The $123,000 Email: How Fake Invoices Quietly Drain Small Businesses
One of the most expensive attacks in business today doesn’t involve malware, ransomware, or a dramatic system lockout. It’s an email — often from what looks like a familiar vendor — asking you to update the bank details on an invoice you were already expecting to pay. According to the FBI’s 2025 Internet Crime Report (released April 2026), business email compromise drove $3.05 billion in reported U.S. losses across roughly 24,800 cases, averaging about $123,000 per incident. Recent cases show how fast it happens: in April 2026, attackers redirected a single supplier payment and stole £700,000 from a UK energy company simply by altering the bank details on a legitimate invoice.
What makes this so effective is how little it costs the attacker. There’s no sophisticated exploit — just a stolen password, patience, and one well-timed message. That low barrier to entry is why payment-redirect fraud has become one of the most common threats aimed at small and mid-sized businesses.
How the scam works
Unlike a smash-and-grab attack, this one is quiet and patient:
- An attacker gains access to an email account — often a vendor’s, sometimes yours — through a phishing link or a reused password.
- They sit and watch, sometimes for weeks, learning who approves payments, which suppliers are active, and when large invoices are due.
- At the right moment, they insert a message into a real email thread: “We’ve changed banks — please update our payment details.”
- The payment goes out as normal. By the time anyone notices, the money is gone and often unrecoverable.
Small and mid-sized businesses are prime targets because the request looks completely routine. The impersonation angle is what makes it land: attackers pose as trusted partners — suppliers, accountants, law firms — precisely because we’re inclined to act on their requests without a second look. When the email comes from a real vendor’s actual account (a tactic known as vendor email compromise), even careful staff can be fooled.
What good looks like
You don’t need a big security budget to shut this down — you need a few reliable habits:
- Verify any bank-detail change out of band. Before changing payment information, confirm it by calling the vendor at a known number — never the one in the email requesting the change. This single step stops most of these attacks. (Finance)
- Require two sets of eyes on payments. Dual approval for new payees and any change to banking details adds friction exactly where it matters. (Finance)
- Turn on multi-factor authentication for email. Most account takeovers start with a stolen password; MFA (a second login step beyond the password) blocks the vast majority of them. (IT)
- Train the people who touch invoices. Short, regular awareness training on realistic examples turns your finance and operations staff into a strong last line of defense. (HR / Operations)
The bigger picture
Each of these steps helps on its own, but the real protection comes from how they fit together — the right controls, applied in the right priority, backed by a plan for the day something slips through. That’s where a fractional CISO adds value: an experienced security advisor who helps you decide what matters most and move from reacting to incidents toward preventing them, without the cost of a full-time hire. Good security is both tactical and strategic, and you don’t have to sort out the balance alone.
Here’s a useful gut check: if a trusted vendor emailed your team tomorrow asking to change their bank account, would someone pick up the phone to verify — or would the payment just go out? If you’re not certain of the answer, that’s a conversation worth having. The Plow Networks team is glad to help on both fronts: the practical controls you can put in place now, and the longer-term strategy behind them.
Explore more on: