This one costs small businesses more than most malware, and there is nothing technical to detect. A supplier emails to say their bank details have changed. The invoice is real, the amount is right, the sender looks correct. The account number belongs to someone else.
How it actually works
Usually the attacker has been reading email for weeks — either your supplier's or yours, through a password taken in an earlier phishing attempt. They know who invoices you, for how much, and when. They wait for a genuine invoice and then intervene at exactly the right moment, in the right tone, referencing the right project.
Sometimes the email comes from a domain one character different from the real one. Sometimes it comes from the genuine account, because that account is compromised — in which case every technical check passes, because nothing is being faked.
The one control that stops it
Any change to bank details gets verified by phone, on a number you already had. Not the number in the email. Not a number in the signature. The number you have used before.
That is the whole defence, and it works because it moves verification off the channel the attacker controls. Everything else is secondary to it.
Supporting controls
- Two people for payments above a threshold you choose. Fraud relies on one person acting alone under time pressure.
- Treat urgency as suspicious in itself. "Before the end of day" is a technique, not a business requirement.
- Two-factor authentication on email. Most of these start with a mailbox somebody else can read.
- Be sceptical of a request that avoids the phone. "I'm in meetings all day, just email me" is a line, not a schedule.
If a payment has already gone
- Call your bank immediately and use the words "authorised push payment fraud". Within hours there is sometimes something to recover; within days there is usually not.
- Tell the real supplier — if their mailbox is the compromised one, you will not be the only customer targeted.
- Get the mailbox checked for forwarding rules. Attackers routinely add a rule that quietly copies or hides messages, and it survives a password change.
- Report it. Even when recovery fails, it feeds the picture that catches these accounts.
If any of this is beyond where you want to go on your own, a Koadi technician can take it from here — remotely anywhere in the US, or on-site in New Jersey, New York and Pennsylvania. Describe the problem in your own words and someone who does this every day will pick it up.