invoice fraud

Invoice fraud with a changed IBAN: approval steps that protect finance

AA
Aurum Avis Labs Author
8 min read

Invoice fraud with a changed IBAN: what to do before you pay

Invoice fraud with a changed IBAN happens when someone intercepts or impersonates supplier communication and sends a genuine-looking invoice with new bank details. In Swiss reporting this falls under business email compromise. The PDF can look correct and the amount can match a real order. Only the payment instruction has changed.

Your first job is to stop the outgoing payment and verify the account on a channel you already trust. Then fix how master data and approvals work, so the next attempt fails earlier. BACS describes attackers who take over a mailbox and resend real invoices with a new IBAN. It recommends a phone callback, awareness training for finance staff, two-factor authentication, clear payment processes and a check of mail forwarding rules.

Fraud made up 52 percent of reports in BACS’s second-half 2025 figures. Training for finance teams usually covers this pattern alongside phishing; security awareness training topics lists what a session can include. The four-eyes principle for payments has its own checklist article. This one is about verification when the IBAN on the invoice does not match your records.

  1. Hold the payment

    Do not release the batch until bank details are confirmed. Note who received the invoice and when.

  2. Compare master data

    Match the IBAN against your supplier record, not only against the last PDF in the thread.

  3. Call the supplier

    Use a number from your contract or an old invoice, not from the email you are checking.

  4. Report internally

    Tell IT if the mailbox may be compromised; check forwarding rules and recent logins.

  5. Document and learn

    Record what happened for insurance and audit, even if no money left.

Why changed IBAN fraud works in SMEs

Many companies with 20 to 250 people run lean finance. One person matches invoices, another approves, and urgent suppliers get fast-tracked. Attackers watch for that rhythm. They may take over the supplier’s mailbox or your purchasing inbox, or write from a look-alike domain. The invoice itself looks normal, so automated checks on amount and VAT ID still pass.

  • ChannelEmail

    Most cases start in the thread you already use with the supplier.

  • ChangeIBAN only

    Layout, logo, and amounts often stay plausible.

  • GoalOutbound pay

    Money leaves before anyone calls back.

How to spot an IBAN change in the thread

Watch for the signals that filters miss:

  • A sender address one character off your usual domain.
  • A footer saying «new bank details effective immediately» while the rest of the invoice looks unchanged.
  • A PDF that matches the template but carries a different QR-bill or reference number.

Sometimes the mail really does come from the supplier’s mailbox, because someone logged in there and swapped only the payment line.

IT can analyse the mail headers if needed. For accounts payable, two questions often suffice: does the IBAN match the ERP, and who announced the change in writing before the invoice arrived?

Where other rules take precedence

CEO fraud is a different pattern: a message from the boss asks for a transfer by chat. For new bank details, add a second checker before payment. This is not legal advice on recovering funds: after a wrongful payment, your bank and the police take over.

Limits of email and PDF checks alone

An email can pass SPF and DKIM and still carry a fraudulent IBAN. A signed PDF does not prove that the bank details are unchanged since the last legitimate invoice. OCR and three-way matching catch duplicates and quantity mismatches. They do not catch social engineering inside a real thread.

A made-up example: Tuesday afternoon in accounts payable

A made-up example: a trading company with 45 staff. On Tuesday, accounts payable receives a PDF invoice from a long-standing packaging supplier. The amount matches the purchase order, but the IBAN in the footer differs from the one stored in the ERP by two digits. The clerk pauses the payment run and calls the number on last month’s invoice. The supplier says it has not changed banks. Its own IT then finds a forwarding rule in the compromised mailbox that copied threads to an external address. No payment went out. The trading company adds a rule: any IBAN change needs a phone confirmation, logged in the ticket system, before approval.

If the payment has already left

Act on the day you discover it.

  1. Call your bank at once and ask for a recall or a block.
  2. Report it to the police and note the reference number.
  3. Tell IT and management.
  4. Keep the email, the PDF, the bank statement and the approval timestamps.

