Cybersecurity

How to protect your business from email payment scams

Business Email Compromise Jumped 81% Last Year! Learn How to Fight It

A convincing email can be enough to send money to the wrong bank account. The message may appear to come from a director, supplier, customer or staff member. It may also refer to a real invoice or conversation.

This type of fraud is often called business email compromise. The criminal may copy a trusted sender, break into a genuine mailbox or monitor a conversation before changing payment instructions.

The safest response is a mix of secure email accounts and clear payment checks.

How the scam works

A criminal first gathers information about the business. Company websites, social media and public staff profiles can reveal names, roles, suppliers and current projects.

They then use that information to make a request sound familiar. Common examples include:

  • A supplier says its bank details have changed.
  • A manager asks for an urgent payment and says they cannot take a call.
  • A customer receives an altered invoice from a genuine mailbox.
  • A staff member is directed to a fake Microsoft 365 sign-in page.

A request for secrecy or unusual urgency is a warning sign, but some fraudulent messages are calm and well written. Staff should not rely on spelling mistakes or poor formatting to spot them.

Put a separate check around payments

Technology can reduce dangerous email, but it cannot confirm that a payment request is genuine. Your payment process needs its own check.

When bank details change, call the supplier using a phone number already held in your records. Do not use the number in the email that requested the change. For larger or unusual payments, require a second authorised person to review the request.

Write the process down and give staff permission to pause. A genuine supplier or manager should accept a short delay while a payment is verified.

Protect business email accounts

Use a unique password for every account and store passwords in a business password manager. Turn on multi-factor authentication so a password alone is not enough to sign in. Where available, use a passkey or security key instead of a text message code.

Ask your IT provider to configure the records that help receiving mail systems confirm which services are allowed to send email for your domain. These records are commonly called SPF, DKIM and DMARC. They need to be set up and monitored correctly, not simply switched on with a template.

Email filtering can also block many known scams, dangerous links and attachments before staff see them. It should support staff judgement, not replace it.

Help staff report suspicious messages

Keep training short and practical. Show staff examples they may actually receive, such as a fake invoice, delivery notice or Microsoft 365 sign-in request.

Make reporting simple. Staff should know who to call and should never be blamed for reporting a message that turns out to be harmless. Early reporting gives your business more time to block a sender, protect an account or stop a payment.

Useful account checks include:

  • Reviewing unexpected messages in the Sent folder.
  • Checking for forwarding rules that nobody approved.
  • Investigating sign-ins from unfamiliar devices or locations.
  • Removing old accounts and access when staff leave.
  • Keeping computers, phones and apps updated.

Have a response plan

If someone sends money after a fraudulent request, contact the bank immediately and ask whether the transfer can be stopped or recalled. Then contact your IT support provider so they can secure affected accounts, preserve useful records and check whether other messages were changed or sent.

Your plan should also name the person responsible for contacting your insurer, customers, legal adviser or relevant authorities when required. Keep a copy of the plan somewhere staff can reach if email is unavailable.

Review your email and payment process together

An email security product cannot fix an unsafe approval process, and a strong payment process cannot protect an exposed mailbox. Both need attention.

Give accounts staff our Invoice Fraud Checklist so they have the verification steps beside them when a request arrives.

If bank detail changes still rely on email alone, book an email and payment security consultation with JCPIT Support. We will review the Microsoft 365 accounts and payment controls that could let a fraudulent request through.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
10 Tips to Help Small Businesses Get Ready for the Unexpected
Next Article →
How to Use Threat Modeling to Reduce Your Cybersecurity Risk