Guide · Payment fraud

How to stop fake invoices, changed bank details and fake-boss payment requests

Published 2026-09-29 · 6 min read

In 2024, Americans reported losing about $2.77 billion to business email compromise, the scam where a criminal poses as a supplier, a client or the boss and asks for money to go somewhere new.[1] This guide explains the three versions that hit small offices most, how deepfake voices and video have joined them, and the simple payment rules that stop all of them regardless of how convincing the request looks.

What business email compromise looks like

Business email compromise, or BEC, is not really a hacking crime. It is a paperwork crime that uses email. The FBI describes three common methods: sending from an address that looks almost like a real one, sending targeted fake messages that mimic someone you trust, and breaking into a real mailbox so the criminal can read genuine conversations about payments and slip in at the right moment.[2] In 2024 the FBI's Internet Crime Complaint Center (IC3) logged 21,442 BEC complaints.[1]

For a small office, it usually arrives in one of three costumes:

A case that proves size is no protection

Between 2013 and 2015, a Lithuanian man named Evaldas Rimasauskas and people working with him registered a company in Latvia with the same name as Quanta Computer, a real hardware maker in Taiwan that supplied Google and Facebook. They opened bank accounts under that name and sent emails and forged invoices to the staff who routinely paid the real supplier.[3] Over roughly 2 years, the two companies wired more than $120 million to the fake.[3][4] Rimasauskas pleaded guilty to wire fraud and was sentenced in December 2019 to 5 years in federal prison.[4]

Nothing about the paperwork gave it away. What was different was where the money went: bank accounts in Latvia and Cyprus instead of the supplier's usual bank. One phone call to a contact already on file would have ended it. The full story is in our case file on the $120 million fake invoices.

Deepfake voices and video calls

The fake boss no longer has to stay on email. In March 2019 the chief executive of a UK energy company sent about €220,000 to a supplier in Hungary after a phone call from someone who sounded exactly like the head of his German parent company. The voice was generated by software.[5] Read how the voice deepfake worked.

In January 2024 a finance worker at engineering firm Arup's Hong Kong office joined a video meeting with what looked and sounded like the company's CFO and several colleagues. Police said every one of them was fake. He made 15 transfers totaling HK$200 million, about US$25 million, before checking with head office.[6] See the Arup deepfake video call.

In December 2024 the FBI warned that criminals are using AI to clone voices, create fake identity documents and appear as authority figures in live video calls. Its advice is to hang up and call back using contact details you already trust, and for families to agree on a secret word or phrase.[7] The point for a business is this: you cannot reliably spot a good fake by looking or listening. You can make it irrelevant with a process that never depends on recognizing a face or a voice.

The one rule that stops all three

Every version of this scam ends the same way: money goes to an account the real person does not control. So the defense is to verify every new or changed payment instruction, and every unusual payment request, through a channel the requester does not control. The FBI lists exactly this, alongside careful checks of email addresses and caution with urgent requests.[2]

In practice that means a callback:

A deepfake can fill a video screen. It cannot answer the real CFO's desk phone when you are the one who dialed.

Payment rules for a small office

Good rules take away the pressure to decide on the spot. These fit on one page and work in a 5-person office as well as a 50-person one:

If money has already gone

Speed matters more than anything else. The FBI's advice is to contact your bank immediately and ask it to contact the receiving bank, then file a report at ic3.gov.[2] The IC3's Recovery Asset Team works with banks to freeze fraudulent transfers. In 2024 it acted on 3,020 complaints and reported a 66% success rate, freezing about $469 million in domestic cases.[1] Those results depend on fast reporting, so put your bank's fraud line on the same page as your payment rules.

Your payment fraud checklist

Common questions

How can I tell a deepfake voice or video call is fake?

Sometimes you can. The FBI suggests looking for odd details such as distorted hands, strange facial features or shadows that do not fit.[7] But the fakes are improving, and in the Arup case the employee recognized the people on screen.[6] Do not rely on spotting it. Rely on the callback rule, which works whether the fake is good or bad.

The email came from the vendor's real address. Is it safe?

Not necessarily. One of the methods the FBI describes is criminals getting into a real mailbox and reading genuine conversations before sending a request.[2] A message from the right address, in the middle of a real thread, can still carry fake bank details. The rule stays the same: new payment instructions get a callback to a number you already had.

Will my bank or insurance cover a BEC loss?

Often not. When an authorized employee sends a wire, the bank has usually done what it was told. Some cyber insurance policies cover this kind of fraud, and some exclude it or cap it, so read the section on social engineering or funds transfer fraud and ask your agent directly. Prevention is far cheaper than recovery, and the first call to your bank should be made within minutes, not days.

Close the same gap

Put it in writing

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More guides

General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.

Sources
  1. FBI Internet Crime Complaint Center: 2024 Internet Crime Report
  2. FBI: Business Email Compromise
  3. Africa Check: Man stole $122 million from tech giants by sending random bills? No, it was a global fraud
  4. CyberScoop: Man who scammed Facebook and Google out of $120 million sentenced
  5. Sophos: Scammers deepfake CEO's voice to talk underling into $243,000 transfer
  6. CNN: Finance worker pays out $25 million after video call with deepfake chief financial officer
  7. FBI Internet Crime Complaint Center: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (PSA, December 3, 2024)