Published:

A convincing email arrives from what looks like a trusted supplier. The invoice attachment matches your usual format. The bank account details are different from last time, and there is a note at the bottom asking for payment by Friday. In a 10–25 seat business, the person processing invoices often works alone on payments. They confirm the bank details by email alone. The money moves.
That is invoice fraud — also called payment redirection fraud — and it does not require sophisticated hacking. It works because email alone is never proof that a bank-detail change is genuine, and many SMEs have no process that forces verification outside the original message.
The five checks before any payment leaves your business are simple in principle:
Call back the supplier on a known, independently sourced phone number — not one on the invoice or email.
Require a second approver for any payment to a new account or changed details.
Check against a change log — has this supplier ever changed bank details before, and is there a record of the last change?
No exceptions for "urgent" — urgency is the fraudster's primary lever.
Record the verification — note who called, when, what was confirmed, and keep that record with the payment file.
If your insurer asks why a loss occurred, they will not be looking for perfection. They will be looking for evidence that you had a process and that it was followed. This article walks through what invoice fraud looks like at SME size, how to build verification checks that actually work, and where a structured baseline review fits into the bigger picture.
What Does Invoice Fraud Actually Look Like at SME Size?
Invoice fraud is not a single technique. It covers several overlapping tactics, all aimed at the same outcome: getting your accounts team to pay money into an account controlled by the fraudster instead of the legitimate supplier.
The most common pattern is supplier impersonation with a bank-detail change. A fraudster compromises or spoofs an email from your supplier, sends an invoice that looks normal, but lists a different bank account. The finance person processes it because the email came from what appears to be the right address, the invoice format matches, and there is no reason to doubt the change.
Another variant is invoice interception. The fraudster gains access to your supplier's email, sees an invoice coming through to you, and sends a second version with altered bank details — sometimes after the original has already been received.
The NCA and NatWest describe the pattern in their joint campaign material as criminals deceiving businesses into paying fake invoices or diverting genuine payments into accounts controlled by fraudsters, using impersonation, email interception, or convincing invoice generation. The objective is always the same: manipulate the payment into an unauthorised destination.[^1]
The scale is substantial. Action Fraud figures released by the NCA show that in September 2025 alone, invoice fraud victims lost £3,908,086 from 83 cases — averaging more than £47,000 per case. Invoice fraud accounted for 85% of all Payment Diversion Fraud losses that month.[^2]
UK Finance's Half Year Fraud Report 2025 puts the broader picture at £19.9 million lost to invoice and mandate scams in the first half of 2025, with 75% of those losses occurring on non-personal or business accounts.[^3]
That last point matters for SMEs. Business accounts tend to move larger sums more regularly, which makes a single fraudulent payment harder to spot against the normal flow.
[^1]: National Crime Agency, "NCA and NatWest launch campaign to protect against Invoice Fraud in business", 29 January 2026.
[^2]: Ibid.
[^3]: UK Finance, "Half Year Fraud Report 2025", published 24 October 2025.
Why Email Alone Is Never Proof of a Bank-Detail Change
The central weakness that invoice fraud exploits is not technology — it is trust. Most SMEs do not have a rule that says: if bank details change, verify through a different channel.
Email can be spoofed. Email accounts can be compromised. Invoice attachments can be forged or intercepted. None of those things make a convincing email any less dangerous; they just mean it should never be the sole basis for accepting a payment-detail change.
The NCA's guidance to businesses is distilled into three words: Check, Verify, Never. Check for changes to invoice details or urgency. Verify by calling the genuine supplier on a previously used phone number. Never transfer money until you are satisfied the details are correct.[^4]
That "previously used phone number" is the critical part. The number should come from your own records — a previous invoice, a contract document, the supplier's official website. It should not come from the suspicious email or invoice you are currently processing.
[^4]: National Crime Agency, "NCA and NatWest launch campaign to protect against Invoice Fraud in business", 29 January 2026.
The Five Checks Before Any Payment Leaves
Check 1: Call Back on a Known Number
