The email comes from a supplier you have paid for years. It is polite, it references the right order, and it attaches their real invoice for the right amount. At the bottom is one extra line: "Please note that we have changed banks. Kindly update your records and use the attached details for this and future payments." Your accounts clerk updates the supplier record, pays, and three weeks later the supplier phones asking where their money is.
This is payment-redirection fraud, sometimes called business email compromise, and in South Africa it is one of the most expensive crimes a small business can suffer. It needs no malware on your computers. It needs one person, on one busy afternoon, to trust an email.
How the fraud actually works
The convincing versions are not guesses. They usually start with someone breaking into a real mailbox, either at your supplier or in your own business, often through a password reused from another breach or a fake sign-in page. Then they wait. They read the email for days or weeks, learning who pays whom, how invoices are worded, which months are busy, and who approves payments.
When a real invoice is about to be paid, they step in. Sometimes they send from the genuine, compromised mailbox. Sometimes they register a domain one letter different from the real one and reply from that, keeping the thread intact. They set up rules to hide replies from the real owner. By the time the email reaches your clerk, every detail is right because every detail was copied from the real conversation.
The invoice is real. The relationship is real. The only thing that is false is the one line nobody thought to check.
Why it works on good staff
This is not a story about careless people. It works on experienced, careful staff because it exploits the things that make them good at their jobs: they are responsive to suppliers, they keep payments moving, and they do not want to be the reason a long-standing partner is paid late. Add month-end pressure and a message saying the old account is closing, and the fastest helpful response is the wrong one.
Which is why the fix is not "tell staff to be more careful". It is a rule that removes the judgement call entirely.
The one rule: call back on a number you already have
Every change of banking details is verified by phone, on a number already on file or on the supplier's published website, never on a number in the email asking for the change. The call is to a person you know, and it confirms the new account number digit by digit. No exceptions for urgency, for seniority, or for how genuine the email looks.
Then add a second pair of eyes. The person who changes the bank details on the supplier record should not be the person who releases the payment, and the change should be approved by a second person before the next payment run. This is the same separation of duties that protects you from internal fraud, and your audit trail should show who changed which details and when.
The same trick, pointed inwards
Watch for the internal versions too. An "email from the MD" asking for an urgent, confidential transfer. A message from an employee asking payroll to pay this month's salary into a new account. A voice note on WhatsApp that sounds exactly like the boss. Voice cloning is cheap and good now, so a familiar voice is no longer proof. The call-back rule applies to all of them: verify on a channel you already trust, not the one the request arrived on.
Training that sticks
An annual slideshow does little. What works is short, specific and repeated:
- Show real examples. Take genuine attempts your business or your suppliers have received, blank out names, and walk through what gave them away. People remember a real near-miss far better than a list of warning signs.
- Train the people who pay. Accounts, payroll, admin and the owner. They are the targets, and they need the rule more than anyone.
- Make reporting easy and praised. A clerk who stops a payment and says "this feels off" should be thanked every time, including when it turns out to be genuine. If questioning a request feels risky, people will stop questioning.
- Practise the first hour. Everyone who handles payments should know that if money has gone to a wrong account, the first call is to your bank's fraud line, immediately. Hours matter; days usually mean the money has gone.
Tie this into how the team already works rather than bolting it on. A written payments procedure, reviewed once a year, is part of your ways of working, not an IT policy nobody reads.
The technical layer behind the habit
People are the last line of defence, not the only one. A few settings make the fraud much harder to set up in the first place:
- Multi-factor authentication on every mailbox. Most of these frauds begin with a stolen password. MFA turns a stolen password into a failed login. See the basics for where to start.
- SPF, DKIM and DMARC on your domain. These stop criminals sending email that appears to come from your exact address. Our guide to email authentication explains the setup. It will not stop a look-alike domain, which is why the call-back rule still matters.
- External email warnings. A banner on messages from outside the business, so an "internal" request from a look-alike domain stands out.
- Alerts on mailbox rules. Attackers create forwarding and hiding rules. Microsoft 365 and Google Workspace can alert an administrator when one is created.
- Unique passwords, kept in a password manager. Reused passwords are how the first mailbox usually falls.
Write the rule down this week
You do not need a project to start. Write one paragraph, have the owner sign it, and give it to everyone who touches payments: "We never change a supplier's or employee's banking details based on an email or message alone. Every change is confirmed by phone on a number we already hold, and approved by a second person before payment."
Then tell your suppliers you work this way, and ask them to do the same with you. A fraudster's email stops working the moment the person receiving it knows that the next step is always a phone call.