Protecting your business from invoice payment redirection fraud
By InvoiceReminder Editorial Team · Published 6th August 2026
Invoice payment redirection fraud is a sophisticated and increasingly common scam that targets UK businesses of all sizes. It involves a fraudster impersonating one of your genuine suppliers, tricking your accounts department into paying a real invoice into their own bank account instead of your supplier's. The result can be catastrophic, with businesses losing thousands—or even tens of thousands—of pounds in a single transaction, with little chance of recovery.
This article provides a practical guide for UK small businesses, freelancers, and their accountants on how this fraud works and, more importantly, the robust procedures you can implement to protect your business. We will cover the tactics fraudsters use, the red flags to watch for, and the essential verification steps for both paying customers and issuing suppliers.
What is Invoice Payment Redirection Fraud?
Invoice redirection fraud is a specific type of Authorised Push Payment (APP) fraud. This is a critical distinction: you, or someone in your business, are not 'hacked' in the traditional sense. You are deceived into authorising the payment yourself. Because the payment was willingly sent, banks are often reluctant to provide a refund, making prevention the only real cure.
The scam hinges on social engineering and exploiting the routine nature of B2B payments. It typically unfolds in one of two ways, with the first being far more common:
- Supplier Impersonation: A fraudster gains access to your supplier's email account. They monitor communications until they see an invoice has been sent or is due. They then contact you, posing as the supplier, and provide new bank details, claiming the old ones are no longer in use. You update your system, pay the next invoice to the fraudster's account, and your supplier never receives their money.
- Customer Impersonation: A fraudster compromises your business's email account. They use this access to impersonate you to your own customers, potentially interfering with payments or gathering information to enable a larger fraud.
In both scenarios, the core of the attack is the manipulation of trust and the interception of communications. The fraudster exploits the fact that an email from a known contact asking to update bank details is not, on its own, an immediate cause for alarm in a busy finance team.
How Fraudsters Intercept and Manipulate Invoices
To successfully redirect a payment, a criminal first needs to get inside your supplier's (or your own) digital communications. This is almost always achieved through Business Email Compromise (BEC).
The Entry Point: Business Email Compromise
Fraudsters use several methods to gain access to a business email account:
- Phishing: Sending a deceptive email that tricks an employee into clicking a link and entering their email password on a fake login page. This could be disguised as a message from Microsoft 365, a shared file notification, or a fake security alert.
- Malware: An employee might inadvertently download a malicious file containing a keylogger, which records every keystroke—including passwords—and sends them to the fraudster.
- Password Guessing: Using weak, common, or previously breached passwords makes it trivial for automated software to gain access.
Once they are in, the professional fraudster doesn't act immediately. They are patient.
The Fraudster's Playbook
After compromising an email account, the criminal follows a clear set of steps:
- Silent Reconnaissance: The fraudster will often spend weeks or even months silently observing. They create inbox rules to auto-forward copies of all emails to their own account, learning the rhythm of the business. They identify who handles invoices, who makes payments, the typical invoice values, and when large payments are expected.
- Interception and Attack: When they spot an opportunity—usually a high-value invoice being sent—they strike. They will use their access to:
- Divert the Real Invoice: They might set up an email rule in the compromised account to immediately move the genuine invoice email to a deleted or obscure folder the moment it arrives. The intended recipient never sees it.
- Send a Doctored Version: The fraudster then sends their own email from the supplier's compromised account (or a very similar "spoofed" address). This email will either contain a doctored PDF of the invoice with the bank details changed, or a separate message that follows the "real" invoice.
- The Social Engineering Script: The follow-up email is the crucial part. It will be polite, professional, and plausible. Common excuses include:
- "Hi [Accounts Person Name], Please note we have recently switched our business banking to improve our processes. Please update our payment details in your system to the following for all future invoices..."
- "Apologies, we're having an issue with our main account. To ensure payment is received without delay, please direct the payment for invoice [Number] to our secondary account below..."
- "Our bank is conducting an annual audit, and our primary account is temporarily frozen. Please use these details for the next payment..."
They create a sense of normalcy and even slight urgency, encouraging the accounts person to "helpfully" update the details to avoid payment problems. By the time the real supplier chases the overdue invoice, the money has been sent, transferred out of the fraudster's mule account, and is long gone.
The Red Flags: How to Spot a Potential Scam
Vigilance is your primary defence. Train your team to pause and question whenever they see these warning signs.
In Emails:
- Any "Change of Bank Details" Notification: This should be your number one trigger for suspicion. Treat every single request of this nature as a potential fraud attempt until proven otherwise.
