Business email compromise invoice fraud is a scam in which a criminal gains control of a real email account, waits for a legitimate invoice or payment request to pass through, and changes the bank details so the money lands in an account they control. There is no malware to detect and no fake website to spot. The email is real, the invoice is real, and only the routing number is wrong, which is why it is widely reported as the most financially damaging cybercrime year after year.
How does business email compromise invoice fraud actually work?
We have helped several Treasure Coast businesses unwind these incidents, and the pattern is remarkably consistent. It unfolds in five stages.
1. Getting into a mailbox
The attacker needs a foothold in one real account. Usually it starts with a convincing sign-in page sent by email, sometimes disguised as a shared document or a voicemail notification. The victim enters their password, and in the newer variants, the fake page relays the multi-factor code in real time as well. Other entry points include a password reused from a breached consumer site, or an old account for a former employee that was never disabled.
2. Staying quiet
This is the part most owners do not expect. The attacker does not announce themselves. They create an inbox rule that forwards copies of messages containing words like invoice, payment, wire, or closing to an outside address, and a second rule that moves replies from the bank or the vendor into a folder nobody checks. Then they read. Weeks can pass while they learn who approves payments, which vendors are paid by wire, and what the normal email tone looks like.
3. Choosing the moment
They wait for a large, expected payment: a progress draw on a construction project, a real estate closing, a quarterly vendor invoice, a settlement disbursement. Expected payments are ideal because nobody questions them.
4. The swap
The attacker intercepts the genuine invoice and re-sends it with new bank details, or sends a polite note from the compromised account explaining that the company recently changed banks. Sometimes they register a look-alike domain that differs by one letter so the thread continues even if the original account is locked. The receiving party updates the vendor record and pays.
5. Cash out
The money is moved out of the receiving account within hours, often through several intermediate accounts and into cryptocurrency. Recovery is possible only if the bank is notified fast, typically within one to two business days.
Who is targeted on the Treasure Coast?
Any business that sends or receives large payments by wire or ACH is a candidate, but a few local industries are hit disproportionately.
- Construction and trades. Progress payments between general contractors, subcontractors, and suppliers are large, frequent, and often coordinated by email between small offices.
- Real estate closings. Title companies, attorneys, agents, and buyers exchange wiring instructions by email under time pressure. Seasonal residents closing on homes from out of state are especially vulnerable because they may never meet the closing agent in person.
- Law firms. Trust account disbursements and settlement payments are exactly the kind of one-time, high-value transfer attackers look for.
- Medical and dental practices. Attackers impersonate equipment vendors or the practice owner asking the office manager to update payroll direct deposit.
- HOAs and nonprofits. Volunteer boards and part-time treasurers approve payments by email with limited verification.
Attackers do not care that your business is small. They care that you pay vendors, and small offices have fewer people looking at each payment.
What are the warning signs of a compromised mailbox?
Because the criminal is trying to stay invisible, the signs are subtle:
- Vendors or clients say they replied to an email you never saw.
- Inbox rules you did not create, especially ones that forward externally or mark messages as read and move them.
- Sign-in alerts from unfamiliar locations, or a new authentication app registered on the account.
- A sent-items folder that is missing messages other people received.
- A sudden request to change bank details, or a change followed by a request to keep it confidential or to hurry.
What controls actually stop invoice fraud?
No single tool solves this because the problem spans email, identity, and accounting procedures. The combination below is what we put in place for clients through our cybersecurity services, and it is what cyber-insurance applications increasingly require.
Identity controls
- Multi-factor authentication on every mailbox, with phishing-resistant methods such as passkeys or hardware keys for anyone who approves payments.
- Conditional access that blocks sign-ins from countries where you have no staff and flags impossible travel.
- Prompt offboarding so former employee accounts cannot be used as a doorway.
Mailbox controls
- Disable automatic forwarding to external addresses at the tenant level, and alert on any new inbox rule.
- Tag external email visibly so a look-alike domain stands out.
- Enable SPF, DKIM, and DMARC so your own domain cannot easily be spoofed against your customers.
- Monitor sign-in and mailbox audit logs with a service that actually reads them.
Payment procedures
Technology reduces the risk; procedure eliminates most of what remains. Any change to a vendor's bank details, payroll direct deposit, or wiring instructions must be verified by a phone call to a number you already have on file, never one in the email. Require two people to approve outgoing wires above a threshold you set. Put both rules in writing, train staff on them, and make it culturally safe for a bookkeeper to slow down a payment even when the owner appears to be asking for it.
What should you do if you have already paid a fraudulent invoice?
Speed matters more than anything else.
- Call your bank immediately and ask for a recall or a fraud hold on the wire.
- File a report with the FBI's Internet Crime Complaint Center, which coordinates recovery efforts with banks.
- Reset passwords, revoke active sessions, and remove unknown inbox rules and authentication methods on every account involved.
- Notify the other party in the transaction; their mailbox may be the one that was compromised.
- Preserve the emails and headers for the investigation and your insurer.
If you need help with any of that, our incident response team is available around the clock and works with local banks and counsel regularly.
The best time to review payment controls is before the next big invoice goes out. MainSail Data offers a free email security and payment-process review for businesses from Vero Beach to Stuart. Call (772) 794-1194 or reach out online to schedule it.

