• For whom
    • Small and medium businesses
    • Sales teams
    • Marketing departments
    • Customer service departments
    • For startups
  • Features & Benefits
    • Summary
    • Contact management
    • Process Automation
    • Analytics and Reporting
    • Project management
    • Data security
  • Pricing
  • News
  • Contact
  • English
    • Polski

Try it yourself

Edit Content

Log in to our demo account
and test the capabilities of Epic CRM.

Login - [email protected]
Password - demo

Close

Log in or sign up

Edit Content

Please login to your account

Forgot Password?

Sign In
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Close
Security & Data

Invoice Fraud and Fake Bank Details: Protecting Client Records

July 28, 2026 Krzysztof Balicki Comments Off on Invoice Fraud and Fake Bank Details: Protecting Client Records
Invoice Fraud and Fake Bank Details: Protecting Client Records

One habit stops invoice fraud and business email compromise: never change bank or contact details on the strength of an email alone. Call back on a number you already have on file, and get a second person to approve the change before anything is saved. In late July 2026 the habit matters more than usual, because summer leave puts a stand-in in charge of payments and client email, with fewer colleagues around to double-check. Below is a short verification routine, plus what to do in the first hour if the money has already gone.

Table of Contents

  • How does business email compromise lead to invoice fraud?
  • Why summer stand-ins are the easiest target
  • What a fake bank account change request looks like
  • Verifying bank detail changes: a five-step call-back routine
  • Keeping client records hard to tamper with
  • What to do in the first hour after a suspected fraud
  • FAQ
    • Can invoice fraud happen if the email comes from the real supplier address?
    • Who should approve a bank detail change when the owner is on leave?
    • Is BEC prevention for small business possible without special software?

How does business email compromise lead to invoice fraud?

A criminal spoofs or hijacks a mailbox and asks for a legitimate payment to be sent to an account they control. The message comes from a look-alike address or from a genuinely compromised mailbox replying inside a real thread. It poses as a supplier announcing new bank details, or a client asking to redirect a refund or update contact data. Payment diversion fraud is the same scheme seen from the payer’s side - the invoice is real, only the destination is wrong.

US data reported to the FBI shows an exposed dollar loss of over 55 billion dollars between October 2013 and December 2023, according to the FBI IC3 announcement on business email compromise. The same notice states that the scam targets small local businesses as well as larger corporations.

Why summer stand-ins are the easiest target

Because they lack context. A stand-in doesn’t know the supplier’s usual tone, the invoice rhythm or the contact person, so a forged message slides right through. Out-of-office replies make it worse - they tell the sender who is away and who is covering. The fix is a written routine the substitute follows. Not personal judgement.

What a fake bank account change request looks like

Usually it pairs a new destination for the money with a reason to hurry. The warning signs:

  • new account details arriving shortly before a payment is due
  • pressure to act today
  • a request to keep the matter off the phone
  • a reply-to address that differs from the sender
  • a slightly altered domain name

A hijacked mailbox shows none of the address clues, which is why inspecting the email itself is never enough. The same signals apply to requests to change a client’s contact email or phone, and in my view those deserve the same seriousness, since a swapped address lets the fraudster receive every later invoice and confirmation.

Verifying bank detail changes: a five-step call-back routine

Verifying a bank detail change means confirming it through a channel the sender of the email does not control. Print it and keep it by the payment desk:

  1. Pause the payment and do not reply to the email.
  2. Call the contact on a phone number already on file, never the one in the message.
  3. Confirm the new details verbally, reading them back to the person.
  4. Have a second person approve the change before it is saved.
  5. Record who verified, when and through which channel.

This lines up with the FBI guidance, which advises using secondary channels or two-factor authentication to verify requests for changes in account information. The rule holds for every change, small amounts and long-standing partners included. Exceptions are exactly what an attacker asks for.

Keeping client records hard to tamper with

Client records stay safe when few people can edit them and the trusted phone number lives in the record itself, not in email signatures. So limit who may change contact and payment data. In EpicCRM, roles and permissions restrict editing, while notes in the relationship history on the contact hold the verification record.

Start by reviewing CRM user access before the leave season, so edit rights match the people actually covering. Then spend some time removing stale contact records. An outdated number is useless for a call-back, and a duplicate entry invites the wrong choice under pressure.

What to do in the first hour after a suspected fraud

Call your bank. Ask for a recall of the funds - the FBI guidance stresses that time is of the essence. Then report the case regardless of the amount: IC3 for US incidents, local police or the national reporting body elsewhere.

Change the password of the affected mailbox and check for forwarding rules the intruder may have set. Warn the genuine supplier or client through the number on file, and freeze further changes to that record. If other contact details were overwritten, restoring CRM data from backup in EpicCRM brings back the last trusted version.

