A professional services firm received an email with an invoice attached and a demand for payment. It arrived in the firm’s general mailbox. Then a follow-up arrived, showing the name of someone who works at the firm, pressing for the invoice to be dealt with.
A staff member forwarded both to us, told us they’d already marked them as phishing, and asked if anything else was needed.
We logged a quarter of an hour on it.
How this kind of fraud works
The first email sets things up: an invoice, a payment demand, a sense that something is overdue. The follow-up adds pressure, and it borrows authority by using the name of someone the staff member trusts.
The name is the clever part. An email client usually shows the sender’s display name first, and a display name can be set to anything. The address behind it is where the truth is.
Scamwatch’s page on business email compromise describes the pattern: scammers “send you an invoice with new payee information” so payments go to them instead.
What gave it away
The staff member didn’t need us to spot it. But several warning signs were there for anyone to see:
- an invoice demanding payment that nobody was expecting
- a follow-up using a colleague’s name, sent from an address that wasn’t theirs
- a warning banner from the firm’s email protection noting the sender’s display name closely resembled a user in the organisation
- an earlier message in the chain dated months before it arrived
That last one is easy to miss. A fraudulent chain is often pasted together, and the dates don’t line up.
What we checked
We confirmed the staff member had done exactly the right thing. The email protection had flagged the message with a banner and given them options, and they’d used them.
In the email protection console, we found the original email, from an unrelated outside address, sitting in quarantine and classified as scam or phishing.
The odd date made us want to know whether the email had arrived as one message or two, since that affects whether anything slipped through earlier. We asked, and tried calling to follow up. With no further concerns from the firm, we closed the ticket about a week later.
The habit that stops it
Filters and banners catch a lot. They don’t catch everything, and fraudsters change their approach when one stops working.
The protection that doesn’t depend on technology is a call-back rule. Scamwatch’s advice is to “contact the business you normally deal with by phone using a number you have sourced independently”, and not to use the contact details in the email, which may have been changed.
That applies inside your own business too. If an email from a colleague asks for a payment, ring the colleague.
Where they landed
Staff reported the email and marked it as phishing before acting on it, and the original was confirmed in quarantine.
Write down a simple rule this week: no invoice gets paid and no bank details change based on email alone. Confirm by phone, on a number you already had.
If you’d like help putting that rule in place, get in touch.