- Unusual "From" Address: Look closely at the sender's email address. Fraudsters often use lookalike domains, such as
daveplumbingltd.coinstead ofdaveplumbingltd.co.uk, or a subtle misspelling likeaccounts@micr0soft.com. - Change in Tone or Language: If the email has grammatical errors, unusual phrasing, or a tone that feels different from your supplier's typical style, be suspicious.
- Sense of Urgency or Secrecy: Phrases like "please process this urgently to avoid account closure" or "this is a confidential management decision" are designed to rush you into making a mistake.
- Reply-To Address Mismatch: Sometimes the "From" address is correct, but the "Reply-To" address is set to the fraudster's own email. Hitting "Reply" will send your response to the criminal, not the real supplier.
On Invoices:
- Mismatched Details: The bank details on a new invoice are different from the ones you have on file.
- Poor Quality Editing: Look closely at the PDF invoice itself. Can you see any signs of digital editing? The font for the bank details might be slightly different, or the text might be misaligned.
- Personal Bank Account: The new details are for a personal account (e.g., "Mr J Smith") when the supplier is a limited company. This is a massive red flag.
Protecting Your Business: A Two-Sided Approach
Preventing invoice fraud is a shared responsibility. It requires robust processes on the part of the business making the payment (Accounts Payable) and strong security hygiene from the business issuing the invoice (Accounts Receivable).
For the Payer (Your Accounts Payable Process)
As the one sending the money, you hold the final key. A simple, non-negotiable verification process is the most powerful defence you can build.
- The Golden Rule: Verify by Voice. NEVER change a supplier's bank details based on an email or any other written instruction alone.
- Establish a Call-Back Procedure: When you receive a request to change bank details, you must verbally confirm it.
- Do not use the phone number listed in the suspicious email signature.
- Find a trusted phone number for your contact at the supplier—one you already have on file from previous business or from their legitimate website.
- Call them and verbally confirm the request. Ask them to read back the new sort code and account number to you.
- Implement Dual Control: For any changes to supplier payment information, require a second person within your business to review and approve the change before it is saved in your accounting system. This prevents a single point of failure.
- Send a £1 Test Payment: For a brand-new supplier or after a change of details has been verbally verified, send a small test payment of £1.01. Wait for the supplier to confirm they have received it in the new account before sending the full invoice amount. This is a cheap and highly effective final check.
- Train Your Team: Anyone with the authority to make payments or update supplier records must be trained on this process. Make it a mandatory, documented part of your finance procedures.
For the Supplier (Your Accounts Receivable Process)
As the supplier, your primary responsibility is to stop your email account from being the weak link that enables the fraud.
- Secure Your Digital Front Door:
- Enable Two-Factor Authentication (2FA): This is the single most important step you can take. It requires a second code (usually from a mobile app or text message) in addition to your password to log in. Even if a fraudster steals your password, they cannot access your account without your phone. Enable it on your email, accounting software, and any other critical system.
- Use Strong, Unique Passwords: Don't reuse passwords across different services. Use a password manager to generate and store complex passwords for you.
- Install Reputable Security Software: Ensure all company computers are protected with up-to-date anti-virus and anti-malware software.
- Proactive Communication with Customers:
- Add a Warning to Your Invoices: Put a clear, simple statement in the footer of every invoice you send. For example: "Fraud Prevention: We will never notify you of a change to our bank details by email. Please call us on [Your Trusted Office Number] to verbally verify any such request before making payment." This educates your customers and makes them part of your defence.
- Manage Legitimate Changes Carefully: If you do need to change your bank, do it formally. Inform your customers in advance via multiple channels—send a letter by post as well as an email, and personally call your key clients to let them know.
- Monitor Your Payments Diligently:
- Chase Overdue Invoices Promptly: If an invoice becomes overdue, don't wait. A prompt follow-up can uncover a misdirected payment much faster. A customer who says "we paid that last week" is your cue to investigate immediately.
- Use Automation Wisely: A well-configured system can help you stay on top of your receivables. For example, automated chasing systems like InvoiceReminder can send polite, scheduled follow-ups on your behalf, ensuring no overdue invoice is forgotten. If a customer replies to an automated reminder saying they have paid, it acts as an early warning to check for discrepancies.
