How the attack works
- Supplier impersonation: from a lookalike domain or a genuinely compromised supplier mailbox, the attacker requests a bank-detail update.
- The legitimate invoice arrives — real goods, real amounts — and is paid to the new, fraudulent account.
- Discovery lag: the real supplier chases the unpaid invoice weeks later; by then funds are gone.
Common variants
- Detail-change fraud (the dominant pattern above).
- Phantom vendor: a fake supplier record with a stream of small, plausible invoices.
- Duplicate/inflated invoicing by an insider or colluding vendor.
- Vishing-assisted: a phone call "from the supplier" — sometimes voice-cloned — legitimizes the emailed change. See vishing.
Prevention
Verify every payment-detail change by callback to the number already in your vendor master (never the one on the invoice), hold affected payments until verification is logged, and reconcile supplier statements monthly. Full walkthrough: invoice fraud detection.