Impersonation

Invoice and payroll fraud: how business email compromise drains small organizations

A supplier's bank details change, the CEO needs an urgent transfer, an employee updates their direct deposit. How business email compromise works and the simple controls that stop it.

By the Scammer Checker editors · Updated September 21, 2026 · 5 minute read

Key takeaways

  • Business email compromise caused about $3 billion in reported losses in 2025, second only to investment fraud in the FBI's figures.
  • The scam rarely involves malware. It is an ordinary-looking email asking you to pay a real bill into a new account.
  • One control stops most of it: any new or changed bank details are confirmed by phone, using a number you already had.
  • Small organizations are targeted because one person often handles payments with no second check: charities, churches, schools, contractors, law and real estate offices.
  • If a payment has gone, call your bank to request a recall and file at IC3.gov the same day.

The scam with no warning signs

Most scam advice is about spotting something odd. Business email compromise is dangerous because often nothing looks odd. The invoice is real. The amount is right. The supplier is one you have used for years. The email is in the middle of a genuine thread. The only thing that is different is one line: "Please note our bank details have changed."

The FBI's 2025 internet crime report put losses to business email compromise at just over $3 billion across roughly 24,800 complaints, the second largest category after investment fraud. The average loss is far higher than in consumer scams, and the victims are often small organizations that cannot absorb it.

The five common forms

  1. Supplier invoice fraud. A vendor's email, or a look-alike, sends new bank details for upcoming payments.
  2. Executive impersonation. A message from the "CEO" or "director" to someone in finance: an urgent, confidential payment, and they are unavailable to talk.
  3. Payroll diversion. HR receives a polite email from an "employee" asking to update their direct deposit before the next pay run.
  4. Gift card requests. The boss, the principal, or the pastor asks a staff member to buy gift cards for clients or a sick colleague and send the codes. See gift card scams.
  5. Real estate and legal closings. A buyer or client receives updated wiring instructions that appear to come from the title company, agent, or lawyer.

How they get in

  • A compromised mailbox. Someone clicked a fake sign-in page and gave up their email password. The criminal logs in, sets up rules to hide their activity, and reads for weeks.
  • A look-alike domain. accounts@brightline-supplies.com becomes accounts@brightline-suppIies.com, with a capital I for an l. In a busy inbox it is invisible.
  • A spoofed display name. The name says your director. The address behind it is a free webmail account.
  • Public information. Staff lists, news of a new contract, an out-of-office reply that says who covers payments.

The control that stops most of it

Any request to add or change payment details is confirmed by phone with a known contact, using a number already on file, before any money moves.

Not a number in the email. Not a reply to the same thread. A call to the person you normally deal with, on the number in your records. It takes three minutes and defeats the attack regardless of how the email was forged.

Make it a written rule, tell your suppliers and clients you follow it, and tell them you will never change your own bank details by email alone.

Seven more controls for small organizations

  1. Two people for payments. One sets up a new payee or a large payment, another approves it. Even in a team of three.
  2. Two-factor sign-in on every email account, starting with anyone who handles money. A stolen password is then not enough.
  3. Check mailbox rules and forwarding on finance and executive accounts. Hidden rules that move or delete messages are a classic sign of intrusion.
  4. Slow down "urgent and confidential". Agree in advance that an urgent payment request from a senior person always gets a call back, and that nobody will be criticized for checking.
  5. Verify payroll changes in person or by phone, and consider a waiting period before a changed account receives a full salary.
  6. Flag external email. Most mail systems can mark messages from outside the organization, which makes look-alike senders easier to notice.
  7. Talk to your bank about payee verification, dual approval in online banking, and alerts on new payees.

For charities, churches, schools, and clubs

You are attractive targets: staff and volunteers are trusting, leaders' names are public, and the treasurer is often one person working from a personal inbox. Three habits cover most of the risk: two signatories for payments, a call back for any bank detail change, and a standing rule that leaders never ask for gift cards by message.

For home buyers

Before wiring a down payment or closing funds, call the title company or lawyer on a number you obtained at the start of the process or from their official website, and read the account details back to them. Be suspicious of any last-minute change. Ask your bank whether it offers confirmation of the recipient's name.

If a payment has already gone

Minutes matter, and so does the order.

  1. Call your bank's fraud department. Ask for an immediate recall and for them to contact the receiving bank to freeze the funds.
  2. File at IC3.gov the same day. Include the amount, date, your bank, and the beneficiary's bank name, account, and routing numbers. The FBI can sometimes work with banks to stop fraudulent wires when the report is prompt.
  3. Call the real supplier or client on a known number. They may have been compromised and need to warn others.
  4. Secure your email. Change passwords, sign out all sessions, remove unknown forwarding rules, and turn on two-factor sign-in.
  5. Tell your insurer and, if needed, your lawyer. Some policies cover this, and some require quick notice.
  6. Keep the evidence: the emails with full headers, the payment confirmation, and a timeline.

A culture point

This fraud succeeds in organizations where junior staff are afraid to question a senior request. The most effective protection costs nothing: leaders who say, clearly and often, "If a message from me ever asks for money or gift cards, call me. I will thank you for it."

Common questions

What is business email compromise?

It is a fraud in which a criminal impersonates someone you do business with, such as a supplier, an executive, an employee, or a lawyer, usually by email, to get a payment redirected to an account they control. Sometimes a real mailbox has been broken into. Sometimes the address is only a look-alike.

How do scammers know about our invoices?

Often because someone's mailbox, yours or your supplier's, has been quietly accessed. The criminals read real conversations, wait for a real invoice, and then send new payment instructions at the right moment. Public information such as staff names and project announcements is also used.

Can we get the money back after paying a fake invoice?

Sometimes, if you act within hours. Ask your bank to recall the payment and contact the receiving bank, and file a complaint at IC3.gov with the beneficiary account details the same day. The FBI can sometimes help freeze funds when reports are made quickly. After a few days the chances fall sharply.

Are home buyers at risk too?

Yes. Real estate closings are a major target. Buyers receive an email that appears to come from the title company or lawyer with updated wiring instructions for the down payment. Always confirm wiring details by calling a number you obtained independently before sending closing funds.

Official sources and further reading

Published September 21, 2026, last updated September 21, 2026. This guide is general education for people in the United States. It is not legal or financial advice, and it cannot tell you whether a particular message or person is genuine. Spot an error? Tell us.

Keep reading