The short answer: Invoice fraud, also called mandate fraud, payment diversion fraud or business email compromise (BEC), is when a criminal gets between you and a genuine supplier and persuades you to pay a real invoice into their account, often using a hacked or spoofed email account. UK Finance recorded £41.3 million lost to invoice and mandate scams across 2,305 cases in 2025. The defence is part process, always confirming a change of bank details by phone on a number you already hold, and part IT: MFA, DMARC and alerts on suspicious mailbox rules.
Last updated: 1 October 2026. Checked against the UK Finance Annual Fraud Report 2026, NCSC guidance, the Payment Systems Regulator and Report Fraud on that date.
In this guide
- What is invoice fraud and business email compromise?
- How do criminals pull it off?
- How common is it?
- Will the bank refund you?
- How to stop it
- What to do if you have paid a fraudster
- Frequently asked questions
What is invoice fraud and business email compromise?
Invoice fraud and business email compromise are names for the same family of scams, in which a criminal uses email to redirect a payment your business meant to make to someone else. Report Fraud, which replaced Action Fraud, puts it this way: “Mandate Fraud, also known as Payment Diversion Fraud (PDF) and Business Email Compromise (BEC), tends to affect businesses and customers where electronic financial transactions are taking place.”
UK Finance defines the most common version: “In an invoice or mandate scam, the victim attempts to pay an invoice to a legitimate payee, but the criminal intervenes to convince the victim to redirect the payment to an account they control.” The NCSC describes business email compromise more broadly as “a form of phishing attack where a criminal attempts to trick a senior executive (or budget holder) into transferring funds, or revealing sensitive information.”
| Type | What happens | Who it targets |
|---|---|---|
| Invoice or mandate fraud | A supplier’s invoice is real, but an email tells you their bank details have changed. The new account belongs to the criminal. | Accounts teams paying suppliers |
| CEO fraud | An email that appears to come from the managing director asks for an urgent payment, often while they are travelling or hard to reach. | Finance staff and PAs |
| Conveyancing fraud | Completion funds are redirected after a solicitor’s or buyer’s email is compromised. See our guide to Friday afternoon fraud. | Law firms, estate agents and home buyers |
How do criminals pull off business email compromise?
Most attacks follow the same pattern, and most steps leave something you can catch:
- They get into a mailbox. Often by phishing someone’s Microsoft 365 password, either yours or your supplier’s. See how to spot a phishing email.
- They read and wait. They learn who pays whom, how invoices are worded and when large payments are due.
- They hide their tracks. Microsoft says “Malicious inbox rules are common during business email compromise (BEC) and phishing campaigns and it’s important to monitor for them consistently.” Attackers set rules to delete, move or forward messages so the real person never sees the replies. Microsoft gives a typical example: “They create an inbox rule to forward all emails that contain keywords, such as ‘finance’ and ‘invoice’ in the subject or message body, to their mailbox.”
- They send the request. Either from the compromised mailbox itself, so it looks completely genuine, or from a lookalike domain one letter different from the real one.
- The money moves fast. Once a payment lands in the criminal’s account it is usually moved on quickly, which is why speed matters when you report it.
Here is what that request often looks like. Everything in this example is invented, but each warning sign is real.
Hi Sam,
Thanks for confirming the order. Just to let you know, 3our bank details have changed following an audit and our old account is now closed. Please make the payment for invoice QT-4821 (£18,450.00) to the account below.
4Could this go in today’s payment run? We are holding your delivery until it clears.
5I’m on site all afternoon with no signal, so email is best. Just reply here once it has been sent.
Many thanks,
Karen
And this is how the criminal stops anyone noticing: rules quietly set up inside the victim’s own mailbox, of the kind Microsoft warns about.
How common is invoice fraud in the UK?
UK Finance’s Annual Fraud Report 2026 recorded these losses for 2025:
| Scam type (2025) | Cases | Value lost | Returned to victims |
|---|---|---|---|
| Invoice and mandate fraud | 2,305 | £41.3m | £20.0m |
| CEO fraud | 197 | £5.6m | £1.1m |
| All authorised push payment fraud | 248,070 | £576.4m | Not shown here |
These figures only count cases reported to banks. The Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses had a cyber security breach or attack in the last 12 months, that phishing was by far the most common, experienced by 38% of businesses, and that 12% reported others impersonating their organisation in emails or online.
Will the bank refund invoice fraud?
Possibly, but most businesses should not count on it. Since 7 October 2024, payment firms have generally had to reimburse eligible victims of authorised push payment scams, but the Payment Systems Regulator says the protections apply to individuals, microenterprises and charities. Claims are capped at £85,000, must be made within 13 months of the payment, and firms can apply an optional £100 excess. Businesses that are not microenterprises are outside that scheme, so prevention matters far more than recovery.
Confirmation of Payee helps. It is an account name-checking service that lets your bank check the name on the account before you pay. Treat a “close match” or “no, the name is wrong” result, or a failed check, as a reason to stop and phone the supplier, never as a box to click through.
