emails, including headers where available, attachments and the invoice versions before and after the change. Save the bank-detail instruction and note the channel through which it was accepted. Ask the security team to preserve relevant mailbox and login records.
A screenshot alone may miss technical routing details. Do not delete the entire thread as soon as the fraud is noticed. At the same time, do not keep a compromised account active for convenience; preserve evidence while containing access through the appropriate security process.
Check whose account and workflow were compromised
The criminal may have used a lookalike domain, a genuine hacked mailbox or malware affecting a device. Tell the supplier using a phone number or contact route already known independently of the suspicious message. Both organisations may need to examine their accounts.
Review forwarding rules, unknown sessions and recovery settings. Change compromised credentials and enable multi-factor authentication. Avoid assigning blame before the evidence is assessed; discovering where the instruction entered the workflow helps prevent another payment.
Separate emergency recovery from later liability
Notify police or the official fraud-reporting body for your jurisdiction. If insurance may be relevant, check its notification requirements promptly. Whether a bank, supplier, employee process or insurer bears a loss is a separate legal and contractual question.
Improve the approval process after containing the incident: independently call back on changes to bank details and avoid treating a familiar email thread as sufficient authority. A second pair of eyes should verify the actual change, not merely approve the same unverified document.
A short checklist
- Contact the bank immediately.
- Stop related scheduled payments.
- Notify security and the genuine supplier independently.
- Preserve full emails and invoice versions.
- Review account access and bank-detail approval controls.
Common questions
Can fraud come from the supplier’s real email?
Yes. The FBI describes criminal use of compromised genuine accounts and legitimate invoice conversations. A familiar address does not remove the need to verify changed payment details.
Does a successful recall settle who was responsible?
No. A recall concerns movement of funds. Responsibility, insurance and any unresolved loss need their own assessment under the applicable terms and law.
References
- Business email compromiseFederal Bureau of Investigation · United States; business security guidance
- What to do if you were scammedFederal Trade Commission · United States; practical prevention guidance
- How to recognize and avoid phishing scamsFederal Trade Commission · United States; security guidance