Case Study · Accountancy practice

Accountancy Practice: A £48,000 Invoice Redirection Stopped by a Phone Call

The mailbox had been compromised for five weeks. The amended invoice was perfect. What stopped it was a verification policy written three months earlier.

Client
Accountancy practice
Sector
Accountancy practice
Size
31 staff
Location
Leicester, UK
In short

How is invoice redirection fraud detected before the money leaves?

By verifying every change to bank details on a telephone number held before the request arrived. In this case the finance manager called the supplier on a number from an old contract rather than the one in the email signature, and the supplier confirmed no change had been requested.

The challenge

A supplier to the practice had their mailbox compromised. The attacker sat quietly

for five weeks, reading the thread in which the practice discussed a routine payment, then replied

from the genuine account with amended bank details and a plausible explanation about a banking

migration.

The email was in the right thread, from the right address, in the supplier's usual tone, at exactly

the point a payment was due. Every technical control the practice had was working correctly and had

nothing to detect.

The payment was £48,000.

What we did

What happened on the day

The finance manager followed a verification procedure we had written into the practice's payment

process three months earlier: any change to bank details is confirmed by telephone, on a number held

before the request arrived.

She called the number from the original engagement letter rather than the one in the email signature.

The supplier confirmed they had not requested any change. The payment was held.

What we did next

  1. Confirmed the compromise was on the supplier's side, not the practice's — the practice's own

tenant showed no anomalous sign-ins

  1. Advised the supplier's own IT provider, with the practice's consent, so they could contain it
  2. Reviewed the practice's exposure: which other threads that supplier's mailbox had visibility of,

and whether any other payment was in flight

  1. Hardened the practice's own email: MFA coverage confirmed across all accounts, legacy

authentication blocked, alerting configured for new mailbox rules and external forwarding

  1. Moved DMARC from monitoring to enforcement so the practice's own domain could not be spoofed in

the same way

  1. Ran a briefing for the whole practice, not just finance, using the actual email as the example

The outcome

The payment never left. The practice's own systems were confirmed uncompromised, and

the supplier was alerted early enough to contain their incident.

  • £48,000 payment stopped before transfer
  • No compromise of the practice's own tenant
  • Alerting now in place for mailbox rule creation and external forwarding
  • DMARC moved to enforcement across the practice's domain
  • Payment verification procedure extended to cover all suppliers, not just new ones

The practice's managing partner made the point that the control which saved the money cost nothing.

It was a sentence in a process document and a willingness to make a phone call that felt slightly

awkward.

This case study is published anonymously. Neither the practice nor the supplier is identified, and

the figure is reported with the practice's permission.

Why we publish this one

Because the defence was not technology. Every technical control in the practice was configured

correctly and none of them could have caught this — the message came from a genuine account in a

genuine thread.

Process beats technology for this specific attack, and it is the cheapest control any business can

adopt. Confirm bank details by telephone, on a number you already held. Put it in your client care

letters. Make it awkward to skip.

Published anonymously. Identifying details have been removed or generalised, and no client is named without written consent. Outcomes described relate to this engagement and are not a guarantee of results elsewhere.