Here is the shape of it, and it plays out in small UK businesses every week. The figures below are illustrative, but nothing else about this is unusual.
You have used the same materials supplier for four years. Every month they invoice you, every month you pay. In August the invoice arrives on the same email thread as always, from the same address, with the same layout, the same signature block and the same person's name at the bottom. The only difference is a short line above the bank details: please note we have changed banks — new details below.
Your bookkeeper updates the supplier record and pays £18,400. Six weeks later the supplier calls about the overdue account, and the conversation takes a while to make sense to either of you.
Why it works
This is invoice redirection fraud, sometimes called mandate fraud or business email compromise, and it succeeds because it removes almost every signal people rely on. There is no urgency, no unusual amount, no unfamiliar company, no dodgy attachment. The invoice is genuine in every respect except the sort code.
The usual route in is your supplier's mailbox, not yours. A member of their team has their credentials phished, the attacker sits quietly in the account reading correspondence, learns the invoicing cycle and the tone of voice, and then either replies from the real address or registers a near-identical domain — a swapped letter, a hyphen added, .co.uk instead of .com — that nobody reads carefully at nine in the morning. The tell-tale sign inside a compromised mailbox is a quiet inbox rule filing certain messages into an unused folder so the real employee never sees the replies.
Sometimes there is no email at all: a letter arrives on convincing headed paper announcing a change of banking arrangements, and it goes to accounts payable because that is exactly where it looks like it should go.
Confirmation of Payee is not the safety net people think it is
Most business owners assume the bank's name-check will catch this. Confirmation of Payee compares the account name you enter with the name on the receiving account, and it is genuinely useful — but it is a check on the details you were given, not on whether you should have been given them.
Three things blunt it. The fraudster may have opened or taken over an account in a name close enough to produce a match or a near-match. Your bookkeeper may simply type the name exactly as it appears on the fraudulent invoice, which produces a match against an account the fraudster controls. And when a near-match warning does appear, people click through it, because near-match warnings appear routinely for perfectly legitimate payments — trading names, abbreviations, sole traders paying into personal accounts.
The warning screen only works if the person reading it has been told that a change of bank details is the single riskiest thing that will cross their desk this year.
The reimbursement rules, and the line most firms fall on the wrong side of
Since 7 October 2024, UK payment service providers have been under a mandatory reimbursement requirement for authorised push payment fraud. The headline terms are: a maximum of £85,000 per claim, an optional excess of up to £100 that cannot be applied to vulnerable customers, and a 13-month deadline from the last fraudulent payment. The cost is shared 50:50 between the sending and receiving providers, refunds are due within five business days, or up to 35 days where more investigation is needed.
Then comes the part that catches businesses out. The requirement covers consumers, micro-enterprises and charities — not businesses generally. A micro-enterprise means fewer than 10 employees and an annual turnover or balance sheet total of no more than €2m. It also applies to domestic sterling payments made by Faster Payments or CHAPS, not to international transfers or card payments.
So in our illustration, an eleven-person firm sending £18,400 by Faster Payments sits outside the mandatory scheme entirely. Its bank may still choose to help, and it is always worth asking, but there is no requirement. A firm with eight employees would be inside it — and could still be refused if the provider judged that it acted with gross negligence, for instance by ignoring a specific warning it was given.
That is the whole argument for prevention in one paragraph. Grow past nine employees and your protection changes materially, without anyone sending you a letter about it.
The controls that actually stop it
None of these need software. All of them need someone to decide they are now rules rather than good intentions.
Call back on a number you already hold. Any change to a supplier's bank details is verified by phone, using the number from your own records or their website — never the number on the email or invoice announcing the change. This one control stops almost all of it.
Two people for changes, not just for payments. Plenty of firms require dual authorisation for large payments and none at all for editing a supplier record. The record edit is the actual attack surface.
Write down that bank details are never accepted by email. Put it in your supplier onboarding pack and in your own email footer, so your customers apply the same rule to you.
Make a small first payment. Where a change is genuine, sending £1 and confirming receipt by phone costs nothing.
Protect the mailboxes. Multi-factor authentication on every email account, and an occasional audit of forwarding and inbox rules across the business. If your own mailbox is compromised, your customers become the victims and you become the source.
Slow down urgency. Almost every successful attempt carries a reason to hurry. A standing rule that urgency triggers a call rather than a payment removes the fraudster's main lever.
The first hour, if it has already happened
Speed matters more than anything else, because funds are moved onward quickly. Call your bank's fraud line immediately and ask them to attempt recall. Report it to Action Fraud and keep the reference. Tell the supplier at once, in a phone call rather than an email — their systems are probably the ones that were compromised, and every other customer of theirs is currently exposed.
Preserve the evidence rather than deleting the emails, including full headers. Check your own mailboxes for unfamiliar forwarding rules and reset passwords across the finance team. Notify your insurer: cyber and crime policies sometimes cover social engineering losses, though often only with a specific extension, which is worth checking on your renewal rather than during a claim.
Then have the harder conversation internally. The person who made the payment did their job the way they had always been asked to do it. Treating it as an individual failure guarantees that the next near-miss gets hidden rather than reported.
The wider lesson
Money going out of a small business gets a fraction of the attention money coming in gets. Owners will spend an afternoon on chasing late invoices without losing the client and never once ask who is allowed to change a supplier's bank details. Both are cash. Only one of them can disappear entirely in a single afternoon.
It is worth thinking about the same way you think about where your money sits — a subject covered in where your business cash sits and the FSCS limit. The controls are dull, they take twenty minutes to write down, and they are the difference between an awkward phone call and a five-figure hole in a year's profit.
Common questions
Will my bank refund invoice redirection fraud?
Possibly, but only if you fall inside the mandatory reimbursement rules that took effect on 7 October 2024. Those cover consumers, micro-enterprises and charities — a micro-enterprise being a business with fewer than 10 employees and turnover or a balance sheet total of no more than €2m. They apply to domestic sterling payments by Faster Payments or CHAPS, cap reimbursement at £85,000, allow an excess of up to £100, and require the claim within 13 months of the last fraudulent payment. Larger businesses sit outside the requirement entirely, though a bank may still choose to help if asked.
Does Confirmation of Payee stop this kind of fraud?
Not reliably. Confirmation of Payee checks the account name you type against the name on the receiving account, which catches typos and some impersonation, but it cannot tell you whether the details you were given were legitimate in the first place. If your bookkeeper types the name exactly as it appears on a fraudulent invoice, and the fraudster controls an account in a similar name, the check can pass. Near-match warnings are also routinely dismissed because they appear for plenty of genuine payments. Treat it as one signal, not as verification, and verify changes by phone instead.
What should we do in the first hour after paying a fraudulent invoice?
Call your bank's fraud line immediately and ask them to attempt a recall, because funds are usually moved on within hours. Report it to Action Fraud and keep the reference number. Phone the real supplier rather than emailing them — their mailbox is most likely the one that was compromised, and their other customers are at risk right now. Preserve the emails including full headers rather than deleting them, check your own accounts for unfamiliar forwarding or inbox rules, and reset passwords across the finance team. Then notify your insurer, as some cyber and crime policies cover social engineering losses by extension.
What is the single most effective control against mandate fraud?
A call-back rule: no change to a supplier's bank details is ever actioned without a phone call to a number you already hold, taken from your own records or the supplier's website, never from the email or invoice announcing the change. It costs two minutes and defeats almost every version of this attack, because the fraudster controls the correspondence but not the supplier's phone line. Pair it with dual authorisation on supplier record changes rather than only on payments — the record edit, not the payment run, is where the fraud actually happens.



