Skip to content
0800 374 775

The invoice that was not: how business email compromise actually works

No malware, no dramatic breach. Someone reads your mail for a few weeks, waits for a real invoice, and changes one line. It is the most common way New Zealand businesses lose money to attack.

The mental image of a cyber attack involves encryption and a ransom note. The version that most often costs a business real money is far quieter: somebody gets into a mailbox, reads it patiently, and then sends one entirely plausible email.

There is no malware to detect. The email comes from a legitimate account, or from a domain one character different. It refers to a real project, a real invoice, and a real amount, because the sender has been reading about them for a fortnight. Only the bank account has changed.

The pattern

Access. A password from a breach elsewhere, or a convincing login page. This is why MFA and conditional access matter, and why session theft is worth understanding.

Observation. Nothing happens for days or weeks. The attacker is learning who approves payments, how invoices are phrased, when the finance person is on leave, and which suppliers are mid-project. Often a mailbox rule is quietly created so certain replies are diverted and the real owner never sees them.

The ask. A payment redirect, usually on a genuine invoice, sometimes with a forged remittance follow-up. Or a request to the finance team, apparently from a director, urgent, while that director is genuinely in the air and unreachable.

The gap. Nobody notices until the supplier chases payment, which is often the following month. By then the money has moved several times.

The thing that makes it work is not technical sophistication. It is that the request is exactly the kind of request your business receives all day.

Why the usual defences do not catch it

Spam filtering looks for signals of illegitimacy, and there mostly are none: real account, real thread, correct tone, plausible attachment. Staff training helps, but “be suspicious of emails” is thin advice against a message that is contextually perfect and arrives inside an existing conversation.

Which is why the control that actually works is not about email at all.

The control that works

Verify account changes out of band, always, with no exceptions for urgency.

A change to bank details triggers a phone call to a number you already hold for that supplier, not a number in the email. That is the whole control. It is free, it is unglamorous, and it defeats the entire attack class.

The important word is “no exceptions”, because urgency is the lever the attack pulls. If the process can be skipped when someone senior is insistent and the deadline is today, then the process does not exist. Make it explicit that nobody, including the director, can waive it, and say so out loud to the person who would be asked to.

Alongside that:

  • Dual approval above a threshold. One person cannot both change a payee and release the payment.
  • Alerting on mailbox rule creation and forwarding. The rule is the tell, and it is detectable.
  • Domain protections configured properly. SPF, DKIM and DMARC will not stop a compromised real account, but they raise the cost of look-alike sending.
  • Someone reviews sign-in logs. Impossible travel and unfamiliar locations are the earliest signal you get.

If it has already happened

Move fast on three fronts at once, in this order.

Call the bank immediately and ask for a recall. Hours matter here more than anything else you will do. Then reset the account, revoke active sessions rather than only changing the password, and remove any rules the attacker created. Sessions are the part people miss, and a password change alone does not evict someone already inside.

Then work out what was actually accessed, because if the mailbox held personal information you may have a notification obligation under the Privacy Act 2020, and that assessment should be made deliberately rather than skipped in the rush to fix the money.

Tell the supplier and any client whose thread was involved. It is uncomfortable and it stops the same attack rolling on to them.

Where this sits

This is not an exotic risk requiring a large budget. It is the most likely way a mid-sized New Zealand business loses a five or six figure sum, and the primary defence is a phone call somebody is empowered to insist on.

Worth agreeing on that before an invoice arrives with a new account number.

Next step

Recognise any of this? Let's talk.

We respond within one business day.