The Invoice Is Fake: How BEC and Payment-Redirection Fraud Became B2B's Most Expensive Threat

✍️ By Wei Chen · Supply Chain Quality Engineer
TL;DR

The attack isn't a hack of your bank account. It's a spoofed invoice with a changed bank account, dropped into a legitimate email thread at the exact moment a payment is due. Here's how it works, how to spot it, and the one verification step that stops nearly all of it.

The Most Expensive Email in Your Inbox

Business email compromise is now the single costliest category of fraud reported to the FBI, and the losses keep climbing. But the attack that actually separates B2B buyers from their money is almost never a brute-force breach of your bank. It's quieter.

Someone compromises an email account, either yours or your supplier's. They don't touch anything at first. They just watch. When a real payment is due, they slide into the thread with an invoice that looks exactly right, except the bank account has changed. The buyer pays. The money vanishes. The real supplier never sees a cent.

Why Cross-Border B2B Is the Perfect Target

Fraudsters pick their victims by the size of the wire and the friction in the process. Cross-border B2B has both in spades.

Payments are large, often tens or hundreds of thousands of dollars. Time pressure is real: a delayed deposit can push a production slot or a vessel booking. And there's a language gap. When a buyer and supplier communicate in a second language, small inconsistencies in an email, the kind that might trigger suspicion in a native speaker, get smoothed over. The attacker counts on all three.

Spot the Attack Before You Wire

The tells are there if you look:

Fraud Vectors and How to Stop Them

AttackHow it worksYour defense
Spoofed invoiceFake invoice, changed bank accountOut-of-band verification of any bank change
Lookalike domainsupplier.com vs supp1ier.comCheck the domain after the @
Account takeoverReal supplier email, attacker typingPhone or video confirm before large wires
Invoice interceptionModified PDF in a real threadVerify totals and account against a known copy

The One Step That Stops Nearly All of It

Every defense in the table points to the same habit: verify payment details through a second channel before you wire. A phone call to a number you already have on file. A video call where you read the account number back and the supplier confirms it. That single step, done consistently, defeats the vast majority of payment-redirection attempts, because the attacker controls the email thread but not the phone in your supplier's office.

Make it policy, not a judgment call. Any bank-detail change, any new account, any amount above a threshold: out-of-band confirmation, no exceptions. The buyers who get burned are the ones who decide this one time it's fine to skip the call.

If the Money Is Already Gone

Speed is everything. Contact your bank the moment you suspect a problem and request a wire recall. The first 24 to 48 hours are the window where funds can sometimes be frozen or reversed before they clear the beneficiary bank. After that, recovery odds drop sharply.

File a report with local law enforcement and, in the US, with the FBI's IC3. Tell the real supplier their email was compromised so they can warn other customers. The recall isn't guaranteed, but it's the only shot you get, and it gets worse by the hour.

Common Questions from Buyers

How does payment-redirection fraud actually work?
An attacker compromises the email account of either the buyer or the supplier, then waits. When a legitimate payment is due, they intercept the thread and send a new invoice from a lookalike address, or a message from the supplier's real account, changing the bank details to an account they control. The buyer, expecting an invoice, wires the money to the attacker. The goods never arrive, and the real supplier never got paid.
How do I verify a changed bank account safely?
Never accept a bank change from email alone. Call the supplier on a phone number you already have on file, or get on a video call, and confirm the new account details out loud. Treat any bank-detail change as a red-flag event that requires out-of-band verification through a second, independent channel. Also check that the account name matches the supplier's registered company name, and that the country of the bank matches where the supplier actually operates.
What do I do if I already wired money to a fraudulent account?
Act in hours, not days. Contact your bank immediately and request a wire recall. The first 24 to 48 hours are the window when funds can sometimes be frozen or reversed before they leave the beneficiary bank. Simultaneously file a report with your local law enforcement and, in the US, with the FBI's IC3. Notify the real supplier so they know their email was compromised and can alert other customers. Speed is the single biggest factor in recovery.
How do I spot a fake supplier email domain?
Look at the domain after the @ symbol, not the display name. Attackers register lookalike domains with one character changed, like supplier.com versus supp1ier.com or supplier-co.com. Check the reply-to address, not just the from address. Be wary of invoices arriving from a free webmail account when your supplier normally uses a company domain. When in doubt, don't reply to the email, start a fresh thread to the supplier's known address.

Wire to verified suppliers and build out-of-band payment confirmation into every order on Compare2Best.

This article is produced by the Compare2Best knowledge team and reviewed by fraud prevention and trade finance specialists. Updated August 2026. Fraud techniques evolve quickly; confirm current guidance with your bank and law enforcement. Nothing here is legal or financial advice.