The Email That Costs Businesses Six Figures
It arrives from a supplier you've paid for years. Same signature, same tone, correct reference to an invoice you genuinely owe.
"Please note our banking details have changed — updated details attached for the payment due Friday."
Someone in accounts updates the record. The payment goes out. Three weeks later the real supplier calls to ask why they haven't been paid.
By then the money has been moved through several accounts in several jurisdictions and it is, in practical terms, gone.
Why international payments are the target
Payment fraud concentrates on cross-border transactions for reasons that are entirely rational from the fraudster's perspective:
The amounts are large. Supplier payments to overseas manufacturers dwarf typical domestic transactions.
The process is already unfamiliar. Staff who question an odd-looking domestic payment often don't feel qualified to question an international one. Unfamiliar bank formats and foreign account details look like they're supposed to look strange.
Recall is difficult. Once funds have landed in another jurisdiction and been moved on, recovery is slow, expensive and usually unsuccessful.
Communication is asynchronous. You email a supplier in a different time zone and wait a day for a reply. That delay is the fraudster's working window.
Legitimate changes do happen. Suppliers genuinely do change banks, restructure entities and switch payment corridors. The fraud imitates a real event.
Five controls that work
Most of this is unglamorous and none of it requires new systems.
1. Verified callback on every bank detail change. No exceptions.
Any change to beneficiary details triggers a phone call to a number you already hold on file — never a number from the email requesting the change. Speak to a named person you've dealt with before. Document who you spoke to and when.
This single control stops the overwhelming majority of these attacks, and its effectiveness depends entirely on the "no exceptions" part. Fraudsters engineer urgency precisely to create an exception.
2. Dual authorisation above a threshold.
Two people, one initiating and one approving, with the approver reviewing the beneficiary details rather than just the amount. Set the threshold low enough to be meaningful and high enough that people don't route around it.
3. A written rule that urgency does not override process.
Almost every successful attack includes time pressure — a shipment held at port, a director travelling and unreachable, a discount expiring today. The instruction that protects you is simple and should be in writing: no payment is ever urgent enough to skip verification, and no one in this business will ever be criticised for delaying a payment to check it.
That second clause matters as much as the first. Junior staff bypass controls because they're afraid of holding something up, not because they're careless.
4. Beneficiary consistency checks.
Be alert when the account name doesn't match the supplier name, when a European supplier's new account is in a different country, or when a long-standing corridor changes without explanation. Payment providers can flag mismatches, but the commercial context sits with you — you're the one who knows this supplier has invoiced from Hamburg for six years.
5. Restrict who can be asked.
Fraudsters research organisations and target the person most likely to comply: often someone junior, recently joined, or working alone. Make it explicit that payment instructions arriving by email alone are never actioned regardless of who appears to have sent them, including the CEO. Especially the CEO — that variant is common enough to have its own name.
What to do in the first hour
If a payment has gone out wrongly, speed is the only meaningful variable:
Contact your payment provider immediately and request a recall. Hours matter — funds sitting in the receiving account are recoverable; funds already moved on generally aren't.
Contact the receiving bank directly if you can, in parallel.
Report to Action Fraud and, in the UK, to your own bank's fraud team.
Preserve everything — original emails with full headers, not forwards.
Check for further exposure. These attacks are rarely isolated. If someone had access to your email, assume other payments and other suppliers are compromised too.
Tell your insurer promptly. Cyber and crime policies typically have short notification windows, and late notification is a common reason for declined claims.
What to ask your payment provider
Can you flag when beneficiary details differ from previous payments to the same supplier?
What's your process and realistic timeframe for a recall request?
Do you require dual authorisation, and can we configure the threshold?
Who do we call out of hours, and how fast do you actually respond?
If a provider can't answer the recall question with a specific process and a named contact, that's a meaningful gap in your controls — and it's worth knowing before you need it rather than after.
William Fuller, Co-Founder of Orbis Exchange Group contact on 0203 918 5622
Ben James, Co-Founder of Orbis Exchange Group contact on 0203 918 5621