A useful cyber-enabled fraud guide has to start with an uncomfortable correction. Most training still teaches staff to distrust an urgent email from the CEO, but the fraud we investigate now rarely impersonates an executive at all. It arrives inside a genuine vendor’s email thread, from that vendor’s real mailbox, referencing a real invoice your team is already expecting. The FBI’s Internet Crime Report puts verified business email compromise losses above three billion dollars, and most of that money moves by wire or ACH before anyone suspects a problem. The controls that stop it are procedural rather than technical, and a small finance team can put them in place within weeks.
Why Cyber-Enabled Fraud Slips Past SMB Controls
Fraud succeeds at smaller companies because the approval chain is short and personal. When two people handle payments and know each other well, verification feels redundant, so it gets skipped exactly when it matters. Attackers study that dynamic before they act.
What our team sees behind most losses:
- The request comes from a real, trusted account. A compromised vendor mailbox produces a message with correct history, signature, and tone, so nothing looks forged.
- Approval rules check the amount, not the destination. A payment matching an expected invoice total sails through even though the bank details changed.
- Verification happens on the attacker’s channel. Staff reply to the same thread or call the phone number in the signature, both of which the intruder controls.
- Nobody owns bank-detail changes. Updating vendor payment information is treated as an admin edit rather than a security event with its own approval.
- The clock is unknown. Teams do not know that recovery depends on calling the bank within hours, so the first day goes to internal discussion.
None of that is a technology failure. It is a process gap, which is why buying another filter rarely changes the outcome. We cover the mechanics of the initial mailbox takeover in our explainer on business email compromise and how to prevent it.
The Five Ways Money Leaves Before Anyone Notices
Each path below is one we have worked through with finance teams. They share a shape: a legitimate-looking instruction, a payment channel with no independent check, and a delay before discovery.
One: A Real Vendor Thread Asks for New Bank Details
Vendor email compromise is now the dominant form of cyber-enabled fraud, and it works because the message is authentic. The attacker sits inside your supplier’s mailbox, reads the billing history, waits for a genuine invoice cycle, then replies on that thread saying the account has moved.
The reasonable objection is that verifying every banking change slows the payables run and irritates suppliers you have worked with for years. That friction is real, and finance leads who add a heavy check often watch staff route around it under month-end pressure.
What holds up is a narrow rule rather than a broad one. Bank-detail changes get verified out of band, by calling a number already on file from a prior contract, never one supplied in the request. One phone call, on one type of change, applied without exception. Everything else in the payables process stays as it is, which is what makes the rule survive contact with a busy week.
Two: Payroll Direct Deposit Quietly Redirected
Payroll redirection targets the employee self-service portal rather than finance. An intruder with one staff credential changes the deposit account shortly before a pay run, collects a single cycle, and the theft surfaces only when the employee reports a missing paycheck.
Some operations leads argue this is minor next to a large wire. Per incident that is fair. The counterweight is that it signals an active foothold in your identity system, and the same access usually reaches email and shared files.
We treat any deposit-account change as an event that notifies the employee through a separate channel, so the real person learns of it even when their mailbox is compromised. Changes inside a short window before payroll get held for confirmation. The pattern of how quickly a foothold spreads is covered in our account of stopping an email account compromise in minutes.
Three: A Wire Approved Because the Amount Looked Normal
Approval thresholds create a blind spot when they read only the value. Attackers learn your typical invoice range from the mailbox they occupy, then request an amount that sits comfortably inside it. The payment clears because it matches expectations, and matching expectations is precisely the point.
Against tightening this, a lower threshold means more approvals, and approval fatigue produces rubber-stamping. A team that must sign off on everything stops reading anything, which is arguably worse than a higher limit applied with attention.
Our position is that the trigger should be change rather than size. A new payee, a changed account number, or a first payment to a destination all warrant a second pair of eyes regardless of amount, while a repeat payment to an established account on file does not. That keeps the volume of real checks low enough that people actually perform them. A cyber security audit is usually where these threshold gaps first become visible.
Four: Inbox Rules Hide the Replies
Once inside a mailbox, attackers create rules that move or delete messages containing words like invoice, payment, wire, or bank. The account owner keeps working normally while the relevant correspondence is quietly filed away, which is why victims often insist they never received a warning.
