Invoice fraud often begins with email.
An attacker may compromise a vendor mailbox or impersonate a supplier and ask the business to send future payments to a new bank account.
The request may look completely normal.
Businesses should create a rule that bank changes are never approved by email alone.
Call the vendor using a known phone number, not a number included in the suspicious message.
The same process should apply to unusual payment requests, large transfers, or urgent changes to normal procedures.
MFA and email security reduce the chance of mailbox compromise, but financial verification procedures protect the business even when an email looks legitimate.
A few minutes spent verifying a change can prevent a payment from being sent to a criminal account.
