Business Email Compromise: How Invoice Fraud Works
Cybercriminals are hijacking business emails to divert payments. Learn how business email compromise (BEC) invoice fraud works and how to protect your.
By Lena Hart · Published · 12 min read

Business email compromise (BEC) invoice fraud is a sophisticated scam where attackers impersonate a legitimate supplier to trick a company into paying a fraudulent invoice. By gaining access to business email accounts, criminals can manipulate payment details and divert large sums of money into their own accounts, often before anyone realizes the theft has occurred. According to the FBI, BEC is consistently one of the most financially damaging online crimes, costing businesses billions of dollars globally each year.
What is Business Email Compromise (BEC)?
Business email compromise is a broad category of social engineering attacks conducted over email. Unlike mass-market phishing campaigns that blast out thousands of generic emails, BEC attacks are highly targeted and meticulously researched. The goal is almost always direct financial fraud. While invoice fraud is a common variant, BEC encompasses several distinct tactics:
- CEO Fraud: The attacker impersonates a high-level executive (like the CEO or CFO) and emails an employee in the finance or accounting department, instructing them to make an urgent, confidential wire transfer.
- Invoice Fraud (Vendor Email Compromise): The focus of this article. Attackers compromise a vendor's email account or impersonate them to send fraudulent invoices with altered bank details to their customers.
- Attorney Impersonation: An attacker pretends to be a lawyer or representative from a law firm, often contacting a high-level executive about a confidential and time-sensitive matter that requires an immediate payment.
- Data Theft: Sometimes the goal isn't immediate payment but the theft of sensitive information. Attackers might impersonate an HR manager to request W-2 tax forms or other personally identifiable information (PII) on employees, which can then be used for identity theft or further targeted attacks.
At its core, all BEC relies on deception and exploiting human trust. The emails are crafted to look authentic, using correct names, titles, and language that mimics legitimate business communications.
The Anatomy of an Invoice Fraud Attack
BEC invoice fraud isn't a single event but a multi-stage operation. Attackers follow a patient, methodical process to maximize their chances of success and minimize the risk of early detection.
Step 1: Reconnaissance and Infiltration
First, attackers identify a target organization and its network of suppliers. They use open-source intelligence (OSINT) from sources like company websites, press releases, and LinkedIn to map out key personnel, especially in the accounts payable (AP) or finance departments. They look for names, job titles, and email address formats.
Once they have a target, they need to gain a foothold in the email system of either the target company or one of its vendors. This initial access is often achieved through a simple phishing email that tricks an employee into revealing their password. Alternatively, they may use password spraying (testing common passwords against many accounts) or purchase stolen credentials from criminal marketplaces. These credentials frequently come from widespread attacks using infostealer malware logs sold on the dark web.
Step 2: Monitoring and Waiting
After gaining unauthorized access, the attacker does not act immediately. Instead, they operate in stealth mode, quietly observing the compromised inbox. They may spend weeks or even months learning the organization's internal processes. They study communication styles, identify key vendors, and learn the rhythm of invoicing and payment cycles. To maintain access and cover their tracks, they often set up email forwarding rules that send copies of all incoming and outgoing messages to an external account they control. This allows them to monitor conversations without having to log in repeatedly, which could trigger security alerts.
Step 3: The Attack—Interception and Deception
When the time is right—usually when a large payment is due—the attacker makes their move. They use one of several techniques:
- Email Interception: The attacker intercepts a legitimate invoice sent by the vendor. They modify the attached PDF to replace the real bank account details with their own and then forward it to the customer. The customer receives an email from a trusted source with what appears to be a legitimate invoice.
- Lookalike Domain: The attacker registers a domain name that is nearly identical to the legitimate vendor's domain (e.g., `acme-supply.co` instead of `acme-supply.com`). They then email the customer from this spoofed domain, attaching the fraudulent invoice. To a busy AP employee, this subtle difference is easy to miss.
The fraudulent email is carefully crafted. It often includes a plausible reason for the change in banking information, such as "we are updating our financial systems" or "our bank is conducting an audit." The message will convey a sense of normalcy and urgency, pressuring the employee to process the payment quickly.
Step 4: The Payoff and Disappearance
The target's AP department, believing the request is legitimate, updates the vendor's payment information and processes the invoice. The payment is sent via wire transfer or ACH to the attacker's bank account, which is typically a mule account controlled by the criminals. Once the funds arrive, they are moved rapidly through a series of other accounts or converted into cryptocurrency to obscure the trail and make recovery nearly impossible. The crime often goes unnoticed until the legitimate vendor follows up to ask why their invoice hasn't been paid.