This is the single most effective control. When an invoice arrives with different bank details, pick up the phone and call the supplier using a number you have used before.
What to confirm:
Has the supplier requested a bank-detail change?
If yes, when did it happen?
Is the new account number exactly as stated on the invoice?
Get that confirmation in writing if possible — a reply email from the supplier's verified address, or even a written note on your own pad that you attach to the payment file.
Check 2: Require a Second Approver
In a 10–25 seat business, it is common for one person to handle end-to-end invoice processing. That is fine for routine payments to established accounts. It is not fine for payments to a new or changed account.
A second pair of eyes does two things: it adds friction that stops impulsive payments, and it creates a natural checkpoint where someone unfamiliar with the original email can ask "why are we paying here?"
The second approver does not need to be a senior manager. It needs to be someone other than the person who processed the original invoice, and it needs to be a rule — not a discretionary choice.
Check 3: Maintain a Bank-Detail Change Log
Keep a simple record — a spreadsheet, a shared document, or even a section in your accounting software notes — that records when each supplier's bank details were last changed and by whom.
When a new change request arrives, you can immediately spot whether this is:
A first-time change (triggers full verification)
A repeat change (did we verify the last one? do we have a record?)
A very frequent change (is this supplier's security posture a concern?)
This is governance in its simplest form: traceability of financial data changes. It costs almost nothing to maintain and provides useful evidence if an incident occurs.
Check 4: No Exceptions for "Urgent"
Urgency is the fraudster's primary psychological lever. "Please process this today," "We need payment urgently," "Our bank account is changing tomorrow" — these phrases are designed to short-circuit verification.
The rule is simple: no payment to a changed account proceeds faster than the time it takes to complete the callback and second-approval checks. If a supplier genuinely needs urgent payment, they will understand that you follow security procedure. A fraudster will not.
Check 5: Record the Verification
Every verification step should leave a record. This is not bureaucracy — it is evidence. If you are asked by your insurer, your bank, or Action Fraud why a fraudulent payment was made, the question will not be "Did you have controls?" It will be "Were those controls followed in this case?"
A simple record includes:
Date and time of verification call
Name of person called at the supplier's end
Confirmation given (or denial that a change was requested)
Name of second approver and their sign-off
Any written confirmation received
Store that record with the invoice and payment file. Six months later, it may be the difference between a successful insurance claim and a rejected one.
What an Insurer Expects to See After a Loss
Insurance is not a replacement for verification — it is a backstop. But the question of whether a claim is paid depends on what the insurer can see in your processes.
The NCSC's incident management guidance emphasises that a basic response plan should include key contacts (including insurance), escalation criteria, and clear processes for handling incidents from discovery through to close-down.[^5] That applies to payment fraud just as much as it does to ransomware.
After an invoice-fraud loss, insurers typically look for:
Evidence that a verification process existed (even if it is lightweight)
Confirmation that the process was not bypassed
Documentation of the verification attempt (or why it was not made)
Prompt reporting to the bank and to Action Fraud (now Report Fraud, launched December 2025)
UK Finance data shows that payment service providers returned £9.2 million — 46% of losses — to victims of invoice and mandate scams in the first half of 2025.[^6] That return rate is far from automatic. It depends on how quickly the fraud is reported, whether the receiving bank can trace and recover funds, and whether the paying business can demonstrate that they acted reasonably.
Having a documented verification process does not guarantee recovery, but it materially improves your position — both with your insurer and with the reimbursement process.
[^5]: National Cyber Security Centre, "Incident management: Plan your cyber incident response processes". [^6]: UK Finance, "Half Year Fraud Report 2025", published 24 October 2025.
How This Connects to Your IT Security Baseline
Invoice fraud sits at the intersection of email security and financial process. Better email security — DMARC, SPF, DKIM, mailbox monitoring, MFA enforcement — reduces the chance that a fraudster can spoof or compromise your supplier's email address in the first place. But it does not eliminate the risk entirely, and it does not replace the need for verification checks on payment instructions. As Microsoft's own analysis of common security weaknesses shows, email authentication misconfiguration is one of the most frequent gaps in SME environments — and that is precisely where invoice fraud begins.
