Protecting a business from fraud that arrives by email
- Aug 29
- 3 min read
Updated: 4 days ago
Introduction
An email arrives from a supplier the business has used for years, saying their bank details have changed and attaching a letter on headed paper. The next invoice is paid to the new account. The supplier never sent the email and the money is gone within hours.
Small businesses are targeted because the controls that would catch this do not exist. One person raises, approves and pays, verification is a matter of trust, and there is no separation of duties because there are only four people. Nearly all of the common frauds are defeated by a small number of habits. None of them requires software, a consultant or a budget.
1. Protecting a business from fraud starts with the payment process
Where the money actually leaves.
Almost every significant fraud against a small business ends in a payment being made. Controlling how payments are authorised and to whom is worth more than every other measure combined.
2. Verify bank detail changes by telephone
The single most valuable rule.
Any request to change payment details is verified by calling a number you already hold, not one from the email. This one habit defeats the most common and most expensive attack, and it costs a two-minute call. It works even when the email is a perfect copy of genuine correspondence.
3. Require two people for significant payments
Even in a very small business.
A second pair of eyes on anything above a threshold, even if the second person is the owner's partner or the bookkeeper. Sole authority over payments is the condition every fraud depends on. Remove that and most attacks have nowhere to conclude.
4. Watch for urgency and secrecy
The consistent signals.
Requests that are urgent, confidential, outside normal process, or that discourage checking with anybody. These are the characteristics of the attack rather than of legitimate business, and staff should be told to expect them.
5. Secure email accounts properly
Where the compromise usually begins.
Multi-factor authentication on every email account, particularly those handling invoices and payments. A compromised mailbox lets an attacker read correspondence and time their request perfectly.
6. Give staff permission to check
The cultural part.
Employees do not challenge an urgent instruction that appears to come from the owner. Saying explicitly and repeatedly that verifying is always correct, and that nobody will be criticised for it, is what makes the controls work.
7. Reconcile accounts frequently
Detection when prevention fails.
Weekly reconciliation catches an unauthorised payment while there is still a chance of recovery. Monthly or quarterly checking finds it long after the money has moved through several accounts. It also catches the small test payment that frequently precedes a larger one.
8. Control who has access to what
Basic and neglected.
Banking access, accounting systems and payment cards, reviewed when roles change and removed immediately when somebody leaves. Long-departed staff retaining access is extremely common.
9. Act within hours if it happens
Speed determines recovery.
Contact the bank immediately, then the police or relevant authority, then your insurer. Recovery is occasionally possible in the first hours and almost never possible after a day. Banks can sometimes recall a payment that has not yet been withdrawn from the receiving account.
Consider internal fraud as well, uncomfortable as that is. Long-serving trusted staff with sole control over an area account for a meaningful share of losses, and the controls that prevent it — separation of duties, reconciliation, mandatory holidays — protect honest employees from suspicion as much as they protect the business.
Conclusion
Concentrate on the payment process, because that is where every fraud concludes.
Verify any change of bank details by calling a number you already hold, require a second person for significant payments, treat urgency and secrecy as warning signs, enable multi-factor authentication on email accounts, tell staff explicitly that checking is always acceptable, reconcile accounts weekly, review and remove system access when roles change, act within hours if it happens, and put in place the controls that address internal as well as external risk.
.png)



Comments