The Email Looked Real. The Payment Request Wasn’t.

·

Employee reviewing a vendor invoice and payment-change email with paths showing direct payment to a scammer versus phone verification with the legitimate vendor.

The email looks ordinary.

A familiar vendor says its banking information has changed. The invoice is attached, the signature block looks correct, and the message references work your business recognizes. Payment is due today, so the employee handling accounts payable updates the details and sends the money.

The vendor calls several days later to ask why the invoice is overdue.

The payment did not go to the vendor. It went to a scammer.

This type of fraud is often called business email compromise, or BEC. The scam may begin with a criminal gaining access to a real email account, impersonating a trusted sender, or creating a nearly identical address. The objective is usually the same: make a fraudulent financial request appear to be part of normal business.

According to the FBI’s 2025 Internet Crime Report, IC3 received 24,768 business-email-compromise complaints involving more than $3.0 billion in reported losses. Those figures represent incidents reported to the FBI, not every loss that occurred.

The lesson is not simply that employees need to read email more carefully. Modern scams can contain accurate names, familiar writing styles, legitimate invoice details, and information taken from earlier conversations.

The stronger lesson is this: no email should be trusted enough to change where your money goes without independent verification.

Scammers target the process, not just the inbox

Phishing is often described as a suspicious message containing a bad link or obvious spelling errors. Those messages still exist, but payment scams can be far more convincing.

A criminal may:

  • Impersonate an owner or executive requesting an urgent transfer
  • Pose as a vendor announcing new banking details
  • Take over a real mailbox and continue an existing conversation
  • Send an altered invoice using information from a legitimate transaction
  • Pretend to be an employee changing direct-deposit information
  • Create an email address that differs from the real one by a single character
  • Claim that confidentiality or a deadline prevents normal confirmation

These scams work because they are designed around the way businesses already operate. The criminal does not need to defeat every security tool. They need one employee to believe the request belongs in the normal workflow.

That makes business process part of the cybersecurity defense.

The warning signs are often operational

Employees are commonly told to watch for misspelled words, strange links, and unknown senders. Those clues are useful, but they are not sufficient.

The more dependable warning signs are often changes in behavior or process:

  • A vendor asks to use a new bank account
  • An executive requests an unusual or urgent payment
  • A routine invoice arrives with different instructions
  • The sender discourages a phone call or normal approval
  • Someone asks the employee to keep the transaction confidential
  • The requested payment method differs from previous transactions
  • The employee is asked to bypass a documented threshold or control
  • A familiar request arrives through an unfamiliar channel

Any of these conditions can occur legitimately. That is precisely why an employee should not be forced to decide whether the message “feels real.” The business should define which changes automatically require verification.

Do not make perfect detection the control

Security awareness matters. Employees should know how to examine sender addresses, avoid unexpected attachments, report suspicious messages, and recognize pressure tactics.

But awareness training cannot guarantee that every employee will identify every scam. A fraudulent request may come from a compromised account and appear inside a genuine email thread. Generative AI can help criminals create polished messages without the grammar mistakes people have learned to expect. A busy employee may be handling a real deadline while receiving a realistic request.

If the entire defense depends on someone noticing that one message is fake, the business has a fragile control.

A stronger control works even when the message looks real.

Verify through a channel the request did not control

The FBI recommends using a secondary channel or two-factor authentication to verify requests to change account information with the intended recipient.

For a small business, that can be translated into a simple rule:

Any new or changed payment instruction must be confirmed through a trusted contact method already on file.

If a vendor emails new banking information, do not use the phone number included in that email or on the new invoice. The scammer may control those details too. Instead, call a known representative using a number from the existing vendor record, an earlier verified contract, or the vendor’s independently confirmed website.

Ask the contact to confirm the change. Record who completed the verification, whom they contacted, when it occurred, and what was confirmed.

The same principle applies to requests from executives and employees. A quick call, in-person confirmation, or approved internal channel can determine whether the person actually requested the transaction.

The inconvenience is intentional. A second channel breaks the scammer’s control over the conversation.

Build a payment process that remains usable

A security control that is confusing or excessively slow will eventually be bypassed. The answer is not to remove verification; it is to make the safe path clear and practical.

