How to stop fake invoices, changed bank details and fake-boss payment requests
In 2024, Americans reported losing about $2.77 billion to business email compromise, the scam where a criminal poses as a supplier, a client or the boss and asks for money to go somewhere new.[1] This guide explains the three versions that hit small offices most, how deepfake voices and video have joined them, and the simple payment rules that stop all of them regardless of how convincing the request looks.
What business email compromise looks like
Business email compromise, or BEC, is not really a hacking crime. It is a paperwork crime that uses email. The FBI describes three common methods: sending from an address that looks almost like a real one, sending targeted fake messages that mimic someone you trust, and breaking into a real mailbox so the criminal can read genuine conversations about payments and slip in at the right moment.[2] In 2024 the FBI's Internet Crime Complaint Center (IC3) logged 21,442 BEC complaints.[1]
For a small office, it usually arrives in one of three costumes:
- The fake invoice. A bill that looks like it comes from a vendor you really use, with new payment instructions.
- The changed bank details. A friendly note from a supplier, client, title company or employee saying their bank account has changed. It shows up in payroll as a request to redirect a paycheck, and in real estate as new wiring instructions days before a closing.
- The fake boss. A message from the owner, a partner or the CFO asking for an urgent, confidential payment, or for gift cards, often while they are "in a meeting" or traveling.
A case that proves size is no protection
Between 2013 and 2015, a Lithuanian man named Evaldas Rimasauskas and people working with him registered a company in Latvia with the same name as Quanta Computer, a real hardware maker in Taiwan that supplied Google and Facebook. They opened bank accounts under that name and sent emails and forged invoices to the staff who routinely paid the real supplier.[3] Over roughly 2 years, the two companies wired more than $120 million to the fake.[3][4] Rimasauskas pleaded guilty to wire fraud and was sentenced in December 2019 to 5 years in federal prison.[4]
Nothing about the paperwork gave it away. What was different was where the money went: bank accounts in Latvia and Cyprus instead of the supplier's usual bank. One phone call to a contact already on file would have ended it. The full story is in our case file on the $120 million fake invoices.
Deepfake voices and video calls
The fake boss no longer has to stay on email. In March 2019 the chief executive of a UK energy company sent about €220,000 to a supplier in Hungary after a phone call from someone who sounded exactly like the head of his German parent company. The voice was generated by software.[5] Read how the voice deepfake worked.
In January 2024 a finance worker at engineering firm Arup's Hong Kong office joined a video meeting with what looked and sounded like the company's CFO and several colleagues. Police said every one of them was fake. He made 15 transfers totaling HK$200 million, about US$25 million, before checking with head office.[6] See the Arup deepfake video call.
In December 2024 the FBI warned that criminals are using AI to clone voices, create fake identity documents and appear as authority figures in live video calls. Its advice is to hang up and call back using contact details you already trust, and for families to agree on a secret word or phrase.[7] The point for a business is this: you cannot reliably spot a good fake by looking or listening. You can make it irrelevant with a process that never depends on recognizing a face or a voice.
The one rule that stops all three
Every version of this scam ends the same way: money goes to an account the real person does not control. So the defense is to verify every new or changed payment instruction, and every unusual payment request, through a channel the requester does not control. The FBI lists exactly this, alongside careful checks of email addresses and caution with urgent requests.[2]
In practice that means a callback:
- Use a number you already had. Take it from the original vendor file, a past contract or your own phone contacts. Never use the number, link or email in the message asking for the change.
- Ask a question only the real person can answer. An invoice number from last quarter, the name of their usual contact, or a detail from a recent job.
- Write down who you spoke to and when. Keep it with the vendor record.
A deepfake can fill a video screen. It cannot answer the real CFO's desk phone when you are the one who dialed.
Payment rules for a small office
Good rules take away the pressure to decide on the spot. These fit on one page and work in a 5-person office as well as a 50-person one:
- No bank detail changes by email alone. Any new or changed account for a vendor, client or employee is confirmed by a callback to a known number before the next payment.
