Invoice redirection fraud, also called business email compromise (BEC), works like this: a criminal hijacks or spoofs a company mailbox and slips in a fake change of bank account. The payment lands with the fraudster. What protects you is a call back to a known number and a two person approval rule.
How the account swap works
The scheme is simple, which is why it works. The attacker gets into the mailbox of one party in a deal, usually through a phished login and password. For days or weeks they only read: who pays whom, the amounts, the tone of the emails. When a real invoice appears in the thread, they send a message from the genuine or a near identical address saying the company changed banks and asking for payment to a new number. It all looks familiar, because it comes from someone who knows the context.
How to spot an attempt
The warning signs rarely show up alone:
- a sudden account change just before a payment is due,
- time pressure and a request for an urgent transfer outside the normal process,
- a new account in a different country than the supplier, often an IBAN outside their usual banking,
- a small difference in the email address, such as a swapped letter or a different domain,
- a request to confirm the change by email only, never by phone.
A correct PDF invoice proves nothing. An attachment is as easy to forge as the message body.
Rules that stop the payment before it leaves
The best defence is not technical, it is procedural. Confirm every change of payment details through a return channel: call the number you hold in your own records from earlier work, never the number in the suspicious email. This is out of band verification. Add a two person rule: a second person signs off every account change and every larger transfer. Check the IBAN itself: the bank country should match the supplier country, and a sudden move to an account in another state is a hard signal to hold the payment. We cover related settlement traps in our note on customs clearance and document handling.
The scale of the problem
What companies lose: according to the US FBI, BEC fraud caused about 2.77 billion dollars in losses in 2024 alone across 21,442 reports, and between 2022 and 2024 total losses reached nearly 8.5 billion dollars (source: FBI IC3). Europol notes that in one case against a single company the criminals moved 38 million euro within a few days (source: Europol).
What does to do in the first hour?
Speed decides the outcome. Call your bank at once and ask them to stop and try to recall the transfer. Contact the beneficiary bank to freeze the funds on the fraudster account. Warn the real counterparty through a channel other than the infected email, because their mailbox may be compromised. Preserve evidence: the original messages with full headers, the account number, the timestamps. Report the case to the police and to your national cyber incident response team. Change passwords and turn on two factor authentication on any mailbox that may have been breached.
Why the money rarely comes back
This is the hard part. Fraudsters push the funds through a chain of accounts in several countries and cash out within hours. If the report to the bank arrives late, the money is usually gone. That is why the whole value sits in prevention: one call to a known number costs a minute, while a lost transfer is often the full invoice amount. In freight, where payments move between shipper, carrier and consignee across countries, the risk is built into the way the work is done.
How do we limit this risk and how to ask us?
At OTSL we treat a change of payment details as an event that needs confirmation, not as ordinary mail. If you want to agree a safe settlement process or review a specific transaction, including the customs and document side, see our customs advisory, or write through our contact form. Always confirm bank details on a channel you know from earlier work.
Step by step
- Notice reception. You receive an email stating that a supplier has changed their bank account details.
- Payment hold. You pause the transfer process to avoid sending funds to an unconfirmed account.
- Telephone check. You call the partner using an established phone number from previous verified records.
- Detail confirmation. You verify the new account number directly with the responsible finance staff.
- Dual authorization. You complete the transfer only after obtaining secondary internal approval.
Definitions
- BEC (Business Email Compromise): A cyber fraud scheme where an attacker hijacks or spoofs a corporate mailbox to redirect funds.
- Invoice redirection: Fraud where genuine bank details on an invoice are swapped with an account controlled by criminals.
- Phishing: The practice of tricking individuals into revealing login credentials by pretending to be a trustworthy entity.
- Call back verification: A security practice of confirming payment changes via a telephone call to a known number.
When does this rule not apply?
This verification step does not apply to recurring automated payments under long-term framework agreements, unless an official request for account modification is received through verified formal communication channels.
The OTSL role
At OTSL, we place strong emphasis on communication security and accuracy across international trade routes. Whether handling road transport or clarifying billing components in our guide on what customs clearance costs, we support safe supply chain management.
AI image