The payment has gone through. The invoice is marked paid. Then your supplier calls.
“We haven’t received anything.”
You read out the account details. There is a pause.
“That isn’t our bank account.”
In this illustrative scenario, a small events company has paid a venue deposit after receiving an email with changed banking details. The event was real. The amount was expected. The payment instruction was fraudulent.
Now the team needs to act quickly.
Contact your bank immediately. Do not wait until you have reconstructed every email or worked out who made the mistake.
A fast response can help the recovery effort, but it does not guarantee that the money will be returned. The first hour is a useful planning window, not a deadline after which reporting becomes pointless
1. Call your bank through a trusted channel
Use the bank’s official app, an established contact number or contact details from its official website. Avoid any number or link supplied in the suspicious email.
Explain that your business may have been deceived into making a fraudulent transfer. Ask for the fraud team and request an urgent recall or recovery attempt.
The FBI’s Internet Crime Complaint Center recommends contacting your financial institution immediately after discovering a fraudulent transfer and requesting a recall. What the bank can do will depend on the payment and the circumstances.
You can begin with:
“We believe we sent a business payment to a fraudulent account. Please begin any available urgent recovery process and tell us what information you need.”
Have these details ready where possible:
- The amount and currency.
- The date and time of the transfer.
- The transaction reference.
- The recipient’s account details and bank.
- How the payment was requested.
Ask whether the bank can contact the receiving institution about holding any remaining funds. Record the case reference and the instructions you receive.
If some information is missing, make the call anyway.
2. Pause related payments
While one person speaks to the bank, another should check for further payments connected to the same supplier or instructions.
Is a second instalment scheduled? Were the new details added to the supplier record? Could another colleague pay a different invoice into the same account?
Pause those related transactions and flag the affected bank details for verification.
Contact the genuine supplier through a previously verified number. Explain what happened and check whether other recent payment instructions are genuine.
Do not seek reassurance by replying to the suspicious email thread. That could put you back in contact with the person responsible.
- Alert your finance and IT contacts
Your finance lead needs to coordinate payment checks. Your IT or security contact needs to investigate the email and assess whether an account was compromised.
The UK’s National Cyber Security Centre advises businesses affected by payment fraud to contact their bank directly and notify their IT team as soon as possible.
Give each person a clear responsibility:
- Handle the bank conversation.
- Review related payments.
- Preserve records and coordinate the technical investigation.
In a smaller business, one person may cover several roles. What matters is knowing who owns each action.
Keep blame out of the first response. Staff should feel able to say, “I think something is wrong,” immediately.
- Preserve the original evidence
Resist the urge to delete the email or clean up the inbox.
Keep the original messages, attachments, payment confirmation and related conversations. Ask IT to preserve email headers, which contain technical information about how a message travelled.
Write a simple timeline while events are fresh:
- When the request arrived.
- When the bank details were changed.
- When the payment was approved and sent.
- When the suspected fraud was discovered.
- Who has been contacted and what they advised.
Screenshots can help explain what happened, but keep the original records too.
Preserving evidence should happen alongside the urgent bank call, not before it.
- Check whether an account is still at risk
A fraudulent message does not automatically mean your inbox was hacked. The sender could have used a lookalike address or compromised a supplier’s account.
Ask your IT contact to investigate.
If an account was compromised, recovery may include changing its password, signing out existing sessions, checking for unauthorised forwarding rules and restoring secure sign-in settings.
The NCSC recommends these measures as part of recovering a hacked account, alongside enabling two-step verification.
Coordinate changes with IT or your account provider. If an attacker may still have access to the inbox, use a separate, trusted channel for the response.
Continue working with the bank while the account investigation proceeds.
- Report the incident and track follow-up actions
Start the appropriate police or fraud-reporting process for your jurisdiction. For US reporting, the FBI directs business email compromise victims to IC3.
If you have relevant insurance, notify your insurer promptly and follow its reporting instructions.
Keep bank, police and insurance reference numbers together. Assign someone to track requested information and follow-up actions.
If you discover the fraud hours or days later, still contact your bank and report it immediately.
The five-minute preparation exercise
You do not need to wait for an incident to find gaps in your response.
At your next team check-in, answer these five questions:
- Where is our bank’s verified fraud contact number?
- Who can act if the usual finance lead is unavailable?
- Who can pause related payments?
- Who handles a suspected email compromise?
- Where will we preserve evidence and record the response?
Store the answers somewhere accessible even if business email is unavailable.
Then ask:
“The supplier says the account we paid is not theirs. What do you do first?”
If the answer depends on finding a phone number, waiting for one person or debating whether to report it, you have found something to fix today.
Explore SO Mail
Visit soemailsecurity.com to explore SO Mail.
Available on iOS and Google Play.