High severityBusiness / Financial Fraud
Business Email Compromise (Invoice Fraud)
Updated May 28, 2026
Attackers spoof or compromise a vendor's email to redirect an outstanding invoice payment to a new bank account.
Warning signs
- An email requesting an urgent change to bank routing/account details for an existing vendor.
- Slightly altered sender domain (e.g. an extra letter or different top-level domain).
- Unusual urgency or requests to bypass normal approval steps.
What to do
- Verify any payment detail change by phone, using a number you already have on file — not one in the email.
- Require dual approval for changes to vendor banking information.
- Report suspected fraud to your bank immediately; wire transfers can sometimes be recalled within a short window.
Small businesses are frequent targets because they often lack formal verification processes for payment changes.
See our Small Business Starter Kit for a simple internal-approval checklist that blocks most of these attempts.
This write-up is an educational summary of a known scam pattern, not a real-time threat alert, and does not name any specific Augusta-area victim, business, or law enforcement case.