Accountancy Practice: A £48,000 Invoice Redirection Stopped by a Phone Call
The mailbox had been compromised for five weeks. The amended invoice was perfect. What stopped it was a verification policy written three months earlier.
How is invoice redirection fraud detected before the money leaves?
By verifying every change to bank details on a telephone number held before the request arrived. In this case the finance manager called the supplier on a number from an old contract rather than the one in the email signature, and the supplier confirmed no change had been requested.
The challenge
A supplier to the practice had their mailbox compromised. The attacker sat quietly
for five weeks, reading the thread in which the practice discussed a routine payment, then replied
from the genuine account with amended bank details and a plausible explanation about a banking
migration.
The email was in the right thread, from the right address, in the supplier's usual tone, at exactly
the point a payment was due. Every technical control the practice had was working correctly and had
nothing to detect.
The payment was £48,000.
What we did
What happened on the day
The finance manager followed a verification procedure we had written into the practice's payment
process three months earlier: any change to bank details is confirmed by telephone, on a number held
before the request arrived.
She called the number from the original engagement letter rather than the one in the email signature.
The supplier confirmed they had not requested any change. The payment was held.
What we did next
- Confirmed the compromise was on the supplier's side, not the practice's — the practice's own
tenant showed no anomalous sign-ins
- Advised the supplier's own IT provider, with the practice's consent, so they could contain it
- Reviewed the practice's exposure: which other threads that supplier's mailbox had visibility of,
and whether any other payment was in flight
- Hardened the practice's own email: MFA coverage confirmed across all accounts, legacy
authentication blocked, alerting configured for new mailbox rules and external forwarding
- Moved DMARC from monitoring to enforcement so the practice's own domain could not be spoofed in
the same way
- Ran a briefing for the whole practice, not just finance, using the actual email as the example
The outcome
The payment never left. The practice's own systems were confirmed uncompromised, and
the supplier was alerted early enough to contain their incident.
- £48,000 payment stopped before transfer
- No compromise of the practice's own tenant
- Alerting now in place for mailbox rule creation and external forwarding
- DMARC moved to enforcement across the practice's domain
- Payment verification procedure extended to cover all suppliers, not just new ones
The practice's managing partner made the point that the control which saved the money cost nothing.
It was a sentence in a process document and a willingness to make a phone call that felt slightly
awkward.
This case study is published anonymously. Neither the practice nor the supplier is identified, and
the figure is reported with the practice's permission.
Why we publish this one
Because the defence was not technology. Every technical control in the practice was configured
correctly and none of them could have caught this — the message came from a genuine account in a
genuine thread.
Process beats technology for this specific attack, and it is the cheapest control any business can
adopt. Confirm bank details by telephone, on a number you already held. Put it in your client care
letters. Make it awkward to skip.
Published anonymously. Identifying details have been removed or generalised, and no client is named without written consent. Outcomes described relate to this engagement and are not a guarantee of results elsewhere.