Cybersecurity

Invoice fraud: how to prevent banking detail scams

An invoice can look genuine and still send your payment to the wrong account. The strongest defence is a payment process that does not rely on one email.

Criminals may alter an invoice, impersonate a supplier or gain access to a real mailbox. They then ask the business to use different banking details or send a replacement invoice with their account number.

How invoice fraud happens

A supplier mailbox is compromised

A criminal gains access to a real mailbox and watches a genuine conversation. A fraudulent payment request can then arrive from the correct email account and include accurate information about the supplier or transaction.

A similar domain is used

The sender registers a domain that looks close to the real one. A missing letter, extra word or different ending can be easy to miss.

The display name hides the address

An email may show a familiar person or company name while the actual sending address belongs to someone else.

An invoice or letter is altered

The document may copy the supplier’s logo and format but contain a different account number.

These methods can be combined. A neat email, a familiar signature and a real invoice number do not prove that the payment details are correct.

Warning signs

Stop and verify when:

  • Banking details have changed
  • A new beneficiary must be loaded
  • The request is urgent
  • You are asked to ignore an earlier invoice or message
  • The sender address is slightly different
  • The contact number in the message is new
  • The account holder name does not match what you expect
  • The normal approval process is being bypassed
  • The wording or format is unusual

A warning sign does not prove fraud. It is a reason to check before paying.

Use a separate channel to verify changes

Call the supplier using a number already held in your records or published on a website you reached independently. Do not use the telephone number in the message that requested the change.

Ask the supplier to confirm the account holder, bank and account number. Record who confirmed the change and when.

This rule should apply even when the email comes from the supplier’s real address. A real mailbox can be compromised.

Put the payment process in writing

A basic process should state that:

  • Banking-detail changes require independent verification
  • A second person approves new or changed beneficiaries
  • The person requesting the change cannot be the only person approving it
  • Staff use known contact details for verification
  • Evidence of the check is kept with the payment record
  • Urgency does not cancel the process

If the bank provides an account-verification service, use it as an additional check. It does not replace direct confirmation with the supplier.

Help customers verify your invoices

Tell customers how banking-detail changes will be communicated and verified.

Do not rely on email alone to change our banking details. Confirm any change by calling the number already held in your records or the number published on kwik.support.

Use a stable contact page on the real company domain. Keep customer and supplier contact records current. A verification process is useful only when people can find a trusted number.

Protect the email environment

Payment controls remain necessary even when email security is in place. Useful technical controls include:

  • Multi-factor authentication for mailboxes
  • Review of suspicious forwarding and inbox rules
  • Alerts for unusual account access
  • Clear warnings for messages from outside the organisation
  • Appropriate inbound email filtering
  • SPF, DKIM and DMARC for the business domain

DMARC can help reduce successful spoofing of the exact domain shown in the From address. It does not stop lookalike domains, protect a compromised mailbox, inspect invoice content or prove that a payment request is genuine. Read how managed DMARC works.

If you receive a suspicious invoice

Before paying:

  1. Stop the payment process.
  2. Do not reply using contact details in the suspicious message.
  3. Call the supplier using a trusted number.
  4. Compare the beneficiary against your existing records.
  5. Send the message to the person responsible for IT or security.
  6. Preserve the email and attachment for review.

If a mailbox may be compromised, the authorised IT administrator should review sign-in activity, active sessions, forwarding settings and inbox rules. Passwords and access should be secured using the organisation’s incident process.

If money has already been paid

Act promptly:

  1. Contact your bank through its official fraud channel and explain that the payment was fraudulent.
  2. Ask what recall, tracing or account restriction process is available.
  3. Preserve the invoice, email, payment record and related communication.
  4. Contact the genuine supplier or customer using a trusted channel.
  5. Ask your IT provider to determine whether a mailbox or account was compromised.
  6. Report the crime to SAPS and keep the CAS number.
  7. Notify your insurer or legal adviser if required.

Recovery is not guaranteed. The bank and police will determine what action is possible.

Quick payment checklist

Before paying a new or changed beneficiary, confirm:

  • Did we expect this invoice?
  • Do the account details match our records?
  • Did we verify the change using a trusted contact number?
  • Did a second person approve the beneficiary?
  • Does the account holder name make sense?
  • Have we kept evidence of the verification?

If one answer is no, stop and check.

A sensible next step

Talk to Kwik Support

Tell us about the current setup, the problem you are trying to solve and the outcome your business needs.