If a payment does get as far as your banking app, this is the warning to look for:
The account is held in a slightly different name. Check with the person you are paying before you continue.
How do you stop invoice fraud and business email compromise?
You stop it with two layers: a payment process that does not trust email, and IT controls that make mailboxes hard to take over. Report Fraud’s advice on mandate fraud is to contact the supplier directly “using their official and verifiable contact details to corroborate the payment request”, to “Establish robust internal processes for handling changes to payment details”, and to keep invoices and payment documents accessible only to the staff who need them.
Process controls
- Call back on a number you already hold before acting on any change of bank details, never the number in the email asking for the change.
- Limit who can change payee details and require a second person to approve the change.
- Send a small test payment to new bank details and confirm it arrived by phone before sending the full amount.
- Slow down urgent requests. Pressure to pay today, secrecy and “I can’t talk, just do it” are warning signs, especially from senior staff.
Put together, the process is simple enough to pin up next to every desk that pays invoices:
IT controls
| Control | What it stops |
|---|---|
| MFA on every mailbox. The NCSC calls two-step verification “one of the most effective ways to protect online accounts when passwords are still in use”. | Criminals logging in with a phished password |
| SPF, DKIM and DMARC on your domain. DMARC “allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks.” | Criminals sending email that pretends to come from your exact domain |
| Alerts on new inbox and forwarding rules | Attackers hiding replies or copying your finance emails to themselves |
| Impersonation and lookalike-domain protection | Emails from domains one letter different from your suppliers or your directors |
| Staff phishing awareness | Password theft, a common starting point |
Lookalike addresses are the easiest of these to miss at a glance:
Several of these need configuring in Microsoft 365, and some depend on your licence. Our Microsoft 365 Business Premium guide explains which plan includes what, and our managed cyber security service can help set them up.
What should you do if you have paid a fraudster?
- Call your bank immediately, on the number on its website or your card, and ask it to try to recall the payment. Minutes count.
- Report it to Report Fraud, the national reporting service for fraud and cyber crime in England, Wales and Northern Ireland, which replaced Action Fraud.
- Secure the mailbox. Reset the password, sign out all sessions, remove any inbox or forwarding rules you did not create and check which other accounts use the same password.
- Warn the supplier and your customers. If your mailbox was compromised, the criminal may try the same trick on people who trust your email address.
- Check whether it is a data breach. If personal data was exposed and the breach is notifiable, it must be reported to the ICO without undue delay and no later than 72 hours after becoming aware of it (ICO).
Frequently asked questions
What is the difference between invoice fraud and business email compromise?
They overlap. Business email compromise is the method, using a hacked or spoofed email account to trick someone, and invoice or mandate fraud is the most common result, a genuine invoice paid into the criminal’s account. Report Fraud uses mandate fraud, payment diversion fraud and business email compromise as alternative names for the same scam (Report Fraud).
Will my bank refund invoice fraud?
The mandatory reimbursement rules that started on 7 October 2024 apply to individuals, microenterprises and charities, with claims capped at £85,000 and made within 13 months (Payment Systems Regulator). Businesses that are not microenterprises are outside that scheme, so speak to your bank immediately and focus on prevention.
How much do UK businesses lose to invoice fraud?
UK Finance recorded £41.3 million lost to invoice and mandate scams across 2,305 cases in 2025, £28.0 million of it from business accounts, with £20.0 million returned to victims overall (UK Finance Annual Fraud Report 2026).
Can Microsoft 365 stop business email compromise?
It can block many of these attacks if it is configured properly: MFA on every account, DMARC on your domain, impersonation protection and alerts on suspicious inbox and forwarding rules. Several need configuring, and none of them replaces a call-back check before you change a supplier’s bank details.
Where do I report invoice fraud?
Call your bank first, then report it to Report Fraud at reportfraud.police.uk, which replaced Action Fraud for England, Wales and Northern Ireland (City of London Police).
Sources
- UK Finance, Annual Fraud Report 2026 (covering 2025)
- UK Finance, Annual Fraud Report 2026 press release
- Report Fraud, Mandate fraud
- City of London Police, Report Fraud service goes live (4 December 2025)
- NCSC, Business email compromise: dealing with targeted phishing emails
- NCSC, Email security and anti-spoofing
- NCSC, Small organisations guide: secure your important online accounts
- Payment Systems Regulator, APP fraud reimbursement protections
- Pay.UK, Confirmation of Payee
- Microsoft, Alert grading for suspicious inbox manipulation rules
- Microsoft, Alert grading for suspicious inbox forwarding rules
- DSIT, Cyber Security Breaches Survey 2025/2026
- ICO, Personal data breaches: a guide
Free • 12 minutes • Written PDF report
Who actually holds the keys to your systems?
List the systems your business runs, answer plain-English questions about how they are controlled, and get a report with a red, amber and green rating for every area and what to fix first. Nothing on your systems is touched.
Cyber Essentials certified · Microsoft Partner · rated 5.0 on Google
