Small business cyber safety
Invoice Fraud: The Two-Minute Check Before Changing Bank Details
A genuine-looking invoice can contain one false detail. This short routine helps a small business check changed payment instructions before the money leaves.
If an email says a supplier has changed bank accounts, do not update the details from that email alone. Pause the payment, find a phone number you already trust, and confirm the change with a person you know—or with the supplier through another independently verified contact.
That simple call matters even when the email address, invoice, amount and conversation thread all look correct. In business email compromise, a criminal may be reading a real mailbox or using a convincing look-alike address. The bank details can be the only false part.
The two-minute check
- Stop: do not edit the supplier record or approve the payment yet.
- Step outside the message: find the supplier’s number in your existing records, an earlier verified invoice, contract or official website—not in the email requesting the change.
- Speak to a known person: confirm the new BSB and account number verbally. If your normal contact is unavailable, use the supplier’s main number and ask to be transferred.
- Record the check: note who confirmed the change, when and through which independent contact path.
- Then update and pay: if anything does not match, stop and escalate rather than trying to resolve it inside the suspicious email thread.
“Two-minute check” is a practical name, not a time guarantee. A complicated change may take longer. The point is to make an independent check faster and easier than recovering a misdirected payment.
Why a perfect-looking invoice can still be fraudulent
The Australian Cyber Security Centre describes business email compromise as targeted phishing that abuses trust in ordinary business processes. Criminals may impersonate a representative, use a similar domain name or take control of a real employee or supplier mailbox.
That access can give them the context needed to wait for a real invoice, copy familiar language and send the request at the right time. Looking only for spelling mistakes or a strange logo is therefore not enough.
- The message may sit inside a genuine conversation thread.
- The invoice number, job description and amount may all be accurate.
- The sender may explain the change as a new bank, new accounting system or overdue correction.
- The request may create urgency by mentioning a late fee, delivery hold or end-of-day deadline.
The strongest test is not whether the email looks genuine. It is whether the payment change has been confirmed through a separate trusted path.
Make the check a business rule, not a judgement call
People are more likely to skip verification when they are busy, covering someone else’s role or trying to help an important supplier. A written rule removes the awkwardness.
A useful one-line policy is:
We do not create or change supplier bank details from an email alone. A staff member must verify the details through an independently sourced contact and record the check before payment.
For larger payments or new payees, add a second approval where your bank or accounting process supports it. Small businesses should set a threshold that fits their cash flow and staffing; the rule should be usable on an ordinary busy day, not only in theory.
What counts as an independent contact path?
The verification path must not depend on the same message that asked for the change.
- Better: a number already stored in your supplier record, a signed contract, an earlier verified invoice or the supplier’s official website.
- Weaker: replying to the same email, calling the number printed on the new invoice or using a signature block that arrived with the request.
- Not enough: asking the sender to confirm the details again by email. A criminal controlling the mailbox can simply say yes.
If a supplier calls you unexpectedly, you can still end the call and ring back using your existing records. This is not rude; it is a payment-control process that protects both businesses.
Do not rely on a token test payment by itself
Sending one dollar and asking for email confirmation can feel cautious, but it may still send money to the criminal’s account—and the criminal may be controlling the email reply. A test payment is not a substitute for independent verbal confirmation.
If your bank provides a payee-name matching or verification feature, use it as an additional warning signal. Do not treat any automated result as permission to skip your own call-back rule, particularly when the result is unavailable, partial or inconsistent.
If the payment has already gone
Act immediately. Do not wait until the supplier investigates its email.
- Call your bank or financial institution now. Ask for its fraud team and request an urgent recall or hold.
- Preserve the evidence. Keep the email, invoice, headers if available, payment receipt, phone notes and the exact account details used.
- Contact the real supplier through a trusted channel. Warn them that an account or business process may have been compromised.
- Report the incident through ReportCyber. Follow any additional instructions from your bank or police.
- Review email security. Check account access, forwarding rules, recovery details, connected applications and multi-factor authentication rather than assuming the problem was only the invoice.
Speed does not guarantee recovery, but delay gives the recipient more time to move the funds.
Reduce the chance of the next attempt succeeding
- Turn on multi-factor authentication for business email, banking, accounting and administrator accounts.
- Give staff clear authority to pause an unusual payment without being blamed for causing a delay.
- Use individual banking and accounting logins so approvals can be traced.
- Review supplier details periodically and remove obsolete contacts.
- Protect your own outgoing invoices and tell customers how you will communicate a genuine bank-detail change.
- Discuss suspicious requests in staff induction and repeat the drill before busy payment periods.
Sources and further reading
Frequently asked questions
What if the request comes from the supplier’s real email address?
Still verify it independently. A real mailbox may be compromised, allowing the criminal to read previous messages and reply from the genuine account.
Should every invoice require a phone call?
Not necessarily. The minimum rule should cover new suppliers, changed payment details and unusual or high-risk requests. Businesses can add thresholds and second approvals that fit their own payment process.