TL;DR:
- Invoice redirect fraud — where attackers intercept a legitimate invoice and substitute their own bank account details — is one of the most common and costly attacks against small businesses in the UK.
- It doesn’t require hacking your systems. Attackers compromise email accounts, intercept invoice threads, and insert fraudulent payment instructions.
- The NCSC recommends one practical fix above all others: phone verification of bank account changes using a number from your own records, not one in the email.
If your business pays suppliers or receives payments from customers, invoice fraud is a real threat. The National Fraud Intelligence Bureau (NFIB) recorded over 11,000 reported cases of invoice and mandate fraud in 2025, with total losses estimated at over £137 million. The actual figure is higher — most cases go unreported.
The particularly insidious thing about invoice fraud is that it often doesn’t require compromising your own systems at all.
How Invoice Redirect Fraud Works
The most common variant goes like this:
- An attacker compromises the email account of one of your suppliers — or sets up a convincingly spoofed look-alike address.
- They monitor the inbox, watching for invoice threads between the supplier and customers (you).
- When an invoice is due, they intercept or impersonate the supplier’s email and send a message saying that the supplier’s bank account details have changed, usually with a plausible explanation (“we’ve switched banks” or “please update your records”).
- You update your records and pay the next invoice to the fraudulent account.
- The money is withdrawn immediately and often transferred abroad. Recovery is rare.
The key point: your own systems may be completely untouched throughout. The fraud happens in the supplier’s email or in the email channel between you.
CEO and Management Impersonation
A related variant targets employees with payment authority. An attacker spoofs or compromises a senior person’s email account — the CEO, financial director, or owner — and sends an urgent request to an accounts payable employee to make an immediate bank transfer.
These messages typically:
- Appear to come from the senior person’s email address (or a convincing variant)
- Create urgency and ask for confidentiality (“don’t discuss this with anyone, I’m in a meeting”)
- Involve a time-sensitive payment or acquisition
The pressure and authority of the apparent sender is what makes these work. Employees who would normally question an unusual payment request don’t, because the instruction appears to come from the top.
Five Practical Defences
1. Verify bank account changes by phone — always.
This is the NCSC’s single most important recommendation. If you receive any communication — by email, letter, or even in person — saying that a supplier’s bank account details have changed, call them to confirm. Use a phone number from your own records (your accounting system, previous correspondence, their website) — not any number included in the email making the request.
This one step defeats the vast majority of invoice redirect fraud. Attackers can spoof email addresses, but they can’t intercept your phone calls to a known number.
2. Establish a clear internal process for new or changed payee details.
Decide in advance that no payment will be made to a new or changed bank account without verbal confirmation, regardless of who the instruction appears to come from. Write this down and make it a non-negotiable part of your accounts payable process. It shouldn’t be something your staff have to decide in the moment.
3. Enable multi-factor authentication on your business email accounts.
A significant proportion of invoice fraud starts with a compromised email account on the supplier side. You can’t control your suppliers’ security, but you can make sure your own accounts aren’t the starting point for an attack against your customers. MFA on email dramatically reduces account compromise risk.
4. Check email sender addresses carefully.
Impersonation emails often use slight variations of a legitimate address: finance@supplier.com vs finance@supp1ier.com, or a completely different domain that looks similar at a glance. Your email client may not display the full address by default — click on the sender name to see the actual address.
For internal CEO-impersonation attempts, look for whether the email domain exactly matches your company’s domain, not just whether the display name looks right.
5. Use Confirmation of Payee (CoP) when making new bank transfers.
UK banks participating in the Confirmation of Payee scheme (which includes all major high street banks) allow you to check that the account name matches the sort code and account number before you send money. If the name doesn’t match or the account isn’t registered, you’ll receive a warning. This doesn’t catch all fraud, but it catches the cases where the fraudster uses a completely unrelated account name.
If You’ve Been Defrauded
Act immediately. The faster you act, the higher the chance of a recall.
- Contact your bank the moment you suspect fraud and ask them to recall the payment. Many banks have fraud response lines specifically for this.
- Report to Action Fraud (actionfraud.police.uk) — even if you’re unlikely to recover the money, reporting helps build the intelligence picture.
- Report to the NCSC if the fraud involved a cyber element (email compromise, phishing) — report.ncsc.gov.uk.
- Notify your supplier if their email was the point of compromise — they may have other customers at risk.
Payment recall success rates drop sharply after 24 hours, particularly for international transfers. Speed matters.
The NCSC’s Cyber Essentials Baseline
If you want a structured starting point for reducing your attack surface, the NCSC’s Cyber Essentials scheme covers five baseline controls: firewall configuration, secure settings, access control, malware protection, and patch management. Certification costs from around £300 for small businesses and is widely recognised by public sector procurement frameworks.
Invoice fraud specifically isn’t a “Cyber Essentials” failure — it’s often a process failure rather than a technical one. But strong email security (MFA, anti-spoofing DNS records like SPF, DKIM, and DMARC) reduces the attack surface that makes these frauds possible.