In short
- The scam is a real invoice from a real supplier with the bank details changed, sent from an inbox that looks right because it is right.
- One habit stops most of it: any change to bank details gets confirmed out loud, on the phone number you already had, before a cent moves.
- If it has already happened, the first hour decides whether the money comes back. Call your bank's fraud line first, then report it to the Canadian Anti-Fraud Centre.
This one works without a virus, a ransom note, or anything on a screen that tells you something is wrong. Somebody reads your email for a few weeks, learns how your business pays its bills, and then sends one invoice that looks exactly like all the others.
Your bookkeeper pays it, because everything about it is normal. The supplier chases the invoice a month later. That is usually the moment anyone finds out.
This guide is how it works, what to check in your own office this week, and what to do in the first hour if it has already happened to you. The short version is at is our email safe from the invoice scam.
How it actually works
Step one: one password. Somebody gets into one mailbox. Usually it is a password reused on another website that was broken into years ago, or a convincing sign-in page that asked for it. The mailbox with two-step sign-in turned off is the one they get.
Step two: they read. For two to six weeks nothing happens. They read the sent items and learn who your suppliers are, how much you normally pay, what your invoices look like, who approves them, how your bookkeeper writes, and when your owner travels. Nobody notices, because nothing has changed.
Step three: a rule hides the replies. They add a rule to the mailbox that moves certain messages straight to a folder nobody opens, or deletes them. Now the real supplier can write to you and the mail never reaches the person it was meant for.
Step four: the lookalike. They register a domain one character away from yours or from your supplier's, so a signature and a return address read correctly at a glance. The reply goes to them.
Step five: the invoice. A genuine invoice, the right amount, the right project, sent at the right time of the month, with one difference: the bank details. Often it arrives with a friendly line about the company having changed banks, and a note asking you to update your records for future payments as well.
Step six: the pressure. A gentle deadline. The last day of the month, a supplier who needs it before the long weekend, a discount that expires. Time pressure exists to stop the one phone call that would end the whole thing.
Step seven: the money moves. The payment lands in an account opened for this purpose and leaves it within hours, usually in pieces. Recovery is a matter of hours, so the value of noticing quickly is enormous.
The three shapes it takes
The supplier who changed banks. The one described above. It is the most common, and it is the most costly, because the amounts match invoices you already expected to pay.
The urgent request from the owner. A short message that reads exactly like you: I am in a meeting, can you get this transfer out today, I will explain later. It targets the person who would find it hard to say no to you.
The payroll change. A message that appears to come from a staff member, asking to update the bank account their pay goes into, sent a few days before payday. Small amounts, easy to miss, and it repeats every month until somebody complains that their pay never arrived.
Ten things to check in your office this week
- Two-step sign-in on every mailbox. Start with the owner, the bookkeeper and anyone who can move money. This is the single change that removes most of the risk, and it costs nothing but an afternoon.
- Look at the mail rules on those mailboxes. Your email service lists them in its settings. A rule that forwards, moves or deletes messages that nobody in the business created is a sign somebody else has been in there.
- Write down one rule about bank details. Any change to where money is sent is confirmed by voice, on the number you already had on file, before a payment goes out. The number in the email signature is the scammer's number often enough that using it is the same as not checking.
- Two people on payments above a line you set. Pick the amount. One person prepares, a different person releases. Say it out loud to both of them so neither feels awkward asking.
- Check that the reply address matches the sender. Ask your staff to click the sender's name and read the actual address, especially on anything about money. The display name is decoration, and anyone can put yours in it.
- Set up SPF, DKIM and DMARC on your domain. These three settings tell the rest of the world which servers may send email in your name. They make it far harder for anyone to write to your clients as you.
- Keep supplier bank details in one place, with a note of every change. Who changed it, when, and who confirmed it by phone. A one-line log turns a lucky catch into a system.
- Train the person who pays the bills, and tell them they will never be in trouble for calling to check. The scam works on the social cost of questioning the boss. Remove that cost yourself, in front of everybody.
- Ask your bank what it offers. Most Canadian business banks have controls that hold or flag payments to new recipients, and limits you can set on outgoing transfers. They are free and rarely mentioned unless you ask.
- Look at what has been registered near your name. Check whether domains one letter away from yours exist. Registering the two or three closest lookalikes yourself costs very little a year.
If it has already happened, the first hour
Call your bank's fraud line, immediately. Use the fraud number printed on your statement, by telephone. Ask them to recall the payment. If the money is still in the receiving account, this is the only thing that gets it back, and the window is hours.
Ask your bank to contact the receiving bank. They can freeze what is left.
Change the password on every mailbox involved, and sign every session out. A new password alone leaves anyone already signed in exactly where they were. Your email service has an option to revoke all sessions.
Turn on two-step sign-in before you do anything else with that mailbox.
Look for the mail rules and remove them, and keep a copy of what they said first.
Keep everything. The original emails with their full headers, the invoice, the payment record. Forwarding the message strips the evidence, so leave the originals where they are and take screenshots.
Report it to the Canadian Anti-Fraud Centre, and to your local police. Your insurer and your bank will both ask for the file number.
Tell the real supplier, on a number you already had. Their mailbox may be the one that was broken into, and other customers of theirs are being sent the same invoice this week.
Work out whether personal information was exposed. If the mailbox held personal details about clients, patients or staff, Canadian privacy law may require you to notify the people affected and the Privacy Commissioner. That decision has a deadline, and it is worth an hour of professional advice the same day.
Tell your own staff what happened, in plain terms. The second attempt usually arrives within days, aimed at somebody else in the office.
Why careful people still fall for it
The message is genuine in every way that a careful person checks. It arrives in an existing thread, in the right tone, about a real invoice, on the day such an invoice normally arrives. There is nothing misspelled, because it was written by somebody who has read a month of your correspondence.
That is why the defence is a habit rather than an eye for detail. The phone call to a number you already had works whether or not the email looks perfect, and it takes ninety seconds.
Where this sits in the rest of your setup
Email is the account that unlocks everything else, because it is where password resets land. A mailbox with two-step sign-in turned off is the loose thread on the whole business.
The wider list of what to check is in our infrastructure checklist. If the person who used to look after this has left, start with the first week after your IT person quits. Clinics carry additional duties under Ontario's PHIPA and should read what we do for practices, and the day-to-day work of keeping logins, mail rules and domains under control is described on the managed IT page.
Have someone check this for you
Leave your name and number on the contact page and a person calls you back the same business day, usually within an hour. Say it is about email and we will treat it as the priority it is.
The free infrastructure audit covers two-step sign-in, mail rules, your domain settings and who has access to what, and hands you a written report in plain English. It costs nothing and there is nothing to sign.
If money has already moved, call your bank first and us second.
itopsi is a managed IT provider working with Canadian businesses from a Toronto base.
