
An email arrives from a familiar vendor. The message says the vendor changed banks and asks your accounting employee to use new payment instructions for the next invoice.
The email may use the vendor’s real name, match an existing conversation, and refer to a legitimate project. Nothing looks obviously fake. But if the request is fraudulent, the next payment could go directly to a criminal-controlled account.
This type of fraud is commonly called business email compromise, or BEC. It may involve a criminal taking control of a real email account or creating a convincing imitation of one. The FBI recorded 24,768 BEC complaints and more than $3.04 billion in reported losses during 2025. Those figures represent reported complaints, so they should not be treated as the full amount of fraud that occurred. (FBI 2025 Internet Crime Report)
Invoice fraud does not always begin with an obviously suspicious attachment. A criminal may quietly watch a compromised mailbox, learn how a company communicates, and wait for a real payment conversation.
The fraudulent request may arrive at the right time, use a familiar signature, and include the correct invoice amount. It may also create urgency by claiming that the old account is closing or that payment must be redirected immediately.
Employees should pay special attention to:
A message does not become trustworthy simply because it appears inside a real email conversation. A compromised account can make a fraudulent request look perfectly ordinary.
The most effective business control is straightforward: independently verify any change to vendor payment information.
Call the vendor using a phone number already stored in your accounting system, contract, or trusted contact list. Do not use a phone number supplied in the change request. The FBI specifically recommends using a secondary communication channel to confirm changes in account information. (FBI Business Email Compromise Guidance)
Your procedure should also require:
The FTC also advises businesses to establish clear invoice-approval procedures and have employees examine invoices closely before paying them. (FTC Small-Business Invoice Scam Alert)
Payment procedures remain essential even when a company has strong email security. Technology should support the verification process, not replace it.
Use multifactor authentication for Microsoft 365 and other business email accounts. Review suspicious forwarding rules, remove accounts that former employees no longer need, and configure SPF, DKIM, and DMARC email authentication for the company’s domain. These controls make account takeover and sender impersonation more difficult. (FTC Cybersecurity for Small Business)
Employees should also have an easy way to report suspicious messages. A quick question from accounting should be welcomed, even when the request later proves legitimate.
Contact the originating bank immediately and request a recall or reversal. Speed matters. The FBI advises victims to contact their financial institution as soon as the fraud is recognized and then file a complaint with the Internet Crime Complaint Center.
Preserve the original email and payment records, notify the company’s IT provider, and have the affected email account reviewed. Passwords may need to be changed, active sessions revoked, forwarding rules removed, and other mailboxes checked for related activity. Avoid deleting evidence or continuing the conversation with the suspected criminal.
Invoice fraud succeeds when urgency overrides procedure. A short verification call and a second approval may feel inconvenient, but they are far easier to manage than trying to recover a payment after it has left the account.

Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day

Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety

I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!

I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.

Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.

It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.

Himala and his team from Cybernetic Networks, Inc. has been an integral part of our successful retail business for the past 20 years. He is extraordinarily knowledgable and always available for our IT needs. Thanks to Himala and his team we are always up and running.