
A familiar vendor emails an updated invoice. The logo looks right, the writing sounds normal, and the message appears inside an existing conversation. The only meaningful change is a new bank account for the payment.
That small change should stop the payment process immediately.
Invoice and payment fraud no longer depends on an obviously misspelled email from a stranger. Criminals may impersonate a vendor, create a nearly identical email address, or gain access to a real mailbox and quietly monitor conversations. They wait until a legitimate payment is expected and then replace the payment instructions.
The FBI calls this business email compromise, or BEC. Its newly released 2025 Internet Crime Report recorded approximately $3.05 billion in reported BEC losses.
The most dangerous fraudulent messages often look routine.
Criminals can study public websites, social media profiles, stolen email, and previous invoices to learn who approves payments and which vendors a company uses. Artificial intelligence can also help scammers produce cleaner writing and more convincing impersonations.
Visa’s Spring 2026 threat report describes a broader shift toward fraud that exploits trust, urgency, and human decision-making, rather than relying only on technical attacks.
A fake request may therefore include:
None of those details proves that the request is genuine.
Small businesses do not need a complicated fraud department to create a meaningful safeguard. They need a written rule that applies every time payment information changes.
Treat any new bank account, routing number, mailing address, payment application, or payment method as unverified.
Do not make an exception because the message appears urgent or comes from a senior employee. A short delay is far less damaging than sending money to the wrong account.
Contact the vendor using a phone number already stored in your accounting records, contract, or approved vendor list.
Do not use the telephone number included in the email requesting the change. If a criminal wrote the message, that number may also belong to the criminal.
Ask a known contact to confirm the request and record who approved it.
One employee should not be able to receive new payment instructions, update the vendor record, and release the money without another person reviewing the change.
For a very small company, the second reviewer might be the owner, office manager, or outside bookkeeper. The goal is simply to create a second opportunity to catch an inconsistency.
A display name such as “John at ABC Supply” can be copied easily. Check the complete email address.
Look for:
Remember that a perfect address is not a guarantee. A real mailbox may have been compromised.
Payment procedures work best when the related systems are also secured.
Use multifactor authentication for email, banking, accounting, and administrator accounts. Keep accounting permissions limited to employees who genuinely need them. Remove access promptly when an employee or contractor leaves.
Businesses should also monitor for unusual email forwarding rules, unfamiliar sign-ins, and unexpected changes to vendor records.
A useful policy can fit on one page:
No employee may change vendor payment information based only on an email, text message, or incoming call. The change must be confirmed using trusted contact information already on file and reviewed by a second authorized person.
Employees should know that questioning an unusual request is encouraged, even when the supposed sender is an owner or executive. Criminals rely on urgency and authority to prevent people from slowing down.
Speed matters. Contact the bank immediately through its official telephone number and ask whether the transfer can be stopped or recalled.
Notify your IT provider so the affected email and business accounts can be investigated and secured. Preserve the emails and payment records rather than deleting them. U.S. businesses should also submit a report through the official FBI Internet Crime Complaint Center.
These steps cannot guarantee recovery, but responding quickly may improve the available options.
Payment fraud is not solely an accounting problem or an IT problem. It sits between people, procedures, email, banking, and business systems. That is why a combination of verification rules, secure accounts, limited permissions, employee awareness, and monitoring provides stronger protection than any single tool.

Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day

Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety

I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!

I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.

Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.

It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.

Himala and his team from Cybernetic Networks, Inc. has been an integral part of our successful retail business for the past 20 years. He is extraordinarily knowledgable and always available for our IT needs. Thanks to Himala and his team we are always up and running.