Why is BEC Invoice Fraud So Effective?
The success of BEC hinges on its ability to bypass technical controls and exploit procedural weaknesses and human psychology.
- Exploitation of Trust: The scam leverages the pre-existing trust between a company and its established vendors. An email from a known supplier doesn't immediately raise suspicion.
- Focus on Human Error: It preys on the fact that finance departments are often busy, high-volume environments. Employees processing dozens or hundreds of invoices a week may not scrutinize every detail, especially when under pressure.
- Lack of Verification: Many organizations lack a strict, mandatory protocol for verifying changes to vendor payment information. Attackers know this and count on employees taking the path of least resistance.
- Email's Inherent Weakness: Standard email protocols do not have robust, built-in sender verification. While technologies like DMARC exist, they are not universally implemented, leaving the door open for sophisticated spoofing.
Detecting the Red Flags of Invoice Fraud
Training employees to recognize the warning signs is a critical layer of defense. While attackers are becoming more sophisticated, they often leave subtle clues. Staff should be taught to be skeptical of emails that exhibit the following characteristics:
- Sudden Changes to Payment Details: Any email requesting a change to bank account information should be treated as high-risk and trigger an immediate verification process.
- Sense of Urgency or Pressure: Emails that insist on immediate payment to avoid penalties or that use phrases like "urgent request" are classic social engineering tactics.
- Slight Changes in Email Addresses: Scrutinize the sender's full email address. Look for subtle misspellings, character substitutions (like 'l' for '1'), or different top-level domains.
- Unusual Language or Formatting: If the tone, grammar, or formatting of an email is inconsistent with previous communications from that vendor, it's a major red flag.
- Mismatched Information: Check that the invoice number, amount, and purchase order details align with internal records. Attackers may make mistakes or use generic templates.
Being able to spot a phishing email or text is a foundational skill for every employee, but BEC requires an even higher level of vigilance due to its targeted nature.
| Red Flag Example | What to Look For |
|---|---|
| Lookalike Domain | `billing@vendor-ltd.com` vs. `billing@vendortld.com` (I and l are swapped) |
| Urgent Language | "This invoice is overdue and must be paid today to avoid service disruption." |
| Change in Procedure | "Please disregard previous instructions. All future payments must go to this account." |
| Unusual Bank Location | A US-based supplier suddenly provides a bank account in another country. |
| Generic Salutation | An email from a long-term contact that starts with "Dear Sir/Madam." |
Building a Defense Against BEC Attacks
Protecting an organization from BEC invoice fraud requires a multi-layered approach that combines technology, robust procedures, and a well-trained workforce.
Technological Defenses
While BEC targets people, technology can help filter out many threats before they reach an inbox.
- Enforce Multi-Factor Authentication (MFA): This is the single most effective technical control against account compromise. Even if an attacker steals a password, they cannot access the email account without the second factor. Learn how to set up two-factor authentication properly across all corporate accounts, especially email.
- Deploy Advanced Email Security: Use an email security gateway that can analyze incoming emails for signs of phishing, spoofing, and malicious content. These tools can flag emails from external sources, display warnings about lookalike domains, and scan attachments for malware.
- Implement DMARC, DKIM, and SPF: These are email authentication standards that help prevent attackers from spoofing your own company's domain. They also help receiving mail servers verify that an email claiming to be from your organization is legitimate.
Procedural Defenses
Strong processes are your best defense against a threat designed to exploit human behavior.
- Mandate Out-of-Band Verification: Create a strict, non-negotiable policy that any request to change a vendor's payment information must be verified through a secondary channel. This means calling a known contact at the vendor using a phone number you have on file—never a number provided in the suspicious email.
- Segregation of Duties: If possible, structure your payment process so that the person who enters the invoice data is not the same person who approves and executes the final payment. This two-person check provides an opportunity for a second set of eyes to catch anomalies.
- Regularly Review Vendor Files: Periodically audit your vendor master file for old or inactive accounts and confirm payment details with your key suppliers.
Human Defenses
Your employees are the last line of defense. Empowering them with the right knowledge is crucial.
- Continuous Security Awareness Training: Don't rely on a single annual training session. Conduct regular, engaging training that uses real-world examples of BEC attacks. Simulate invoice fraud attempts to give employees hands-on practice in a safe environment.
- Foster a Culture of Skepticism: Create a work environment where employees feel empowered to pause and question any unusual or urgent financial request. Leadership must communicate that it is better to delay a payment for verification than to send money to a criminal. Reassure staff they will not be penalized for being cautious and reporting a potential threat.



