The invoice that arrives twice
A duplicate of a genuine invoice, same wording and same amount, with one thing changed. Here is why the second one gets paid.
The invoice is real, or was. Someone has seen a genuine one - because a supplier's mailbox was compromised, or yours was - and sent a copy. The wording is identical, the logo is right, the amount matches to the penny. The only difference is the bank account, and one polite line explaining that the supplier has ‘recently changed banks’.
The reason the second one gets paid is not carelessness. It is that everything a person checks against comes back clean. The company name is correct, the reference matches an order you really placed, the figure is what you were expecting. Nothing looks off, because almost nothing is. The single altered field is the one detail no one reads twice.
What makes it worse is timing. These arrive when a real payment is genuinely due, often days after a legitimate invoice, so the duplicate feels like a chase rather than a fresh demand. If your finance work sits with one busy person, or lands in the week someone is on leave, the sort code slides through because the rest of it is beyond question.
The defence is boring and it works: a bank detail never changes on the strength of an email. If a supplier appears to have changed account, you ring them - on a number you already held, not one printed on the new invoice - and you confirm it out loud. Add that one rule and the whole scam has nowhere to land, because the fraud lives entirely in the assumption that nobody will phone.
- ✓Never change a supplier's bank details from an email alone.
- ✓Verify any account change by phone, on a number you already had on file.
- ✓Flag duplicate invoices - same amount, different account - for a second pair of eyes.
- ✓If you have paid one, ring your bank at once and report it to Action Fraud.
- Mandate and invoice fraud: how it works ACTION FRAUD ↗
- Invoice redirection and business email compromise UK FINANCE ↗
- Check before you pay: the callback rule TAKE FIVE ↗
- Phishing and business email compromise guidance NATIONAL CYBER SECURITY CENTRE ↗
Links open each publisher’s live coverage of this topic.