The scam that starts with a real conversation
The most convincing frauds do not start with a suspicious email. They start with a genuine one the attacker has been quietly reading for weeks.
The warning we all learned is to spot the odd email out - the badly written one, the unexpected one, the one from a stranger. The frauds that catch careful businesses do not look like that, because they do not come from a stranger. They come from the middle of a conversation you are genuinely having, one an attacker has been reading silently after quietly getting into one mailbox.
Here is how it works. Someone's email is compromised, often through a phished password. The attacker does not act. They watch - a thread with a supplier about an outstanding invoice, the back-and-forth over a property completion, the run-up to a big payment. They learn the names, the tone, the amounts, the timing. Then, at exactly the right moment, they reply within the real thread: “Quick note, our bank details have changed, please use the account below for this one.”
It works because every signal you are trained to check comes back reassuring. The sender is right, the history is right, the subject line is a thread you started, the request fits the deal you were already doing. The only thing that has changed is the bank account, and that is the one detail email is uniquely bad at verifying. This is the fraud behind a great many of the large, painful losses we see in conveyancing and in supplier payments.
The defence is a habit that ignores the email entirely. Any change of bank details, and any first payment to a new account, gets confirmed by phone on a number you already had - not the number in the email signature, which the attacker controls too. It feels over-cautious right up to the day it saves a five-figure payment. Pair that with two-factor authentication on email, which stops the mailbox being read in the first place, and you have closed both ends.
- ✓Confirm any change of bank details by phone, on a number you already held, before paying.
- ✓Verify the first payment to any new account the same way, however genuine the email looks.
- ✓Turn on two-factor authentication for email so a stolen password cannot open the mailbox.
- ✓Agree with your team that payment-detail changes are never actioned on email alone.
- Business email compromise: how to defend against it NATIONAL CYBER SECURITY CENTRE ↗
- Invoice and mandate fraud ACTION FRAUD ↗
- Take Five: check before you pay TAKE FIVE ↗
- Authorised push payment fraud losses UK FINANCE ↗
Links open each publisher’s live coverage of this topic.