It is one of the most expensive emails a South African business can receive, and it looks completely ordinary: a supplier letting you know their banking details have changed. The invoice is real, the amount is right, the tone is familiar — and the new account belongs to a criminal. Invoice fraud, part of a wider problem known as business email compromise, costs local businesses dearly precisely because it involves no virus, no suspicious attachment and nothing a spam filter is built to catch. This guide explains how the scam works, lets you test yourself on a realistic example, and covers the verification rule, email security settings and staff habits that stop it — plus exactly what to do in the first hour if you have already paid.
The Short Answer
Treat every email that changes where you send money as unverified until you have phoned the supplier on a number you already had — never one in the email — and confirmed the change with someone you know. Protect your own mailbox with multi-factor authentication so criminals cannot use it to defraud your clients, set up SPF, DKIM and DMARC so nobody can send email from your exact domain, and train the people who pay invoices to slow down when an email creates urgency. If you have already paid, call your bank’s fraud line immediately, then report it to the police.
How the Scam Actually Works
There are three common versions, and knowing which one you are facing explains why some of them get past even careful people.
The lookalike domain. The criminal registers a domain one character away from your real supplier’s — mokoena-suppIies.co.za instead of mokoena-supplies.co.za — and emails your accounts team from it. It reads correctly at a glance, especially on a phone.
The hacked supplier. The criminal takes over your real supplier’s mailbox, usually through a stolen password. The email genuinely comes from the supplier’s address, sits in an existing conversation thread and refers to real invoices, because the criminal has been reading their mail for weeks. Nothing about the email itself looks wrong.
The hacked you. The same trick in reverse: your own mailbox is compromised and used to send your clients “updated” banking details for your invoices. Your clients pay the criminal, and you find out when you chase the payment.
In the second and third versions, criminals often add inbox rules that quietly hide or forward replies, so neither side sees the conversation that would expose them.
Spot the Fake: Try It Yourself
This is a typical change of banking details email. See how many warning signs you can find before reading on.
The uncomfortable lesson is that a better-crafted version would have none of these signs. If the email came from the supplier’s genuinely hacked mailbox, the sender address would be real, replies would go to the right place and there would be no dodgy link. That is why spotting fakes is useful but not enough — the protection has to be a process that works even when the email is perfect.
Why Your Spam Filter Will Not Catch It
Email security tools are built to catch malware, known bad links and mass phishing campaigns. An invoice fraud email is usually a short, polite message with a PDF letter and nothing technically malicious in it. When it comes from a real, compromised mailbox, it also passes every authentication check, because it genuinely is from that mailbox. Good email security reduces the volume — it catches most lookalike domains and many impersonation attempts — but the final defence is a person following a rule.
The Rule That Stops Almost All of It: Verify by Phone
Make this a written policy and apply it to everyone, including the owner:
- Any change to banking details is verified by phone before a single rand is paid to the new account.
- Use a number you already have — from a previous invoice, your supplier records or their website. Never use a number in the email asking for the change, because the criminal controls it.
- Speak to someone you know at the supplier, and ask them to confirm the new details to you rather than reading them back.
- Two people approve any new or changed beneficiary in your banking profile. One person captures, another authorises.
- Use your bank’s account verification service where available. Many South African banks offer business clients a check that confirms an account number belongs to the name you expect.
- Treat urgency as a warning sign. “Payment due today” and “reply by email only” are there to rush you past these steps. A genuine supplier will wait for a phone call.
The same applies in the other direction: tell your own clients, on every invoice, that your banking details will never change by email and that they should phone you to confirm any request that says otherwise.
Lock Down Your Own Email
The hacked-mailbox versions of the scam start with a stolen password, so the most effective technical step is making a stolen password useless:
- Turn on multi-factor authentication for every mailbox, especially the owner’s and the accounts team’s. It stops the large majority of mailbox takeovers.
- Check for unexpected inbox rules that forward, delete or move email — a classic sign of a compromised account.
- Block legacy sign-in methods that skip multi-factor authentication.
- Get alerts on suspicious sign-ins from unfamiliar countries or devices.
- Keep devices patched and protected, because a compromised laptop can hand over a mailbox too.
