OpusBUSINESS EXPERT

The most expensive email your business will receive says a supplier's bank details have changed

Andy Shepherd6 min read

It arrives on a Tuesday afternoon, in the middle of a thread that has been running for weeks. Same sender, same signature, quoting the invoice you were expecting, for the amount you were expecting. One new line: we have changed banks, please use these details for the outstanding balance.

Nothing about it looks wrong, because nothing about it is fake in the way you have been taught to check for. The police call it payment diversion fraud, and it is the one that takes five figures in a single transfer.

UK Finance counted 2,305 invoice and mandate scam cases against UK businesses and individuals in 2025, with £41.3 million lost. That is just under £18,000 a case, on the average, and the police are blunt that this fraud is targeted, so individual losses run far higher than for most scams. About half the money came back that year. Half did not.

£41.3m
Lost to invoice and mandate scams in 2025, per UK Finance
£18k
The average case. Individual losses run far higher

Why checking the sender no longer works

The advice everyone has heard is to look closely at the email address and watch for odd spelling. That worked when the fraud was a lookalike domain and a rushed forgery. The current version is better than that.

Often the email genuinely comes from your supplier's mailbox. A criminal has been inside it for weeks, reading, learning the rhythm of the relationship, waiting for an invoice worth diverting. When the message comes, it comes mid-thread, in the supplier's own voice, from the supplier's real address. It passes every authentication check, because it is authentic. The only false thing in it is the sort code.

Your supplier does not know. That is not carelessness on their part; it is the design of the crime.

So the checks aimed at the message fail, the same way they fail against a convincing HMRC fake. Judging the wording is a losing game. What works is refusing to let any message, however genuine, carry that particular instruction.

The rule, in one sentence

No bank details change on the strength of a message. Ever.

Not an email, not a text, not a PDF on a letterhead, not a phone call that came to you. A change of account details gets verified by ringing the supplier on a number you already held before the message arrived. The number in the email footer does not count; if the mailbox is compromised, the footer is the criminal's to edit.

This costs one phone call per change of details, which for most businesses is a few calls a year. Against an £18,000 average loss, it is the cheapest control you will ever run. Write it down, tell whoever pays the invoices, and have them tell you when it happens, because the version of this fraud aimed at your bookkeeper is an email from you, urgently, asking them to pay someone.

What a compromised mailbox actually does

The advice above works even if you never learn how the crime is staged. But the staging is worth knowing, because it is visible if someone looks.

A criminal working from inside a mailbox needs the real owner not to notice the conversation happening in their name. The standard method is an inbox rule, created quietly in Outlook, that moves replies from the target out of sight the moment they arrive. Microsoft's own incident guidance names the favourite hiding places: rules that shunt mail into the Notes, Junk Email or RSS Subscriptions folders, or forward it to an outside address and delete it. Nobody opens their RSS Subscriptions folder. That is why it is chosen.

So there is a short list of things worth checking in any Microsoft 365 mailbox that handles money, and after any suspicious episode:

  • Inbox rules the owner does not recognise, especially ones that move or delete mail
  • Forwarding to any external address, in the mailbox settings and in rules
  • Sign-ins from places the owner has not been

Microsoft now blocks automatic external forwarding by default in Exchange Online, which closes one door. It does not stop a rule hiding replies inside the mailbox, and it does nothing if nobody ever reviews what rules exist. On the estates we run, that review is routine rather than a response to disaster, which is the difference between finding a rule days after it was created and finding it in the loss adjuster's report.

It points both ways

Everything above assumes the compromised mailbox is your supplier's. Turn it around.

If your mailbox is the one that gets opened, the fraudulent email goes to your customer, quoting your invoice, in your voice. They pay the criminal, then they do not pay you, and the argument about who bears the loss is had between two businesses that used to trust each other. Your email security is, in a very practical sense, part of what your customers are buying.

The domain half of that, stopping criminals sending as you from the outside, is an afternoon of DNS work most small firms have not done. The mailbox half is multi-factor authentication and someone who actually looks at the estate. Neither is exotic. Both are cheaper than the phone call that starts "we paid the account on your email".

If the money has already gone

Speed is nearly everything. Banks can sometimes freeze funds in the receiving account, but the window is measured in hours.

  1. 01Ring your bank immediately and ask them to contact the receiving bank to freeze the funds
  2. 02Report it to Action Fraud, online or on 0300 123 2040
  3. 03Tell the supplier through a channel that is not email, because their mailbox may be the crime scene
  4. 04Keep every message; do not tidy up
  5. 05Have the mailboxes on both sides checked for rules, forwarding and sign-ins before anyone declares it over

The last step is the one that gets skipped. A payment redirected once is a mailbox that was open, and a mailbox that was open stays a liability until someone has been through it. We do that check for clients, and the whole review of a small Microsoft 365 estate takes less time than the first phone call to the bank. Ask us before you need the second kind of help rather than after.


We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.

If any of this sounds like your business, we will tell you plainly whether we can help.

We would like to use analytics cookies to understand how this site is used, advertising cookies to measure our ads, and to load our office map from Google. None of them loads on its own unless you accept — though Google Tag Manager itself loads either way, with every category switched off. The map also has a button of its own. Read our cookie policy