<15 min Response

20+ Years Experience

Cyber Essentials Certified

Check Your IT Score

Remote SOS Support

Invoice Fraud and Business Email Compromise: How It Works and How to Stop It

Illustration of a scam email used in invoice fraud and business email compromise

The short answer: Invoice fraud, also called mandate fraud, payment diversion fraud or business email compromise (BEC), is when a criminal gets between you and a genuine supplier and persuades you to pay a real invoice into their account, often using a hacked or spoofed email account. UK Finance recorded £41.3 million lost to invoice and mandate scams across 2,305 cases in 2025. The defence is part process, always confirming a change of bank details by phone on a number you already hold, and part IT: MFA, DMARC and alerts on suspicious mailbox rules.

Last updated: 1 October 2026. Checked against the UK Finance Annual Fraud Report 2026, NCSC guidance, the Payment Systems Regulator and Report Fraud on that date.

In this guide

What is invoice fraud and business email compromise?

Invoice fraud and business email compromise are names for the same family of scams, in which a criminal uses email to redirect a payment your business meant to make to someone else. Report Fraud, which replaced Action Fraud, puts it this way: “Mandate Fraud, also known as Payment Diversion Fraud (PDF) and Business Email Compromise (BEC), tends to affect businesses and customers where electronic financial transactions are taking place.”

UK Finance defines the most common version: “In an invoice or mandate scam, the victim attempts to pay an invoice to a legitimate payee, but the criminal intervenes to convince the victim to redirect the payment to an account they control.” The NCSC describes business email compromise more broadly as “a form of phishing attack where a criminal attempts to trick a senior executive (or budget holder) into transferring funds, or revealing sensitive information.”

TypeWhat happensWho it targets
Invoice or mandate fraudA supplier’s invoice is real, but an email tells you their bank details have changed. The new account belongs to the criminal.Accounts teams paying suppliers
CEO fraudAn email that appears to come from the managing director asks for an urgent payment, often while they are travelling or hard to reach.Finance staff and PAs
Conveyancing fraudCompletion funds are redirected after a solicitor’s or buyer’s email is compromised. See our guide to Friday afternoon fraud.Law firms, estate agents and home buyers
Common types of business email compromise. Definitions from UK Finance and Report Fraud.

How do criminals pull off business email compromise?

Most attacks follow the same pattern, and most steps leave something you can catch:

  1. They get into a mailbox. Often by phishing someone’s Microsoft 365 password, either yours or your supplier’s. See how to spot a phishing email.
  2. They read and wait. They learn who pays whom, how invoices are worded and when large payments are due.
  3. They hide their tracks. Microsoft says “Malicious inbox rules are common during business email compromise (BEC) and phishing campaigns and it’s important to monitor for them consistently.” Attackers set rules to delete, move or forward messages so the real person never sees the replies. Microsoft gives a typical example: “They create an inbox rule to forward all emails that contain keywords, such as ‘finance’ and ‘invoice’ in the subject or message body, to their mailbox.”
  4. They send the request. Either from the compromised mailbox itself, so it looks completely genuine, or from a lookalike domain one letter different from the real one.
  5. The money moves fast. Once a payment lands in the criminal’s account it is usually moved on quickly, which is why speed matters when you report it.

Here is what that request often looks like. Everything in this example is invented, but each warning sign is real.

Example: illustrative mock-upFictional companies
 Inbox · accounts@ashcombeinteriors.co.uk
2RE: Invoice QT-4821 and updated bank details
KH
Karen Holt, Quillfield Timber 1<accounts@quillfie1dtimber.co.uk>
To: Sam Turner · Today 15:42

Hi Sam,

Thanks for confirming the order. Just to let you know, 3our bank details have changed following an audit and our old account is now closed. Please make the payment for invoice QT-4821 (£18,450.00) to the account below.

Account nameQuillfield Timber LtdSort code12-34-56Account number87654321

4Could this go in today’s payment run? We are holding your delivery until it clears.

5I’m on site all afternoon with no signal, so email is best. Just reply here once it has been sent.

Many thanks,
Karen

Five warning signs in this email
1
A lookalike address“quillfie1d” uses the number 1 in place of the letter l. The display name looks perfect.
2
It replies to a real threadThe invoice number is genuine because the criminal has been reading the emails.
3
New bank detailsGenuine suppliers rarely change accounts, and almost never by email.
4
Pressure to pay todayUrgency is there to stop you checking.
5
“Please don’t call”They need the conversation to stay in email, where they control it.
What to do: do not reply. Phone the supplier on a number you already hold and ask them to confirm their bank details.
All names, addresses and account details are invented for illustration.

