Skip to content

Case file

The Invoice That Changed Bank Details (Composite Case)

Location

European Union and United Kingdom (composite scenario)

Period

2023 – 2023

Category

Business Email Compromise

Reviewed by

Pending review
This case is presented for education. Facts, allegations and investigative findings are labelled by their source.

Victim profile

A small finance team at a mid-sized supplier, presented as a composite, handling routine supplier payments.

What happened

This composite scenario reflects common business email compromise reports. A finance team receives an email that appears to come from a long-standing supplier, asking to update bank details for an upcoming invoice. The email references a real project and is timed to a genuine payment cycle. A payment is made to the new account. The real supplier later chases the unpaid invoice, revealing the change was fraudulent.

Warning signs

  • A supplier changing bank details by email.
  • A request timed to an upcoming payment.
  • A reply-to address that differs from the sender.
  • Pressure to process the change quickly.
  • A change that bypasses the normal approval route.

How the deception worked

The deception relied on routine and hierarchy. The message matched an expected invoice cycle and used a trusted supplier's name, so the change looked administrative. This summary stays at the level of what the team experienced.

What failed

Bank detail changes were accepted by email without a call-back to a known supplier number.

How it was detected

The genuine supplier followed up on the unpaid invoice, prompting an internal review.

Impact

A significant payment was lost. A recall was attempted but only part of the funds was recovered.

Lessons

  1. 1Verify bank detail changes by calling a known number.
  2. 2Require dual approval for any payment detail change.
  3. 3Train staff to treat urgency and secrecy as red flags.
  4. 4Reconcile payments with suppliers regularly.

Sources

  • Verified factGOVERNMENT

    Online fraud and cybercrime threat assessments

    Europol · 12 Sept 2024

    View source
  • Verified factGOVERNMENT

    Internet Crime Complaint Center (IC3) public reports and advisories

    FBI Internet Crime Complaint Center (IC3) · 01 Mar 2024

    View source