The message arrived as a reply in an existing conversation about a real project, from the supplier's genuine address, with the correct signature and the usual tone. It said the supplier had moved banks, and gave new details for the invoice due on Friday: a little over forty thousand dollars.
It was stopped by a bookkeeper who thought the phrase kindly update your records did not sound like Steve.
How it was done
The supplier's mailbox had been compromised weeks earlier. The attacker did nothing noisy. They created a mailbox rule that quietly moved anything mentioning invoices or payment into a folder the owner never opened, read the conversations at leisure, and waited for a large invoice to come due.
Nothing on our client's side had been breached. No filter would have caught it, because there was nothing wrong with the email except its contents.
The only control that reliably stops payment diversion is a phone call to a number you already had.
The rule we now give everyone
- Any change to bank details is confirmed by phone before it is entered
- The number dialed comes from your own records, never from the message asking for the change
- The person who enters the change is not the person who approves the payment
- Nobody is ever in trouble for delaying a payment to check
The fourth point matters most. The bookkeeper in this story nearly did not raise it, because the invoice was already late and she did not want to look difficult.
Check your own mailbox rules
It takes two minutes. Look for anything you did not create, particularly rules that move or delete messages containing words like invoice, payment or bank, or that forward mail outside the organization. If you find one, do not delete it. Call somebody first; it is evidence.