Creating a Formal Verification Protocol
To make this process stick, formalise it. A documented checklist ensures no steps are missed, even when your team is busy.
| Step | Action | Why It's Important |
|---|---|---|
| 1. Request Received | An email is received requesting a change to a supplier's bank details. | This is the trigger event. The process starts here. |
| 2. Isolate & Flag | Flag the email as "For Verification". Do not action the change. | Prevents anyone from acting on the request prematurely. |
| 3. Find Trusted Contact Info | Look up the supplier's phone number from your internal records (CRM, accounting software) or their official website. | Crucially, do not use contact details from the suspicious email. This bypasses the fraudster. |
| 4. Verbal Confirmation Call | Call the known contact at the supplier. State that you have received a change request and ask them to verbally confirm it. | This is the core verification step. A direct conversation with a trusted person is required. |
| 5. Read-Back & Confirm | Ask the supplier to read the new sort code and account number to you over the phone. Match it to the details in the email. | Ensures there are no errors and that you are both talking about the same account information. |
| 6. Update & Document | Only after verbal confirmation, update the supplier record in your accounting system. Make a note of who you spoke to and when. | Creates an audit trail showing the verification process was followed correctly. |
What to Do If You Suspect You've Been Scammed
If the worst happens and you realise you have paid a fraudulent invoice, you must act with extreme urgency. Every minute counts.
- Contact Your Bank Immediately: Call your bank's fraud department on their 24/7 emergency number. Tell them you have been the victim of an APP scam. They may be able to trace and freeze the payment before the fraudster can move it. Provide them with all the details of the fraudulent transaction.
- Report to Action Fraud: Immediately file a report with Action Fraud online or by phone. Action Fraud is the UK's national reporting centre for fraud and cybercrime. This is essential for any police investigation and for building a national picture of these crimes. You will be given a crime reference number, which your bank will require.
- Inform the Genuine Supplier: Let your supplier know what has happened. They need to secure their own email account immediately (change passwords, enable 2FA) to prevent other customers from being targeted.
- Preserve Evidence: Do not delete any of the fraudulent emails. Keep a complete record of all communications, transaction details, and reports you have made.
- Understand the CRM Code: The Contingent Reimbursement Model (CRM) Code is a voluntary code that many UK banks have signed up to. It aims to reimburse blameless victims of APP fraud. However, reimbursement is not guaranteed. It depends on whether you and your bank acted with the expected level of care, and whether the receiving bank has also signed the code. Acting quickly and having followed a robust internal process will strengthen your case.
Frequently asked questions
Is it safe to put my bank details on my invoices?
Yes, this is standard and necessary business practice. The risk is not that your bank details are visible, but that an invoice is intercepted and the details are fraudulently changed. The most effective security measures are securing your email with two-factor authentication and educating your customers to verbally verify any change requests.
My supplier's email was hacked. Are they legally liable for my lost payment?
This is a legally complex and disputed area. Liability may depend on proving negligence—for example, if the supplier failed to take reasonable steps to secure their email account (like using 2FA). However, pursuing this can be a long and expensive legal battle. Prevention is far better than trying to assign blame and recover funds after the fact. This is general guidance, not legal advice.
We are a small business; are we really a target for this?
Absolutely. In fact, small and medium-sized enterprises (SMEs) are often seen as ideal targets. Fraudsters assume they have less-formal payment controls, fewer resources for IT security, and are less likely to have dedicated fraud-prevention training compared to large corporations. The loss of a single large invoice can be devastating for an SME, making them a high-impact target.
Isn't Confirmation of Payee supposed to stop this type of fraud?
Confirmation of Payee (CoP) is a valuable tool, but it is not a silver bullet. When you set up a new payee, it checks if the account name you enter matches the name on the recipient account. However, fraudsters are adept at setting up "mule" accounts with very similar names (e.g., "ABC Trading" instead of the genuine "ABC Trading Ltd"). Furthermore, the check doesn't always work for all account types or between all banks, and it can be bypassed. It should be seen as one layer of security, not a replacement for verbal verification.
What is the single most important step to prevent payment redirection fraud?
It depends on which side of the transaction you are on.
- As the Payer: Implement a mandatory, non-negotiable verbal call-back policy. Always call a trusted contact on a known phone number to confirm any request to change bank details.
- As the Supplier: Enable two-factor authentication (2FA) on your email account. This is the single most effective technical control to prevent your account from being compromised in the first place.
While technology can't replace the human vigilance needed to spot fraud, it can streamline your accounts receivable and free up your time to focus on what matters. A well-organised credit control process ensures that overdue invoices are never missed, giving you an early warning if a customer believes they've paid an invoice that you haven't received.
InvoiceReminder helps UK small businesses, freelancers and accountants stop chasing invoices by hand. It connects to Xero, QuickBooks, Sage, and FreeAgent to automatically send scheduled email reminders for unpaid invoices. You can set your own schedule, from a polite prompt before the due date to a firm final notice. The Free plan currently includes unlimited email reminders at no cost, with no card required. InvoiceReminder is built by the UK-based team behind WeCovr, a firm which has arranged over 1,000,000 insurance policies and is authorised and regulated by the Financial Conduct Authority.