By Kyle Sutherland,

Invoice Fraud: The Bank-Detail Switch Scam

An email arrives saying the bank details on an invoice have changed. It reads exactly right, and it is one of the most expensive lies a small business can act on. How the switch works, and the one habit that beats it.

The most expensive email a small business receives

It arrives at exactly the right moment. A job is finished or a delivery has landed, an invoice is due, and an email turns up from the supplier saying their bank details have changed, please pay the balance into the new account. It quotes the right invoice number, the right amount, the right names. Nothing about it reads like a scam, because almost everything in it is real. The only thing that has changed is where the money goes.

The payment is made, the criminal empties the receiving account within hours, and nobody notices anything is wrong until the genuine supplier chases the genuine invoice weeks later. At that point both businesses discover they have a problem: one is owed money it never received, and the other has already paid it once.

What it costs, in real numbers

UK Finance's Annual Fraud Report, published in June 2026, counted 2,305 cases of invoice and mandate scams in 2025, with £41.3m lost. That is a fraction of the case count of the mass-market frauds, but the money per hit is in a different league: an average of nearly £18,000 a time, and £28m of the total, about two thirds, came out of business accounts rather than personal ones.

The same report puts its finger on why businesses bear the brunt: firms make genuine higher-value payments regularly, so a fraudulent one does not stand out the way it would in a personal account. A £9,000 payment to a supplier is a Tuesday, not an alarm bell. For a small firm running on thin margins, one hit of that size can be the year's profit gone in a single bank transfer.

How the switch actually works

The crude version is a forged email. The criminal sends a message that appears to come from a supplier's address, or from a lookalike address one letter off, asking for payment to a new account. We have written about why email makes that impersonation so easy, and it remains easier than most owners believe.

The version that does the real damage is quieter. The criminal gets into a genuine email account, usually through a phished password, and then does nothing at all. They sit and read. They watch the invoices go out, learn the amounts, the payment terms, the way each party writes. Then, at the moment a real payment is due, they send the bank-detail change from inside the real conversation, or intercept the real invoice and send it on with the account number altered. From where you sit, it is the same thread, the same address and the same tone as every message before it.

That is why trades and building work, weddings, vehicle purchases and house deposits come up again and again in these cases. Anywhere large one-off payments move between parties who mostly know each other by email, the switch fits perfectly.

The one habit that stops it

a builder beside his van on a terraced street, making a phone call
AI-generated image

Verify every change of bank details by phone, on a number you already had, before you pay a penny. Not the number at the bottom of the email announcing the change, because the criminal wrote that email and will happily answer that phone. The number from your contacts, a previous invoice, or the side of their van. It is one call of under a minute, and it defeats the compromised-inbox version of this scam completely, because the one thing the criminal cannot do is answer your supplier's actual phone.

Make it a rule rather than a judgement call, so it does not soften when the email is convincing or the deadline is tight, and urgency in the message should raise your suspicion rather than lower it. Tell your own customers it is your rule too: you will never change your bank details by email alone, so if they ever receive a message saying otherwise, they should ring you before paying. Your bank helps here as well. When the account name check on a new payee comes back as no match or only a partial match, treat that as a stop sign, not a formality to click past.

Keeping your name out of the criminal's toolkit

Half of this scam is about the emails you receive. The other half is about the emails your customers receive with your name on them. If your domain's email records are missing or loose, a criminal does not need to hack anything to send an invoice as you; they can simply forge your address, and the receiving inbox has no reliable way to object. The customer pays the fake invoice, loses the money, and remembers your business as the place that cost them thousands.

Three public records on your domain, SPF, DKIM and DMARC, are what close that door, and the free security check reads them and grades your domain in seconds, with nothing touching your site or inbox. If the check finds gaps, setting the records up properly is exactly what the email security service does, for a fixed price, whether or not I built your website.

If the money has already gone

Speed matters more than anything else. Ring your bank the moment you realise, because the first hours are when a payment can still sometimes be frozen or traced before it is broken up and moved on. Then report it to Action Fraud, and tell the business at the other end of the conversation straight away, because if their inbox is compromised, you are not the only customer being worked, and they need to change passwords and check their email rules today.

Keep every email exactly as it is, including the headers, because they are the evidence of where the messages really came from. And once the immediate mess is handled, have an honest look at how the door was open in the first place. That conversation, from either side of this scam, is one I am always happy to have, so get in touch if you want a straight answer about where your own setup stands.

All guides