How it actually runs
It starts with one password. Reused on another site that was breached, typed into a convincing sign-in page, or simply guessable. Nothing happens for weeks after that, which is the part owners find hardest to believe. Somebody reads. They learn who approves payments, who your suppliers are, and how your invoices are worded.
Then they set a quiet mail rule that files certain replies into an unused folder, so the conversation only reaches them. They wait for a real invoice to come up. The message that arrives looks ordinary, mentions the right project, and carries new banking details, sometimes from a domain one letter different from the real one. The money leaves on a Friday.
Signs somebody is already in the mailbox
Replies that people swear they sent and you never saw. Mail rules or forwarding you did not create. Items in the sent folder you do not remember writing. A supplier asking about a message nobody at your end wrote. A sign-in alert from a place none of your staff has been.
Any one of those is worth an hour of somebody’s attention today. They are far cheaper to check than to explain to your bank later.
What actually stops it
A second step on every login, including the owner’s and the bookkeeper’s. This one control ends most stolen-password attacks on its own, because the password stops being enough.
An alert whenever a new mail rule or forwarding address is created, so the quiet part of the attack makes a noise.
The three settings on your domain that make it harder for anyone to send mail that looks like it came from you. They go by the initials SPF, DKIM and DMARC, they are configured once, and your staff never see them.
Registering the two or three obvious lookalike versions of your domain, so nobody else can.
A written payment rule: no change of bank details is acted on from an email alone, ever, and confirmation happens by phoning a number you already had on file. Tell the people who pay invoices, in plain terms, that slowing a payment down will never get them in trouble.
The first hour, if money already moved
Call your bank and ask for a recall immediately, because the chance of getting funds back falls away by the hour. Change the password on the mailbox and sign every session out, so the reading stops. Check the mail rules and remove the ones you did not create. Keep the messages exactly as they are, headers included, since they are the evidence.
Then tell your insurer, tell whoever else was in the conversation, and check whether any other mailbox in the office shows the same signs. A person here calls you back the same business day, usually within an hour, and can work the list with you.