Business email compromise is simple and effective. A criminal gains access to a supplier's email, or registers a look-alike address, then sends a genuine-looking message: our bank details have changed, please pay this invoice to the new account.
Warning signs
- A request to change bank details, especially close to a payment date.
- Urgency, or a request to keep it confidential.
- An address that is almost right: an extra letter, or a different ending.
- A message from a senior person asking finance to make an unusual transfer.
Simple controls that stop it
- Verify changes by phone, using a number you already hold, never the number in the email.
- Two people approve new beneficiaries and large payments.
- Turn on two-step verification for every email account, so a stolen password alone is not enough.
- Train staff to pause and check. Most of these frauds succeed because someone was rushed.
If it happens
Contact your bank immediately; the sooner they act, the better the chance of stopping the transfer. Report it to the Cyber Security Authority, change the affected passwords and check the mailbox for forwarding rules the attacker may have added.