None of this depends on spotting a clever forgery. Business email compromise fails against a call-back to a known number, a second approver and a written note on the contact record. Whoever happens to be covering the desk this summer.

FAQ

Can invoice fraud happen if the email comes from the real supplier address?

Yes. A hijacked supplier mailbox sends from the correct address, often inside a genuine thread. Which is exactly why the check is a call-back on a number already on file, not a closer look at the sender.

Who should approve a bank detail change when the owner is on leave?

Two people: one verifies by phone, the other approves. The owner or a named deputy should stay reachable remotely for that second step. Write both names into the routine before the holiday starts.

Is BEC prevention for small business possible without special software?

Yes, because the core defence is procedural. A call-back rule, two-person approval, restricted edit rights and a written record of each verification cover the main risk. The discipline does the work.

Read also:

  • NIS2 Deadline: What Small Businesses and Suppliers Should Know
  • Summer Holiday Cover: Keeping Support and Clients Covered
  • Overdue Invoice Follow-Up: Getting Paid and Keeping the Client
  • Gmail and Yahoo Sender Rules 2024: What Changes for CRM Emails

Post navigation

Previous
Next

Search

Categories

  • Automation & Integrations (33)
  • CRM best practices and tips (56)
  • CRM Guides (42)
  • Customer Support (17)
  • Industry insights and trends (12)
  • Sales Management (45)
  • Security & Data (17)

Recent posts

  • Customer Journey Map for Small B2B Firms: First Call to Renewal
    Customer Journey Map for Small B2B Firms: First Call to Renewal
  • Sales Playbook for Small Teams: What to Write Down First
    Sales Playbook for Small Teams: What to Write Down First
  • Key Account Management for Small B2B Teams: Where to Start
    Key Account Management for Small B2B Teams: Where to Start

Tags

AI analytics automation B2B business business growth Business Software checklist compliance CRM CRM Trends customer data Customer Engagement Customer Retention customer service customer support Data Management data migration data quality Data Security email marketing follow-up forecasting GDPR guide help desk KPI lead generation lead management lead scoring marketing pipeline productivity revenue Sales Sales Forecasting sales management sales metrics sales pipeline sales process sales team small business software spreadsheets workflow

Related posts

Customer Journey Map for Small B2B Firms: First Call to Renewal
CRM Guides

Customer Journey Map for Small B2B Firms: First Call to Renewal

October 8, 2026 Krzysztof Balicki Comments Off on Customer Journey Map for Small B2B Firms: First Call to Renewal

A customer journey map for a small B2B firm is one page. It shows every contact a client has with you, from the first call to the renewal, with a named owner beside each step. Most owners can tell you exactly how deals get won. What happens after the contract is signed? That’s hazier. The […]

Key Account Management for Small B2B Teams: Where to Start
Sales Management

Key Account Management for Small B2B Teams: Where to Start

September 26, 2026 Krzysztof Balicki Comments Off on Key Account Management for Small B2B Teams: Where to Start

Key account management means picking the few clients your business really depends on and giving each one a named owner, a written plan and a regular review. That way they stop sitting in the same queue as everyone else. And plenty of small B2B firms have exactly this problem: a handful of clients bring in […]

Cyber Resilience Act Reporting: What to Ask Your Software Vendors
Security & Data

Cyber Resilience Act Reporting: What to Ask Your Software Vendors

September 25, 2026 Krzysztof Balicki Comments Off on Cyber Resilience Act Reporting: What to Ask Your Software Vendors

The Cyber Resilience Act reporting rules put new duties on manufacturers. Not on the small companies that buy their products. But they do hand you, the buyer, a solid excuse to ask every vendor one thing: how will news of a flaw and its fix actually reach us? What follows is the customer’s side of […]

Do you want to receive news and updates?


    Epic CRM

    CRM for small and medium businesses: sales, tasks, contracts and customer service in one place.

    Resources
    • Features
    • Pricing
    • News
    • FAQ
    • Terms of Service
    • Privacy Policy
    • Cookie Policy
    • DPA
    • Cookie settings
    • Features
    • Pricing
    • News
    • FAQ
    • Terms of Service
    • Privacy Policy
    • Cookie Policy
    • DPA
    • Cookie settings
    Partners
    • Botino: AI voicebots
    • Web Systems Łódź
    • Sellaro: eCommerce integrations
    • MailCraft: email marketing
    • Inteleo: AI assistants
    • Botino: AI voicebots
    • Web Systems Łódź
    • Sellaro: eCommerce integrations
    • MailCraft: email marketing
    • Inteleo: AI assistants

    All rights reserved 2024 - 2026 ©EpicCRM

    • Developed by Web Systems