A small-business payment-verification process can include:

Defined triggers

Require independent verification for specific events, such as:

  • New vendors
  • Changes to bank accounts or payment destinations
  • Changes to employee direct-deposit information
  • Unusual payment methods
  • Urgent or confidential payment requests
  • Transactions above a defined threshold
  • Requests that bypass the normal invoice or purchase process

Employees should not have to debate whether these events deserve a second look. The trigger should be automatic.

Trusted contact information

Maintain approved vendor and employee contact details separately from incoming change requests. Limit who can modify those records, and document how a new contact becomes trusted.

Clear authority

Define who may create or change a payee, who may approve a payment, and who may release the funds. For higher-value transactions, separating those responsibilities can reduce the likelihood that one compromised account or rushed employee causes a loss.

A fast escalation path

Employees need to know exactly whom to contact when something appears wrong. If the owner is the only person who can resolve a question and is unavailable, the pressure to proceed without verification increases.

Permission to slow down

Leaders must make it clear that stopping a questionable payment is responsible behavior—even when the request appears to come from the owner. An employee who fears being blamed for missing a deadline may obey the fraudulent message instead of challenging it.

A realistic example

Imagine that a construction company regularly purchases materials from the same supplier.

An accounts-payable employee receives an email inside an existing conversation. The supplier appears to say that its bank has changed and asks for the next invoice to be sent to a new account. The invoice number, project name, and amount are accurate.

Nothing about the request appears obviously fake.

Under a weak process, the employee changes the banking information because the details match an expected payment.

Under a stronger process, the change itself triggers verification. The employee calls the supplier using the established number in the vendor record. The supplier confirms that it did not request the change. The payment is held, the fraudulent message is reported, and the business avoids the loss.

The employee did not need to outsmart the scammer. The process made the scammer prove control of a second, trusted channel.

Technology still matters

Process controls should complement—not replace—basic technical protections.

Small businesses should use multifactor authentication on email, financial, and other sensitive accounts. CISA advises businesses to use the strongest option available and to aim for phishing-resistant MFA. Email services should be configured to identify suspicious messages, and access to payment and vendor records should be limited according to job responsibilities.

Businesses should also:

  • Use unique passwords and a password manager
  • Keep email, browsers, devices, and financial software updated
  • Remove access promptly when employees leave or change roles
  • Review email forwarding rules and account activity after suspected compromise
  • Protect vendor-master and banking records from unauthorized changes
  • Make reporting suspicious messages easy and blame-free

Technology can reduce the chance that an account is compromised. Verification can reduce the chance that a convincing message becomes a completed payment. Both layers matter.

Know what to do if money is sent

Speed matters after a fraudulent payment is discovered.

The FBI advises victims of business email compromise to contact the originating financial institution as soon as the fraud is recognized and request a recall or reversal. The business should also file a detailed complaint with the FBI’s Internet Crime Complaint Center at IC3.gov.

Do not delay while trying to conduct a complete internal investigation. Contact the bank immediately, then preserve the email, invoice, payment details, account information, timestamps, and related communications. Notify the appropriate internal leaders and technology provider, and determine whether an email or financial account was compromised.

The incident-response contact list and bank telephone number should be documented before an incident occurs. Searching for the procedure after the money has moved wastes valuable time.

Test your payment process

Walk through the last payment change your business received and ask:

  1. What event triggered additional verification?
  2. How did the employee know which contact information to trust?
  3. Could the person requesting the change also modify the trusted record?
  4. Were creating the payee, approving the payment, and releasing the funds controlled appropriately?
  5. Could an employee question an executive’s request without fear of punishment?
  6. What happens when the normal verifier is unavailable?
  7. How quickly would the business contact its bank after discovering fraud?
  8. Does everyone who handles payments know how to report a suspicious request?

If the answers depend on memory, intuition, or “knowing the vendor,” the process is not yet dependable.

Trust the relationship—but verify the transaction

Scammers succeed by making a fraudulent request feel routine. They borrow the authority of an executive, the familiarity of a vendor, and the urgency of a deadline. Their advantage is not always technical sophistication. Often, it is their understanding of how people behave when work needs to move quickly.

Telling employees to be more careful is not enough.

Give them a simple rule, trusted contact information, permission to pause, and a clear way to verify unusual financial requests. Design the process so that one convincing email cannot change where the business sends its money.

The safest payment is not the one associated with the most realistic message. It is the one that followed a verification process the scammer could not control.

References