A common and costly fraud: someone monitors business email, then sends a message at the right moment asking for payment to a different bank account.
HOW IT USUALLY WORKS
An attacker gains access to a mailbox, often through a reused password, and watches quietly. When an invoice is due, they send a message from a lookalike domain, or from the real compromised mailbox, with new bank details. The payment goes to them.
WARNING SIGNS
A change of bank details arriving by email Urgency and pressure to pay before a deadline A sender address off by one character from the real one A reply-to address different from the from address A request to keep the transaction confidential
PROTECTING YOUR BUSINESS
Verify any change of payment details by telephone, using a number you already hold, never one from the email. Make that a written rule for whoever handles payments. Use 2FA on all mailboxes. Check periodically for forwarding rules you did not create, which is how attackers watch quietly. Register lookalike domains where the cost is justified.
IF YOU HAVE PAID
Contact your bank immediately, as speed determines whether funds can be recalled. Then secure the mailbox and report the incident.