Architecture firms send and receive invoices all the time. Owners pay fee invoices, and the firm pays engineers, renderers, and other consultants. Attackers exploit that flow with invoice fraud, where a fake or altered message redirects a real payment to a criminal’s bank account.
How the scam usually works
The most common version starts with a compromised mailbox. An attacker gets into an email account at your firm, a client, or a consultant. Then they read quietly for weeks and learn who pays whom, how often, and in what tone.
Next, they strike at a natural moment. For example, they reply inside a real invoice thread and say the bank details have changed. Because the message looks familiar, the recipient updates the payment and sends the money.
Other versions skip the break-in. Instead, the attacker registers a lookalike domain that differs from yours by one letter. They then email your client from that domain with a new invoice and new banking instructions.
Why design firms make easy targets
Architecture work involves many parties and many invoices. A single project may include the owner, a developer’s representative, several engineering consultants, and specialty designers. So your accounting staff sees a steady stream of payment requests from outside the firm.
In addition, fee invoices on large projects can be significant. That makes a single redirected payment painful for the firm or the client. It can also damage a relationship that took years to build, even when the firm did nothing wrong.
Build a payment verification process against invoice fraud
The strongest defense is a process, not a product. Specifically, never change payment details based on an email alone. Instead, verify every change through a separate channel that the attacker cannot control.
- Treat any request to change bank details as suspicious by default.
- Call the vendor or client at a number you already have on file, not one in the email.
- Confirm the change with a person you know, and record who confirmed it.
- Require a second person to approve new or changed payment details.
- Hold the first payment to new details until someone confirms receipt.
- Flag urgent or secretive payment requests for a manager’s review.
Also, write this process down and share it with every consultant you pay. When they know you will call, they are less likely to fall for fake messages about your firm.
Tell clients how you will bill them
Your clients are targets too. Attackers may pose as your firm and send them fake invoices. Therefore, set expectations at the start of each engagement.
For example, state in your proposal or agreement that your firm will never change bank details by email. Tell clients to call a known contact at the firm before paying any invoice with new instructions. That one sentence can stop a costly mistake.
Harden your email domain
Technical controls make impersonation harder. First, publish SPF, DKIM, and DMARC records for your domain. Together, these standards help receiving mail servers reject messages that pretend to come from you.
Next, move your DMARC policy toward enforcement once you confirm legitimate mail passes. Then add external sender warnings so staff see a banner on outside email. As a result, a message from a lookalike domain stands out more clearly.
In addition, consider watching for newly registered domains that resemble yours. Early warning gives you time to alert clients before an attack lands.
Protect the mailboxes attackers want
Many invoice fraud cases begin with a stolen password. So protect the accounts that handle billing and payments with extra care.
- Require MFA for all staff, especially accounting and principals.
- Block automatic forwarding of email to outside addresses.
- Alert on new inbox rules that move or delete messages.
- Review sign-in activity for unusual locations or devices.
Finally, train staff to pause when a message creates urgency around money. A short, regular training program works better than a single annual session.
What to do if a payment goes to the wrong account
Speed matters most. Call your bank right away and ask them to attempt a recall of the transfer. Then contact your IT provider to check for a compromised mailbox, and notify your cyber insurer.
Also, report the incident to law enforcement through the appropriate channel, and preserve the emails involved. Your insurer and counsel can guide the next steps, including any client notifications.
How WEBIT helps
WEBIT’s Security Advanced add-on includes email security, Microsoft 365 threat detection and response, security awareness training, and dark web monitoring. Together, these tools help catch compromised accounts and suspicious messages sooner. We can also add Duo MFA for stronger sign-in protection.
Our team can review your email domain settings and payment workflows with you. Learn more about our cybersecurity services, or visit our architecture firm IT page.
Key takeaways
- Never change payment details based on an email alone.
- Verify changes by phone using a number already on file.
- Tell clients in writing that you never change bank details by email.
- Publish SPF, DKIM, and DMARC, and move toward enforcement.
- Protect billing mailboxes with MFA and alerts on inbox rules.