And this is how the criminal stops anyone noticing: rules quietly set up inside the victim’s own mailbox, of the kind Microsoft warns about.

Example: illustrative mock-upFictional mailbox
 Mail settings · Rules
Inbox rules
Rules run automatically on every message that arrives.
Newsletters
IfFrom contains newsletter
ThenMove to Newsletters
1.
IfSubject or body includes invoicebankpaymentremittanceQuillfield
Then2Move to RSS Subscriptions and mark as read
3..
IfSubject or body includes invoicefinance
ThenForward to k.holt.accounts@freemail.example
What the criminal set up
1
A rule with no real nameA dot or two is easy to miss in a list of rules.
2
Replies are hiddenWhen the real supplier writes “we never changed our bank details”, it lands in a folder nobody opens, already marked as read.
3
Copies go outsideFinance emails are forwarded to an outside address, so the criminal keeps watching even after a password reset.
What to do: check your mailbox rules today, and ask your IT provider to alert you whenever a new rule or forward is created.
Based on the patterns Microsoft describes in its guidance on malicious inbox rules. All names are invented.

How common is invoice fraud in the UK?

UK Finance’s Annual Fraud Report 2026 recorded these losses for 2025:

Scam type (2025)CasesValue lostReturned to victims
Invoice and mandate fraud2,305£41.3m£20.0m
CEO fraud197£5.6m£1.1m
All authorised push payment fraud248,070£576.4mNot shown here
Source: UK Finance Annual Fraud Report 2026. Of the £576.4m total, £75.6m was lost by businesses.

These figures only count cases reported to banks. The Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses had a cyber security breach or attack in the last 12 months, that phishing was by far the most common, experienced by 38% of businesses, and that 12% reported others impersonating their organisation in emails or online.

Will the bank refund invoice fraud?

Possibly, but most businesses should not count on it. Since 7 October 2024, payment firms have generally had to reimburse eligible victims of authorised push payment scams, but the Payment Systems Regulator says the protections apply to individuals, microenterprises and charities. Claims are capped at £85,000, must be made within 13 months of the payment, and firms can apply an optional £100 excess. Businesses that are not microenterprises are outside that scheme, so prevention matters far more than recovery.

Confirmation of Payee helps. It is an account name-checking service that lets your bank check the name on the account before you pay. Treat a “close match” or “no, the name is wrong” result, or a failed check, as a reason to stop and phone the supplier, never as a box to click through.

If a payment does get as far as your banking app, this is the warning to look for:

Example: illustrative mock-upGeneric banking app
15:515G
‹ New payee
Name on the account
Quillfield Timber Ltd
Sort code
12-34-56
Account number
87654321
1The name is a close match

The account is held in a slightly different name. Check with the person you are paying before you continue.

Name on the account: QUILLFIELD TRADING LTD
Edit payee details
2Continue anyway
Confirmation of Payee is your last warning
Banks check the name you type against the name on the account before you pay. A criminal’s account may be held in a name close to the real supplier’s.
1
“Close match” or “the name is wrong”Treat either result as a reason to stop, not a box to tick.
2
“Continue anyway” is where the money goesIf you carry on after a warning, getting the money back may be harder.
What to do: stop, and phone the supplier on a number you already hold to confirm the account name and number.
Generic banking app. Wording varies between banks. All names and account details are invented.

How do you stop invoice fraud and business email compromise?

You stop it with two layers: a payment process that does not trust email, and IT controls that make mailboxes hard to take over. Report Fraud’s advice on mandate fraud is to contact the supplier directly “using their official and verifiable contact details to corroborate the payment request”, to “Establish robust internal processes for handling changes to payment details”, and to keep invoices and payment documents accessible only to the staff who need them.

Process controls

  • Call back on a number you already hold before acting on any change of bank details, never the number in the email asking for the change.
  • Limit who can change payee details and require a second person to approve the change.
  • Send a small test payment to new bank details and confirm it arrived by phone before sending the full amount.
  • Slow down urgent requests. Pressure to pay today, secrecy and “I can’t talk, just do it” are warning signs, especially from senior staff.

Put together, the process is simple enough to pin up next to every desk that pays invoices:

A simple process that stops itATS Connection
The call-back check
Use it every time a supplier, colleague or client asks you to pay to new or changed bank details.
1
PauseDo not reply to the email or use any phone number or link in it.
2
Call a number you already holdFrom your records, a past invoice or the supplier’s own website.
3
Confirm the detailsRead back the account name, sort code and number you were sent.
4
Second approvalA different person signs off the change before anyone pays.
5
Test, then paySend a small amount, confirm it arrived by phone, then send the rest.
STOPIf anyone pushes you to skip a step because it is urgent, treat that as the warning sign.

