Business Email Compromise and Invoice Fraud

Business email compromise can turn one mailbox, one invoice or one fake supplier message into a costly incident.

What business email compromise looks like

Business email compromise, often called BEC, can involve a real mailbox being accessed by an attacker, a look-alike domain, a fake supplier identity, an altered invoice or a hidden rule that forwards sensitive emails. It is especially dangerous because it often looks normal until money has moved.

Warning signs

  • A supplier suddenly changes bank account details.
  • Customers receive strange payment instructions from your address.
  • Sent items are missing or emails appear as read unexpectedly.
  • Mailbox rules forward, delete or hide messages.
  • Login alerts show unfamiliar countries, devices or applications.
  • A property, legal, building or professional services payment was redirected.

Evidence to collect quickly

Preserve the original emails, invoice versions, bank details, timestamps, phone call notes, mailbox audit logs, sign-in records, forwarding rules and any communications with the bank. If a payment has just occurred, contact the bank urgently through official channels.

What a specialist may help determine

A forensic review may identify whether the mailbox was actually compromised, whether a fake domain was used, whether more accounts are affected, what data was exposed and whether the incident created privacy, insurance or reporting obligations.

Payment redirection incidents are time sensitive. Banks may have a narrow window to attempt recall or trace actions.

Related help

Evidence checklist

A practical list of what to preserve before logs, screenshots or account records disappear.

Need clear next steps?

Speak with a digital forensic specialist before evidence is lost.

Tell us what happened, what devices or accounts are involved, and how urgent it is. We will help you frame the right response.

Request a consultation