If you use Microsoft 365, Business Premium adds Defender for Office 365, with impersonation protection that flags lookalike senders and link checking that catches fake sign-in pages, plus conditional access to control where and how staff can sign in. Our comparison of Microsoft 365 Business Premium and Business Standard covers what each licence includes.
Stop Criminals Pretending to Be You: SPF, DKIM and DMARC
Three records in your domain’s DNS decide whether someone can send email that appears to come from your exact address:
- SPF lists the mail servers allowed to send email for your domain.
- DKIM adds a digital signature to every email you send, proving it was not altered and came from you.
- DMARC tells other mail servers what to do with email claiming to be from your domain that fails those checks — monitor it, quarantine it or reject it.
With DMARC set to reject, a criminal can no longer send email from your exact domain to your clients. It does not stop lookalike domains, and it cannot help if your real mailbox is compromised, which is why it works alongside multi-factor authentication rather than instead of it. Setting DMARC straight to reject without checking can also block your own legitimate email — from your invoicing system, for example — so it should be rolled out in stages while you watch the reports.
Train the People Who Pay Invoices
General cybersecurity awareness training is useful, but the people who capture and release payments need something more specific: what a banking-change request looks like, the exact verification steps your business follows, and explicit permission to delay a payment — even one the owner has asked for urgently — until it has been verified. Criminals often impersonate the boss precisely because staff are reluctant to question them. Make it clear that nobody will be in trouble for checking. Our guide to ransomware protection covers the wider training and security layers every business needs.
If You Have Already Paid a Fraudster
Speed matters more than anything else. In the first hour:
- Call your bank’s fraud line and ask for the payment to be recalled or the receiving account to be flagged. The sooner this happens, the better the chance of stopping the money before it moves on.
- Open a case with the South African Police Service and keep the case number for your bank and insurer.
- Preserve the evidence. Do not delete the emails — keep them, with their full headers, plus the invoice, the letter and the payment confirmation.
- Secure the mailbox that was involved. Change the password, sign out all sessions, turn on multi-factor authentication and check for inbox rules the criminal may have created.
- Warn the other side. Phone your supplier or client on a known number so they can check their own systems and warn others.
- Tell your insurer if you have cyber or crime cover.
If a mailbox containing client or staff information was compromised, Section 22 of POPIA requires you to notify the Information Regulator and the affected people as soon as reasonably possible. Our POPIA IT compliance checklist covers what reasonable security looks like before an incident like this.
A Payment Security Checklist
- A written rule: every banking change is verified by phone on a known number
- Two-person approval for new or changed beneficiaries
- Your bank’s account verification service used for new suppliers
- A line on every invoice saying your banking details never change by email
- Multi-factor authentication on every mailbox
- Regular checks for unexpected inbox rules and sign-ins
- SPF, DKIM and DMARC set up for your domain, with DMARC moving towards reject
- Email security with impersonation protection switched on
- Payment staff trained on this specific scam, with permission to delay
- A written first-hour plan, with your bank’s fraud number where the accounts team can find it
How IT-Support-SA Can Help
We set up the technical side of this for South African businesses: multi-factor authentication across every mailbox, Microsoft 365 security configured properly rather than left on defaults, a staged SPF, DKIM and DMARC rollout that does not break your own email, and a check of every mailbox for rules and sign-ins that should not be there. We can also help you write the verification procedure and walk your accounts team through it. It is the kind of work that pays for itself the first time it stops a single payment — see our IT support pricing guide for how managed support is typically priced.
Conclusion
Invoice fraud works because it looks like normal business, and no email filter can fully protect you from a message that genuinely comes from a hacked supplier. What stops it is a simple rule applied every single time — verify any banking change by phone on a number you already have — backed by multi-factor authentication on your own mailboxes, SPF, DKIM and DMARC on your domain, and payment staff who know they are allowed to slow down. Put those in place before the email arrives, not after.
Contact IT-Support-SA for an email security check — we will look at your mailboxes, sign-in protection and domain records and tell you plainly what needs fixing. We support businesses across Pietermaritzburg, Durban, Ladysmith, Johannesburg, Cape Town and all 9 provinces of South Africa.