Trade contractors pay a steady stream of invoices to equipment distributors, supply houses, and subcontractors. Criminals know this, so they target the people who approve those payments. Supplier invoice and payment fraud usually starts with an email that looks completely normal.
This guide explains how the schemes work and how to stop them.
How supplier scams reach your office
The most common scheme is simple. A criminal breaks into a supplier’s email account, or sets up a lookalike domain. Then they send your office a message saying the supplier has new bank details.
The email often arrives in a real thread about a real order. For example, it might reference the rooftop units you ordered last week. Because the details match, your bookkeeper has no reason to doubt it.
Other versions target you from the inside. A fake message “from the owner” asks the office manager to wire a deposit for a large commercial job today. The urgency is the point, since it pushes people to skip their normal checks.
Warning signs your team should know
No single sign proves fraud. Still, certain patterns should make anyone pause before paying. Teach everyone who touches payables to watch for these:
- A request to change bank account or remittance details, for any reason.
- A sender address that is one letter off from the real supplier’s domain.
- Pressure to pay today, keep the request quiet, or skip normal approval.
- An invoice that arrives outside your usual supplier portal or process.
- A reply-to address that differs from the address shown as the sender.
Also watch for small changes in writing style or signature blocks. Criminals copy templates well, but they often miss the tone of someone you know.
Build a verification process that stops payment fraud
Technology helps, but process stops most losses. The core rule is simple: never trust payment instructions that arrive by email alone.
- Call the supplier using a phone number you already have on file, never one from the email.
- Confirm any bank change with a known contact before updating your vendor record.
- Require a second person to approve new payees and changed account details.
- Set a dollar threshold above which every payment needs dual approval.
- Hold new bank details for a short waiting period before the first payment.
- Log each verification call with the date, contact name, and who made it.
Next, write this process down and make it the only way changes happen. That way, nobody has to feel rude when they refuse to skip a step for the owner.
Lock down the email accounts behind payables
Many payment scams succeed because an attacker is already inside your own mailbox. Once there, they watch conversations and time their fake invoice perfectly. So protecting email is protecting cash.
First, require multifactor authentication on every Microsoft 365 or email account. Then turn on alerts for suspicious sign-ins and new inbox forwarding rules. Attackers often create hidden rules that move supplier replies out of sight.
In addition, use email filtering that flags lookalike domains and external senders. A clear “external” banner on messages helps staff notice when the “owner” is writing from outside the company.
Work with your bank and suppliers
Your bank offers tools that many contractors never use. For instance, positive pay compares checks and ACH debits against the payments you approved. Many banks also support dual authorization for wires and new ACH payees.
Likewise, talk with your major suppliers about how they will communicate changes. Some will agree to confirm changes only through their secure portal. Others will simply appreciate knowing you will call to verify.
What to do if a payment goes out
Speed matters more than anything else. If you suspect payment fraud, call your bank immediately and ask them to recall the transfer. Then report the incident to the FBI’s Internet Crime Complaint Center (IC3).
After that, reset passwords on any affected email accounts and check for forwarding rules. Finally, contact your cyber insurance carrier, because many policies require prompt notice.
How WEBIT helps
WEBIT protects the email accounts and devices your payables team depends on. Our Security Advanced add-on provides Microsoft 365 threat detection and response, email security, and security awareness training. Together they help catch lookalike domains, suspicious sign-ins, and hidden inbox rules.
We also help you document an approval process that fits a busy contracting office. Explore our cybersecurity services or contact our team to review your current setup.
Key takeaways
- Most supplier scams begin with a compromised or lookalike email account.
- Never change bank details based on an email alone; call a known number.
- Dual approval and waiting periods catch fraud before money moves.
- Multifactor authentication and inbox rule alerts protect payables email.
- If money goes out, call your bank first and act within hours.