IT controls

ControlWhat it stops
MFA on every mailbox. The NCSC calls two-step verification “one of the most effective ways to protect online accounts when passwords are still in use”.Criminals logging in with a phished password
SPF, DKIM and DMARC on your domain. DMARC “allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks.”Criminals sending email that pretends to come from your exact domain
Alerts on new inbox and forwarding rulesAttackers hiding replies or copying your finance emails to themselves
Impersonation and lookalike-domain protectionEmails from domains one letter different from your suppliers or your directors
Staff phishing awarenessPassword theft, a common starting point
IT controls against business email compromise.

Lookalike addresses are the easiest of these to miss at a glance:

Example: illustrative mock-upFictional companies
Spot the fake sender
Criminals register addresses that look almost identical to a supplier’s. Read the part after the @ slowly.
✓
The real supplier
accounts@quillfieldtimber.co.uk
✕
accounts@quillfie1dtimber.co.uk
The number 1 in place of the letter l
✕
accounts@quillfieldtirnber.co.uk
“r” and “n” together look like an “m”
✕
accounts@quillfieldtimbers.co.uk
One extra letter
✕
accounts@quillfield–timber.co.uk
A hyphen added
✕
accounts@quillfieldtimber.com
A different ending
✕
Quillfield Timber <qt.accounts@freemail.example>
The right display name on a free webmail address
Impersonation protection in Microsoft 365 can flag lookalike domains, but a careful eye still matters. All names are invented.

Several of these need configuring in Microsoft 365, and some depend on your licence. Our Microsoft 365 Business Premium guide explains which plan includes what, and our managed cyber security service can help set them up.

What should you do if you have paid a fraudster?

  1. Call your bank immediately, on the number on its website or your card, and ask it to try to recall the payment. Minutes count.
  2. Report it to Report Fraud, the national reporting service for fraud and cyber crime in England, Wales and Northern Ireland, which replaced Action Fraud.
  3. Secure the mailbox. Reset the password, sign out all sessions, remove any inbox or forwarding rules you did not create and check which other accounts use the same password.
  4. Warn the supplier and your customers. If your mailbox was compromised, the criminal may try the same trick on people who trust your email address.
  5. Check whether it is a data breach. If personal data was exposed and the breach is notifiable, it must be reported to the ICO without undue delay and no later than 72 hours after becoming aware of it (ICO).

Frequently asked questions

What is the difference between invoice fraud and business email compromise?

They overlap. Business email compromise is the method, using a hacked or spoofed email account to trick someone, and invoice or mandate fraud is the most common result, a genuine invoice paid into the criminal’s account. Report Fraud uses mandate fraud, payment diversion fraud and business email compromise as alternative names for the same scam (Report Fraud).

Will my bank refund invoice fraud?

The mandatory reimbursement rules that started on 7 October 2024 apply to individuals, microenterprises and charities, with claims capped at £85,000 and made within 13 months (Payment Systems Regulator). Businesses that are not microenterprises are outside that scheme, so speak to your bank immediately and focus on prevention.

How much do UK businesses lose to invoice fraud?

UK Finance recorded £41.3 million lost to invoice and mandate scams across 2,305 cases in 2025, £28.0 million of it from business accounts, with £20.0 million returned to victims overall (UK Finance Annual Fraud Report 2026).

Can Microsoft 365 stop business email compromise?

It can block many of these attacks if it is configured properly: MFA on every account, DMARC on your domain, impersonation protection and alerts on suspicious inbox and forwarding rules. Several need configuring, and none of them replaces a call-back check before you change a supplier’s bank details.

Where do I report invoice fraud?

Call your bank first, then report it to Report Fraud at reportfraud.police.uk, which replaced Action Fraud for England, Wales and Northern Ireland (City of London Police).

Sources

Free • 12 minutes • Written PDF report

Who actually holds the keys to your systems?

List the systems your business runs, answer plain-English questions about how they are controlled, and get a report with a red, amber and green rating for every area and what to fix first. Nothing on your systems is touched.

Cyber Essentials certified · Microsoft Partner · rated 5.0 on Google

Take the free IT Security Review

Free • No obligation • Senior engineer • 30 minutes

Want a straight answer about your own IT?

We look after IT, cyber security and phones for businesses across Sussex and the UK, on a fixed monthly price from £30 per user. Book a free review and a senior engineer will tell you plainly what is worth fixing first.

Your free IT review

  • Review WiFi, devices and network infrastructure
  • Benchmark Microsoft 365 and security posture
  • Assess backup, recovery and operational continuity
  • Map a clear, costed IT & security roadmap

Book your free IT & cyber review



Free, no obligation. We only use your details to arrange the review. Privacy policy.