Invoice Fraud and Fake Bank Details: Protecting Client Records
One habit stops invoice fraud and business email compromise: never change bank or contact details on the strength of an email alone. Call back on a number you already have on file, and get a second person to approve the change before anything is saved. In late July 2026 the habit matters more than usual, because summer leave puts a stand-in in charge of payments and client email, with fewer colleagues around to double-check. Below is a short verification routine, plus what to do in the first hour if the money has already gone.
Table of Contents
How does business email compromise lead to invoice fraud?
A criminal spoofs or hijacks a mailbox and asks for a legitimate payment to be sent to an account they control. The message comes from a look-alike address or from a genuinely compromised mailbox replying inside a real thread. It poses as a supplier announcing new bank details, or a client asking to redirect a refund or update contact data. Payment diversion fraud is the same scheme seen from the payer’s side - the invoice is real, only the destination is wrong.
US data reported to the FBI shows an exposed dollar loss of over 55 billion dollars between October 2013 and December 2023, according to the FBI IC3 announcement on business email compromise. The same notice states that the scam targets small local businesses as well as larger corporations.
Why summer stand-ins are the easiest target
Because they lack context. A stand-in doesn’t know the supplier’s usual tone, the invoice rhythm or the contact person, so a forged message slides right through. Out-of-office replies make it worse - they tell the sender who is away and who is covering. The fix is a written routine the substitute follows. Not personal judgement.
What a fake bank account change request looks like
Usually it pairs a new destination for the money with a reason to hurry. The warning signs:
- new account details arriving shortly before a payment is due
- pressure to act today
- a request to keep the matter off the phone
- a reply-to address that differs from the sender
- a slightly altered domain name
A hijacked mailbox shows none of the address clues, which is why inspecting the email itself is never enough. The same signals apply to requests to change a client’s contact email or phone, and in my view those deserve the same seriousness, since a swapped address lets the fraudster receive every later invoice and confirmation.
Verifying bank detail changes: a five-step call-back routine
Verifying a bank detail change means confirming it through a channel the sender of the email does not control. Print it and keep it by the payment desk:
- Pause the payment and do not reply to the email.
- Call the contact on a phone number already on file, never the one in the message.
- Confirm the new details verbally, reading them back to the person.
- Have a second person approve the change before it is saved.
- Record who verified, when and through which channel.
This lines up with the FBI guidance, which advises using secondary channels or two-factor authentication to verify requests for changes in account information. The rule holds for every change, small amounts and long-standing partners included. Exceptions are exactly what an attacker asks for.
Keeping client records hard to tamper with
Client records stay safe when few people can edit them and the trusted phone number lives in the record itself, not in email signatures. So limit who may change contact and payment data. In EpicCRM, roles and permissions restrict editing, while notes in the relationship history on the contact hold the verification record.
Start by reviewing CRM user access before the leave season, so edit rights match the people actually covering. Then spend some time removing stale contact records. An outdated number is useless for a call-back, and a duplicate entry invites the wrong choice under pressure.
What to do in the first hour after a suspected fraud
Call your bank. Ask for a recall of the funds - the FBI guidance stresses that time is of the essence. Then report the case regardless of the amount: IC3 for US incidents, local police or the national reporting body elsewhere.
Change the password of the affected mailbox and check for forwarding rules the intruder may have set. Warn the genuine supplier or client through the number on file, and freeze further changes to that record. If other contact details were overwritten, restoring CRM data from backup in EpicCRM brings back the last trusted version.
None of this depends on spotting a clever forgery. Business email compromise fails against a call-back to a known number, a second approver and a written note on the contact record. Whoever happens to be covering the desk this summer.
FAQ
Can invoice fraud happen if the email comes from the real supplier address?
Yes. A hijacked supplier mailbox sends from the correct address, often inside a genuine thread. Which is exactly why the check is a call-back on a number already on file, not a closer look at the sender.
Who should approve a bank detail change when the owner is on leave?
Two people: one verifies by phone, the other approves. The owner or a named deputy should stay reachable remotely for that second step. Write both names into the routine before the holiday starts.
Is BEC prevention for small business possible without special software?
Yes, because the core defence is procedural. A call-back rule, two-person approval, restricted edit rights and a written record of each verification cover the main risk. The discipline does the work.