The objection here is practical: nobody has time to audit mail rules across a company. True, if done by hand.
So it should not be done by hand. Rule creation and forwarding changes are the sort of signal a monitored detection service treats as an alert rather than a log entry, and unfamiliar forwarding to an outside address deserves immediate attention. Generative tooling has also made the fraudulent messages themselves harder to spot, which we cover in our piece on AI-powered extortion and ransomware.
Five: The Recovery Window Closes Before the Bank Is Called
Recovery of a fraudulent wire depends almost entirely on speed. Funds can sometimes be recalled or frozen when the sending bank and law enforcement are notified within hours, and the odds fall sharply after that. Most SMBs lose the window to internal deliberation about who should make the call.
Some leaders reasonably say a written playbook for this is overkill for a company of thirty people. The rebuttal is that the playbook is four lines long and the loss it prevents is the largest single-day loss most SMBs will face.
Write down who calls the bank, the direct number for the fraud desk rather than the general line, who notifies the insurer, and who contacts law enforcement. Give that page to two people so it does not depend on one person being reachable. Our cyber incident containment team works these first hours regularly, and the difference between a call at hour two and hour twenty is usually the whole recovery.
How to Close the Cyber-Enabled Fraud Path in Weeks
Sequence the work by how much exposure each step removes. Start with the out-of-band verification rule for bank-detail changes, because it blocks the dominant attack path and costs nothing but a written procedure and a short conversation with the payables team.
Next, change approval triggers from amount to change, so new payees and altered account numbers require a second reviewer. Then enable multi-factor authentication on email and the payroll portal if that is not already done, and turn on alerting for new mail-forwarding rules.
Finally, write the four-line recovery card and put it where two people can find it. Rehearse it once by calling the bank’s fraud desk to confirm the number reaches a human, which is worth learning before an incident rather than during one.
That order is deliberate. The first item stops the most common loss, the second catches the variants, and the last one determines how much money comes back when something still gets through. Teams thinking about continuity more broadly can start from our business continuity planning work, and the finance-leadership view is laid out in our 2026 business fraud strategy for CIOs and CFOs.
Frequently Asked Questions
Does cyber insurance cover losses from cyber-enabled fraud?
Coverage varies and often sits under a separate social-engineering or funds-transfer-fraud endorsement rather than the main cyber policy. Many claims are reduced or denied when the insurer finds that a documented verification step was skipped, so the procedure matters for recovery as well as prevention. Read the endorsement and confirm what your policy requires before an incident.
How is vendor email compromise different from a phishing email?
Phishing sends you a fake message from a fake or lookalike address, while vendor email compromise sends a real message from a real address the attacker now controls. There is nothing forged to detect, which is why filters and lookalike-domain checks miss it. Verification of the payment instruction, not inspection of the email, is what catches it.
Can we recover money already wired to a fraudulent account?
Sometimes, and speed decides it. Notifying the sending bank’s fraud desk and law enforcement within hours gives the best chance of a recall or freeze before funds are moved onward. After a day or two the money has usually been layered through further accounts, and recovery becomes unlikely.
Who should approve a change to a vendor’s bank details?
Someone other than the person who received the request, using a phone number already held on file rather than one in the message. Separating those two roles is the single change that breaks this fraud, and it works even when the requesting email is genuine. Record who verified it and when, because that record supports an insurance claim later.
Does multi-factor authentication stop cyber-enabled fraud on its own?
It removes the most common route into the mailbox, so it prevents many incidents from starting, but it does not stop a fraud that begins in a supplier’s compromised system rather than yours. That is why payment verification sits alongside it. The two controls cover different halves of the problem.
Talk Through Your Payment Controls With Our Team
You already know how money moves through your business and where the pressure points sit at month end. What we bring is the pattern from working these losses, so you can see which of the five paths is genuinely open at your company and which your process already covers.
Most finance teams we sit down with are further along than they expected on approvals and further behind on bank-detail changes, which is a cheap fix once it is named. Book a free strategy call and we will walk the five paths against your actual payables process, name the one worth closing first, and leave you with the order of work whether or not you engage us.

