Hungry Nova LabsAugusta CybersecurityHungry Nova Labs
All threats
High severityBusiness / Financial Fraud

Business Email Compromise (Invoice Fraud)

Updated May 28, 2026

Attackers spoof or compromise a vendor's email to redirect an outstanding invoice payment to a new bank account.

Warning signs

  • An email requesting an urgent change to bank routing/account details for an existing vendor.
  • Slightly altered sender domain (e.g. an extra letter or different top-level domain).
  • Unusual urgency or requests to bypass normal approval steps.

What to do

  • Verify any payment detail change by phone, using a number you already have on file — not one in the email.
  • Require dual approval for changes to vendor banking information.
  • Report suspected fraud to your bank immediately; wire transfers can sometimes be recalled within a short window.

Small businesses are frequent targets because they often lack formal verification processes for payment changes.

See our Small Business Starter Kit for a simple internal-approval checklist that blocks most of these attempts.

This write-up is an educational summary of a known scam pattern, not a real-time threat alert, and does not name any specific Augusta-area victim, business, or law enforcement case.