The Most Expensive Email in Your Inbox
Business email compromise is now the single costliest category of fraud reported to the FBI, and the losses keep climbing. But the attack that actually separates B2B buyers from their money is almost never a brute-force breach of your bank. It's quieter.
Someone compromises an email account, either yours or your supplier's. They don't touch anything at first. They just watch. When a real payment is due, they slide into the thread with an invoice that looks exactly right, except the bank account has changed. The buyer pays. The money vanishes. The real supplier never sees a cent.
Why Cross-Border B2B Is the Perfect Target
Fraudsters pick their victims by the size of the wire and the friction in the process. Cross-border B2B has both in spades.
Payments are large, often tens or hundreds of thousands of dollars. Time pressure is real: a delayed deposit can push a production slot or a vessel booking. And there's a language gap. When a buyer and supplier communicate in a second language, small inconsistencies in an email, the kind that might trigger suspicion in a native speaker, get smoothed over. The attacker counts on all three.
Spot the Attack Before You Wire
The tells are there if you look:
- The domain, not the name. Check what's after the @. Lookalike domains swap one character: supplier.com becomes supp1ier.com. The display name will still say the supplier's real name.
- The bank change. Any change to payment details is the single biggest red flag in the entire process. Treat it as an incident, not a routine update.
- The reply-to. A reply-to address that differs from the from address is a classic sign. So is a company invoice arriving from a free webmail account.
- The mismatch. A bank account in a country where your supplier doesn't operate, or an account name that doesn't match the registered company name.
Fraud Vectors and How to Stop Them
| Attack | How it works | Your defense |
|---|---|---|
| Spoofed invoice | Fake invoice, changed bank account | Out-of-band verification of any bank change |
| Lookalike domain | supplier.com vs supp1ier.com | Check the domain after the @ |
| Account takeover | Real supplier email, attacker typing | Phone or video confirm before large wires |
| Invoice interception | Modified PDF in a real thread | Verify totals and account against a known copy |
The One Step That Stops Nearly All of It
Every defense in the table points to the same habit: verify payment details through a second channel before you wire. A phone call to a number you already have on file. A video call where you read the account number back and the supplier confirms it. That single step, done consistently, defeats the vast majority of payment-redirection attempts, because the attacker controls the email thread but not the phone in your supplier's office.
Make it policy, not a judgment call. Any bank-detail change, any new account, any amount above a threshold: out-of-band confirmation, no exceptions. The buyers who get burned are the ones who decide this one time it's fine to skip the call.
If the Money Is Already Gone
Speed is everything. Contact your bank the moment you suspect a problem and request a wire recall. The first 24 to 48 hours are the window where funds can sometimes be frozen or reversed before they clear the beneficiary bank. After that, recovery odds drop sharply.
File a report with local law enforcement and, in the US, with the FBI's IC3. Tell the real supplier their email was compromised so they can warn other customers. The recall isn't guaranteed, but it's the only shot you get, and it gets worse by the hour.
Common Questions from Buyers
How does payment-redirection fraud actually work?
How do I verify a changed bank account safely?
What do I do if I already wired money to a fraudulent account?
How do I spot a fake supplier email domain?
Wire to verified suppliers and build out-of-band payment confirmation into every order on Compare2Best.