A costly fraud that targets businesses through email.
HOW IT WORKS
An attacker gains access to a mailbox, often through a reused password, and watches quietly for weeks. When an invoice is due, they send a message with new bank details, either from a lookalike domain or from the genuine compromised mailbox. The payment goes to them.
WARNING SIGNS
A change of bank details arriving by email Pressure to pay quickly A sender address off by one character A reply-to address different from the from address A request to keep the transaction confidential
PROTECTING YOUR BUSINESS
Verify any change of payment details by telephone, using a number you already hold, never one from the email. Make this a written rule for whoever handles payments. Check periodically for forwarding rules nobody created. Use strong unique passwords on every mailbox. Consider registering obvious lookalike domains.
IF YOU HAVE PAID
Contact your bank immediately; speed determines whether funds can be recalled. Then secure the mailbox and tell everyone who might be targeted next.