Wire Fraud and Fake Invoice Emails: How Business Email Compromise Works
The most expensive email a business will ever receive doesn't carry a virus. It carries new wiring instructions, arrives in a real thread, and reads exactly like the person you've been dealing with for weeks. Here's how it works and the one rule that beats it.
Business email compromise, or BEC, is one of the costliest categories in the FBI's annual cybercrime report, and it does its damage without malware, without a ransom note and usually without anyone noticing until the money is gone. It works because it uses your real transactions. Only the destination changes.
The Short Version
No bank detail changes by email, ever. Any new account number, any “updated” wiring instruction, any last-minute change to where money goes gets confirmed by phone, on a number you already had before the email arrived. That single rule, written down and followed, stops nearly all of it.
How the Scam Actually Runs
Get into a mailbox
A phished password on an account with no second factor (see how to spot phishing). Or, with no break-in at all, register a lookalike domain: yourfirm-law.com instead of yourfirmlaw.com, with the display name copied exactly.
Watch, quietly
For weeks. Inbox rules forward copies of anything mentioning “wire,” “closing” or “invoice” to the attacker and hide the replies, so the real owner never sees the conversation drift.
Wait for real money
A closing date. A large vendor invoice. A payroll cycle. The scam uses the genuine transaction, with the genuine amount, on the genuine schedule.
Send the change
From the real mailbox or the lookalike, inside the existing thread, often on a Friday afternoon, with a plausible reason: “our bank is being audited,” “new account for this closing.”
Move it and vanish
The money lands in a mule account and is split and forwarded within hours. After about 72 hours, the odds of getting it back collapse.
Why Law Firms, Title Agents and Accountants
Large, predictable transfers on deadlines, many parties on one email thread, and a culture of urgency. A Tampa Bay real estate closing is the textbook target: buyer, seller, agents, lender, title agent and attorney all trading wiring details in the same week. Accounting firms get the vendor-invoice and payroll versions; law firms get trust-account requests dressed up as client instructions. Our law firm and accounting firm IT pages cover what we set up for each.
The Four Versions
| Variant | How it reads | Who receives it |
|---|---|---|
| Executive request | “I'm in a meeting, wire this today and keep it quiet,” or a request for gift cards | Anyone with a company card or bank access |
| Vendor invoice | A real vendor's real invoice, with a new bank account for payment | Bookkeepers, accounts payable, accounting firms |
| Payroll diversion | “Please update my direct deposit” from a spoofed employee address | HR, payroll, small offices where one person does both |
| Closing wire | Updated wiring instructions sent to the buyer or title company days before closing | Law firms, title agents, and the buyers themselves |
The Controls That Actually Stop It
- The callback rule. Every change to payment details is verified by voice, on a number you already had. Not the number in the email signature. Put it in writing, and tell clients up front that you will never change instructions by email.
- Two people over a threshold. Any transfer above an amount you choose needs a second approver who wasn't on the email thread.
- Passkeys or MFA on every mailbox. The scam starts with a sign-in. A passkey makes the phished password worthless.
- Inbox rules reviewed. A forwarding rule to an outside address is the loudest sign of a compromised mailbox. Check them quarterly, or have monitoring watch for them the minute they're created.
- DMARC on your domain. Stops anyone sending as your exact address. See SPF, DKIM and DMARC. Lookalike domains still need the callback rule.
- Wiring instructions off email. Deliver them by phone or through a secure portal, and tell clients that anything arriving another way is fake.
- A freeze window. No changes to any instruction in the 48 hours before a closing, full stop.
If a Wire Already Went Out
Speed is the only thing that matters. In this order:
- Call your bank now. Ask for the fraud department and a recall. Give them the receiving bank and account number. Money moved within the last 24 to 72 hours can sometimes be frozen.
- File a report at ic3.gov. The FBI's Recovery Asset Team works with banks to freeze funds from fresh domestic wires, and the report is what triggers it.
- Call the receiving bank's fraud line and ask them to hold the account.
- Preserve the emails with full headers. Don't delete or forward anything until you've saved it.
- Lock the mailbox down: change the password, revoke sessions, remove the inbox rules, and check every other mailbox in the firm for the same rules.
- Notify your insurer (many cyber policies carry a separate funds-transfer-fraud limit) and, for law firms, talk to counsel about client and bar obligations.
Quick Self-Check
| Question | If “no” or “not sure”... |
|---|---|
| Is there a written rule that payment changes are confirmed by phone on a known number? | Write it this week |
| Does every mailbox in the firm have a passkey or authenticator app? | Do this first |
| Would anyone notice a new forwarding rule on a partner's mailbox? | Worth a call |
| Do your clients know you'll never change wiring instructions by email? | Add it to your engagement letter |
Set Up the Mailbox Side of This
Passkeys, DMARC, inbox-rule monitoring, and identity threat detection that flags the overseas sign-in and the new forwarding rule the same minute they happen. Built for firms that move client money.
Frequently Asked Questions
Will the bank refund a wire I authorized?
Usually not. A wire is final once it settles, and because you approved it, it isn't treated like card fraud. Recall attempts are best-effort and depend entirely on speed, which is why the first phone call matters more than anything that follows.
Does cyber insurance cover wire fraud?
Often, but under a separate social engineering or funds-transfer-fraud limit that is smaller than the main policy, and only if you followed the procedures you attested to. Our cyber insurance guide covers what applications ask about this.
How does a SOC help with an email scam?
Identity threat detection sees the sign-in from a new country, the new inbox rule and the mailbox permission change as they happen, and can suspend the session before the attacker has watched a single thread. That is what Bay Geeks SOC does around the clock.
Isn't a phone call enough to verify?
Only on a number you already had. Attackers put their own number in the email signature and answer it cheerfully. Use the number from your contacts, a prior invoice, or the company's website.
We send wiring instructions through a secure portal. Are we covered?
That closes most of the gap on your side. The remaining risk is a lookalike email reaching your client with different instructions, which is why clients need to hear the rule from you before the transaction starts.
More Guides
The five tells, the scams hitting Tampa Bay right now, and what to do if you already clicked.
The sign-in method a fake login page can't steal, and how to set one up.
Why a stolen password is now the most common way in, and how it's stopped.
What carriers ask about MFA, backups and EDR, and how to get to an honest yes.
SPF, DKIM and DMARC explained, and the mistakes that break them.
Disable first, capture the mailbox, revoke access, wipe the devices.
📞 727-579-4335 · ✉️ support@baygeeks.com · Privacy Policy · Terms of Service