The NCSC's phishing guidance makes this explicit: no single layer of defence is sufficient, and over-emphasising user training or email filtering while neglecting process controls leaves gaps that attackers will exploit.[^7] The NCSC's four-layer approach to phishing defence — make it hard to reach users, help them report, limit effects of undetected messages, respond fast — is the framework that complements the payment verification checks this article covers.
A maintained IT security baseline — the minimum agreed security standard across identity, devices, patching, malware protection and backup — includes conditions that reduce this exposure. As our defensible IT security baseline for SMEs outlines, the baseline framework covers exactly these controls: identity management that prevents leaver accounts from persisting, secure configuration that reduces spoofing surfaces, and patching discipline that closes the windows attackers exploit. A Modern Workplace approach to Microsoft 365 governance ensures these controls are not ad-hoc but consistently applied across your estate.
Secure mailbox configuration that makes spoofing harder
Clear payment-change processes documented and enforced
Finance verification conducted outside the original email thread
Prompt leaver account removal so compromised credentials are short-lived
This is not a technology problem alone. It is an ownership and governance question: who owns the payment-verification process, who enforces it, and how is compliance checked?
If you would like to understand your current baseline against a structured framework, Book a Security Triage Call. The purpose is to clarify your current controls — including payment verification and finance process controls — before you make tooling or provider decisions.
[^7]: National Cyber Security Centre, "Phishing attacks: defending your organisation".
Frequently Asked Questions
Do banks refund invoice-fraud losses?
UK Finance data shows that payment service providers returned 46% of invoice and mandate scam losses to victims in the first half of 2025. This is not automatic — it depends on how quickly the fraud is reported, whether funds can be traced and recovered, and whether the paying business can demonstrate they acted reasonably. The reimbursement rate is higher for personal accounts than for business accounts, which reflects the different protections and investigation timelines.
What if a supplier emails new bank details?
Treat any email requesting a change to bank details as potentially fraudulent, regardless of how convincing it looks. Call the supplier on a previously used phone number — one from your own records, not from the email. Do not click links in the email to find a contact number. Confirm the change verbally, get written confirmation from the supplier's verified address, and record the verification before processing payment.
Who should be allowed to change a supplier's bank details?
This is an ownership question. The answer depends on your business structure, but a practical approach is to restrict who can update bank details in your accounting system to named individuals, with periodic review of those permissions. Changes should require a second authorised person to approve the update, and every change should be logged with the date, the reason, and the evidence that was checked.
Does Microsoft 365 do anything to stop this natively?
Microsoft 365 includes email authentication tools (SPF, DKIM, DMARC), spam and phishing filtering, and threat protection features that can reduce the volume of fraudulent emails reaching your inbox. But these tools are not designed specifically to prevent invoice fraud, and no email platform can reliably distinguish a genuinely compromised supplier account from a cleverly spoofed one. They are one layer in a layered defence — not a replacement for human verification and process controls.
Next Steps
Invoice fraud exploits a simple gap: the assumption that an email about a bank-detail change is trustworthy because it looks like it came from the right place. Closing that gap requires a process, not a product.
The five checks — callback on a known number, second approver, change log, no urgent exceptions, and recorded verification — are straightforward to implement. They do not require new software or a large team. What they require is someone to own them, enforce them, and review them periodically.
For most 10–25 seat owner-managed SMEs in Sussex and Kent, the starting point is a clear view of what controls you already have — including payment verification — and where the gaps are. Book a Security Triage Call to map your current baseline before you make tooling or provider decisions.

Backup & Disaster Recovery
First 24 Hours of a Cyber Incident: SME Playbook

Cyber Security
Cyber Essentials Support for Kent SMEs

Modern Workplace
Invoice Fraud Checks UK SMEs: 5 Verification Steps

Backup & Disaster Recovery
One-Page Business Continuity Plan Template for UK SMEs

Modern Workplace