Recovery depends on deadlines and on the receiving account. This article is not legal advice.

Insurers will later ask who approved, which IBAN sat in the ERP and which callback never happened. The earlier you have that in writing, the calmer the conversation, even if the money does not come back.

Who may change supplier IBAN in your systems

In small teams, any assistant may maintain master data. For attackers that is the shortest path: one phishing click, a replaced IBAN in the ERP, then the «normal» invoice from the thread. Separate «capture invoice» from «change bank details». Whoever can change an IBAN needs a second pair of eyes and a callback before the next run pays the new number.

Purchasing may approve orders and finance may pay. Both should know that a changed IBAN always stops the payment, whether or not something «feels odd».

Who should skip elaborate process work for now

If you make only a handful of supplier payments a month and every beneficiary is domestic and long known, a short written rule plus phone verification may be enough until volume grows. If you pay abroad, work with many new suppliers, or let assistants edit master data alone, put approval steps in place before the next audit or insurance questionnaire.

When a short rule is enough

  • Few fixed suppliers, same IBAN for months
  • One person sees every invoice before release

When to tighten earlier

  • Many new suppliers or cross-border payments each quarter
  • Several people can edit master data without a second checker

Technical hygiene that supports finance

Among its BEC recommendations, BACS lists two-factor authentication on business email and a review of forwarding rules. After any suspected fraud, your IT partner can search for automatic forwarding to external addresses and for unfamiliar inbox rules. That does not replace the phone call, but it closes a common entry path.

Ask whether purchasing shares the same mailbox password habits as finance. Shared credentials in a small team let an attacker move from a phishing click to the invoice threads in one step. Multi-factor authentication for everyone who can change supplier records belongs in the same programme as finance awareness.

  • Remove forwards to private or unknown addresses
  • Review purchasing and finance mailboxes for unfamiliar sign-in locations
  • Do not release payment while IBAN and ERP still disagree

Questions insurers and auditors ask after a near-miss

Cyber insurance applications and customer audits often ask how you verify changes to bank details. A one-page internal rule plus a logged callback convinces most reviewers more than an informal «we usually call». Keep the log minimal: date, supplier name, who confirmed, and the IBAN agreed. You do not need a software project to start.

If money has already left, insurers will want the timeline, the original invoice, the fraudulent instruction and the police reference number. Documenting from the day you find the mismatch speeds up that conversation, even when recovery fails.

Should we report a near-miss with a changed IBAN?

Internally, yes: treat it as a security incident. Externally, voluntary reports to BACS feed the Swiss statistics. The statutory cyberattack reporting duty applies to operators of critical infrastructure, not to most SMEs.

Is it enough to confirm the IBAN by email?

No. If the thread is compromised, the attacker will answer. Call a number you used before the incident.

Closing the loop with staff training

Finance is the last gate, but purchasing and assistants often see the forged thread first. A live security awareness session of one to two hours can walk through invoice fraud, CEO urgency and how to report odd mail without blame. The security awareness page describes the remote and on-site options in Switzerland.

Before a session, take a short look at your three most frequent suppliers: where does the IBAN sit today, who may change it, and who calls back when something differs? Those three answers are often enough to start the session with, and you do not need to share any confidential amounts.

Reporting to authorities and voluntary notices

A misdirected payment is a matter for the bank and the police. You can also report it to BACS voluntarily, which feeds the statistics and warnings to other businesses. That is a different thing from the reporting duty for critical infrastructure in force since April 2025. Keep the two apart when management asks about «mandatory reporting».

invoice fraud iban business email compromise payments
AA

Written by

Aurum Avis Labs

Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.

Customize your cookie preferences. Essential cookies cannot be disabled as they are required for the website to function properly.

Essential Cookies

Required for basic website functionality, security, user authentication, and error tracking.

Always active

Analytics Cookies

Help us understand how visitors interact with our website to improve user experience. Includes Google Analytics and Microsoft Clarity session recordings.

Marketing Cookies

Used to track visitors across websites to display relevant and engaging advertisements.