Case file
The Invoice That Changed Bank Details (Composite Case)
Location
Period
Category
Reviewed by
Victim profile
A small finance team at a mid-sized supplier, presented as a composite, handling routine supplier payments.
What happened
This composite scenario reflects common business email compromise reports. A finance team receives an email that appears to come from a long-standing supplier, asking to update bank details for an upcoming invoice. The email references a real project and is timed to a genuine payment cycle. A payment is made to the new account. The real supplier later chases the unpaid invoice, revealing the change was fraudulent.
Warning signs
- A supplier changing bank details by email.
- A request timed to an upcoming payment.
- A reply-to address that differs from the sender.
- Pressure to process the change quickly.
- A change that bypasses the normal approval route.
How the deception worked
The deception relied on routine and hierarchy. The message matched an expected invoice cycle and used a trusted supplier's name, so the change looked administrative. This summary stays at the level of what the team experienced.
What failed
Bank detail changes were accepted by email without a call-back to a known supplier number.
How it was detected
The genuine supplier followed up on the unpaid invoice, prompting an internal review.
Impact
A significant payment was lost. A recall was attempted but only part of the funds was recovered.
Lessons
- 1Verify bank detail changes by calling a known number.
- 2Require dual approval for any payment detail change.
- 3Train staff to treat urgency and secrecy as red flags.
- 4Reconcile payments with suppliers regularly.
Sources
- Verified factGOVERNMENT
Online fraud and cybercrime threat assessments
Europol · 12 Sept 2024
View source - Verified factGOVERNMENT
Internet Crime Complaint Center (IC3) public reports and advisories
FBI Internet Crime Complaint Center (IC3) · 01 Mar 2024
View source