- Two people for large or unusual payments. Set a dollar threshold. Above it, a second person who was not part of the request approves the payment.
- Urgency and secrecy are red flags, not reasons. Tell staff in writing that the owner will never be upset about a delay caused by checking.
- Payroll changes happen in person or inside the payroll system. Never from an email asking to redirect a paycheck.
- Real estate and legal offices send wiring instructions one way only. Tell clients at the start that you will never change instructions by email, and to call you on a number they already have before sending.
- No gift cards, ever. No legitimate boss pays anyone in gift cards.
- Protect the mailboxes. Turn on multi-factor login for all email, since a broken-into mailbox lets criminals watch real conversations. Our MFA guide explains which kind to use, and our case on the Unatrac fraud shows how one stolen email password cost about $11 million.
If money has already gone
Speed matters more than anything else. The FBI's advice is to contact your bank immediately and ask it to contact the receiving bank, then file a report at ic3.gov.[2] The IC3's Recovery Asset Team works with banks to freeze fraudulent transfers. In 2024 it acted on 3,020 complaints and reported a 66% success rate, freezing about $469 million in domestic cases.[1] Those results depend on fast reporting, so put your bank's fraud line on the same page as your payment rules.
Your payment fraud checklist
- Written callback rule. Every new or changed bank account is confirmed by phone, using a number already on file.
- Dual approval above a set amount. A second person signs off on large or unusual payments.
- Vendor file with verified contacts. Names and phone numbers collected when the relationship started, not from later emails.
- MFA on every mailbox. Especially the owner, finance and anyone who talks to clients about money.
- Staff know it is safe to slow down. The owner has said so, in writing.
- Clients are warned. Especially in real estate, legal and accounting, where clients send you money.
- Bank fraud line and ic3.gov are on the page. So nobody has to search for them in a panic.
Common questions
How can I tell a deepfake voice or video call is fake?
Sometimes you can. The FBI suggests looking for odd details such as distorted hands, strange facial features or shadows that do not fit.[7] But the fakes are improving, and in the Arup case the employee recognized the people on screen.[6] Do not rely on spotting it. Rely on the callback rule, which works whether the fake is good or bad.
The email came from the vendor's real address. Is it safe?
Not necessarily. One of the methods the FBI describes is criminals getting into a real mailbox and reading genuine conversations before sending a request.[2] A message from the right address, in the middle of a real thread, can still carry fake bank details. The rule stays the same: new payment instructions get a callback to a number you already had.
Will my bank or insurance cover a BEC loss?
Often not. When an authorized employee sends a wire, the bank has usually done what it was told. Some cyber insurance policies cover this kind of fraud, and some exclude it or cap it, so read the section on social engineering or funds transfer fraud and ask your agent directly. Prevention is far cheaper than recovery, and the first call to your bank should be made within minutes, not days.
Put it in writing
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Employee offboarding checklist: how to cut off a former employee's access the same day
- How to verify callers before password resets, and protect your phone number from SIM swaps
- How a small business keeps software and devices patched, and why default passwords must go
- Backups that survive ransomware: offline copies, tested restores and a one-page plan
- Which two-step login actually stops phishing, and how a small office rolls it out
- How to manage vendor, IT provider and contractor access to your systems
- Cases behind these controls
General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.
- FBI Internet Crime Complaint Center: 2024 Internet Crime Report
- FBI: Business Email Compromise
- Africa Check: Man stole $122 million from tech giants by sending random bills? No, it was a global fraud
- CyberScoop: Man who scammed Facebook and Google out of $120 million sentenced
- Sophos: Scammers deepfake CEO's voice to talk underling into $243,000 transfer
- CNN: Finance worker pays out $25 million after video call with deepfake chief financial officer
- FBI Internet Crime Complaint Center: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (PSA, December 3, 2024)