ClickCerts
Back to all posts

The Invoice Was Real. The Bank Account Wasn't.

BEC cost businesses $3 billion last year at ~$123K per incident. How vendor payment fraud actually works, and the two habits that stop it.

August 20, 2026ClickCerts Team
The Invoice Was Real. The Bank Account Wasn't.

Here is how it usually goes.

Your bookkeeper gets an email from a vendor you've used for six years. Same logo. Same signature block. Same person she's traded emails with since 2021. The invoice attached is for work that actually happened, in an amount she was already expecting to pay.

There's one line of new information: we've switched banks, please update our remittance details. She updates them. She pays the invoice. Nothing feels wrong, because almost nothing is wrong. The vendor is real. The work is real. The invoice is real. The only fraudulent element in the entire transaction is nine digits of routing number.

Six weeks later the vendor calls to ask about the overdue balance.

The most expensive attack nobody talks about

Ransomware gets the headlines. Business email compromise gets the money.

The FBI's Internet Crime Complaint Center logged $3.04 billion in reported Business Email Compromise (BEC) losses last year, second only to investment fraud, and ahead of every other category of business-targeted crime. That came from 24,768 complaints, which works out to roughly $123,000 per reported incident.

Sit with that number for a second. Not $123,000 across a portfolio. $123,000 per event, per company, at whatever size that company happened to be. For a forty-person manufacturer, that's a quarter's profit gone in one afternoon.

And the money moves fast. The FBI notes that the overwhelming majority of BEC losses go out by wire or ACH, a payment rail that is built for speed, not for second thoughts. Once the funds land and get moved onward, recovery odds drop off a cliff. The FBI's Recovery Asset Team can freeze receiving accounts, but only if you report it quickly and only if the money hasn't already been moved out.

The window is measured in days. Sometimes hours.

Why your spam filter didn't catch it

Because there was nothing to catch.

Classic phishing carries technical tells: a spoofed domain, a mismatched reply-to, a malicious attachment, a link to a credential harvester. Filters are genuinely good at those now. Vendor payment fraud frequently carries none of them. Two common versions:

The compromised mailbox. The attacker isn't impersonating your vendor's controller. They're inside his mailbox, sitting quietly, reading the thread history. They know your payment terms, your invoice cadence, your project names. When they finally send the banking-change email, it originates from the legitimate domain, passes SPF and DKIM cleanly, and lands in an existing thread. There is no technical anomaly, because there is no technical attack against you.

The lookalike thread. A domain registered one character off, a lowercase L where there was an uppercase i, or .co instead of .com, with the full prior conversation pasted underneath. Your eye reads the thread, not the header.

Add AI to the mix and the last remaining tell disappears. The IC3 report's first-ever AI section logged 22,364 complaints and $893 million in associated losses. The old advice about clumsy grammar and awkward phrasing hasn't been useful for a while now.

You cannot filter your way out of this. There's nothing malicious in the message. The malice is in the instruction.

The two habits that actually work

The good news is that the defense here is unusually cheap and unusually specific. This isn't "be vigilant." It's two concrete behaviors.

One: banking changes get verified out-of-band, every time, no exceptions.

Someone in your organization picks up the phone and calls the vendor at a number you already had on file — from a prior invoice, from your ERP, from your own contact record. Never the number in the email requesting the change. Never a number in the email signature. If the mailbox is compromised, the attacker controls the signature too.

The whole verification takes ninety seconds. It has to be a rule rather than a judgment call, because the entire attack is engineered to make it feel unnecessary.

Two: the person who can change vendor banking details isn't the person who releases the payment.

Split those two functions across two people. It's basic separation of duties, the kind of control your auditor already expects on the accounting side, applied to the specific step attackers target. One compromised mailbox then isn't enough to move money.

If you're a small shop where the same person genuinely does both, the compensating control is a standing callback rule with a written record: date, who was called, what number, who confirmed. Boring, but it works.

Where the training piece fits

Here's the part that gets skipped: these habits only hold if the people executing them know why the rule exists.

A callback policy nobody has been walked through becomes a formality. The bookkeeper who understands that vendor mailboxes get compromised, and that the email may be genuinely authentic, calls the vendor. The bookkeeper who was handed a policy PDF in onboarding eighteen months ago approves the change, because the email looked completely normal — which it did, because it was.

That's the case for training on a real cadence rather than an annual box-check. Not because a video stops a wire, but because the person at the keyboard needs the reasoning fresh enough to override a request that looks entirely legitimate.

Worth noting who "the people" are here. Finance, AP, and anyone with vendor-record access are the ones being targeted. In most small companies that's three to five people who need this specific reasoning, sitting inside a general training program that covers everyone else on broader ground.

If it already happened

Move on all three of these at once, not in sequence:

Call your bank's fraud department and ask them to attempt a recall. Time is the only variable that matters. File a complaint at ic3.gov with the full wire details — that's what activates the Recovery Asset Team and their ability to freeze the receiving account. Then check whether the compromise was on your side: forwarding rules, inbox rules hiding replies, mailbox delegation, unfamiliar sign-ins. If it was your mailbox rather than theirs, the same attacker is very likely working your other vendors too.

And tell the vendor. They may not know they're compromised, and you're probably not the only customer in that mailbox.

The uncomfortable part

Nobody in this story did anything obviously dumb. The bookkeeper wasn't careless. She paid a real invoice to a vendor she trusted, using instructions that arrived through the normal channel.

That's what makes the attack work, and it's why "train people to spot suspicious emails" is the wrong. The email wasn't suspicious. The request type was.

So train on the request type. Any change to where money goes gets verified by voice, on a number you already had, by someone other than the person who releases the payment.

Every time. Even when — especially when — it looks completely routine.

ClickCerts delivers quarterly security awareness training that ends in a dated certificate for every employee, so you can show an auditor or a carrier exactly who was trained and when. We don't run phishing simulations; we document completed training. If you're building the proof side of your security program, talk to us.

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.