Home Articles Get your free assessmentComing soon

Tag: invoices

  • Business Email Compromise: How One Fake Invoice Drains an Account

    Business Email Compromise: How One Fake Invoice Drains an Account

    Your church is six months into a roof replacement. The contractor has invoiced twice already, both paid without incident. On a Thursday morning, the third invoice arrives from the same email address you’ve been corresponding with all spring.

    The invoice looks right. Same logo, same layout, same project reference, correct amount. There’s one difference, and it’s mentioned in a single line of the email body:

    Please note we’ve changed banks — updated remittance details are on the invoice. Sorry for the inconvenience.

    Your bookkeeper updates the payee, sends $47,000, and files the confirmation.

    Eleven days later the contractor calls to ask when they’re getting paid.

    This is business email compromise. It is the most expensive attack aimed at organizations your size, and it almost never looks like an attack while it’s happening.

    What BEC actually means

    Business email compromise — you’ll see it shortened to BEC everywhere — is the category of fraud where someone uses email to impersonate a person you trust in order to redirect a payment.

    The name is slightly misleading, and the confusion matters, because the two versions call for different responses.

    Version one: nothing was compromised. The attacker registered a domain that looks like your contractor’s and sent mail from it. Your vendor is `midlandroofing.com`; the attacker owns `midiandroofing.com` — an l swapped for an i, invisible in most fonts at normal size. Or `midland-roofing.com` with a hyphen. Or `midlandroofing.co` dropping the m. Everything else in the email is copied from real correspondence. Nobody’s account was ever accessed.

    Version two: an account really was taken over. The attacker got into a mailbox — usually through a phished password — and is sending from the genuine address. This version is far more dangerous, because there is nothing to spot in the sender line. It’s genuinely the right address. Worse, the attacker can read the entire history first: they know your project, your invoice format, your payment cycle, who approves what, and how your bookkeeper writes. They often set up a quiet mail rule that moves the real vendor’s messages into an unread folder, so the two of you stop seeing each other’s emails while the attacker relays between you.

    The second version is why “just look at the sender address” is necessary advice but not sufficient advice.

    The scale of it

    The FBI’s Internet Crime Complaint Center recorded 24,768 BEC complaints in 2025, totalling $3,046,598,558 in losses. That works out to an average reported loss of about $123,005 per complaint.

    Sit with that figure against a church budget. For most congregations, one successful BEC is larger than a quarter of total giving. For a small nonprofit, it can be existential.

    And BEC is a rounding error away from being invisible. There’s no ransom note, no locked screen, no alarm. The first sign is almost always a vendor politely asking about an overdue payment.

    The five shapes it takes in a ministry

    The vendor bank change. The scenario above. Most common and most costly, and it spikes during building projects, capital campaigns, and any period when large payments to unfamiliar contractors are normal.

    The leadership wire request. An email that appears to come from your pastor or executive director, asking the bookkeeper to send a payment urgently, usually with a reason it can’t be discussed by phone.

    The payroll redirect. A staff member appears to email HR asking to update their direct deposit details. We’re covering this one in full tomorrow, because it works differently enough to deserve its own post.

    The invoice that was never real. A plausible bill for something a church actually buys — copier maintenance, website hosting, denominational dues, a directory listing — from a company you can’t quite remember but probably use. Small enough to approve without scrutiny. Often repeated monthly until someone notices.

    The data request. No money at all. Someone asks for the staff list, W-2 information, or the donor database. That data becomes the ammunition for the next attack, aimed at a different organization.

    Why churches are good targets for this specifically

    Three things, none of them a failing.

    Approval is informal. In a five-person office, the person who receives the invoice is often the person who pays it. There’s no purchasing department, and adding one would be absurd. But it means a single deceived person completes the whole transaction.

    Large, irregular payments are normal. A church might make three $40,000 payments a year and hundreds of $200 payments. The big ones don’t recur often enough for anyone to develop an instinct about them, and they cluster in exactly the periods — building projects, campaigns — when everyone is busy and moving fast.

    Your relationships are public. Your bulletin thanks the contractor. Your newsletter names the architect. Your board minutes list the vendors. An attacker doesn’t have to guess who you’re paying.

    The one control that stops it

    There is a single procedure that defeats every version of this attack, and it costs nothing:

    Any change to payment details is verified by voice, using a phone number you already had, before the payment goes out.

    Every word in that sentence is load-bearing.

    Any change — not just large ones. The threshold approach fails, because attackers learn thresholds.

    By voice — not by email. If the attacker controls the email thread, every confirmation you receive is written by them. This is the part people get wrong most often: replying to the message and getting a reassuring answer feels like verification, and it is the opposite of verification.

    A number you already had — from a signed contract, a previous invoice, or your own contacts. Never the number in the email or on the new invoice. Attackers put their own number on the document precisely so you’ll “verify.”

    Before the payment goes out — because after is a recovery problem, not a prevention one.

    Two additions make it stronger. Require two people for any payment over a threshold your board sets — one to initiate, a different one to release. And read the bank details aloud during the verification call, digit by digit, rather than asking “did you change banks?” A yes-or-no question invites a yes.

    Write the rule down. Give it to everyone who touches a payment. And state plainly that no one will ever be criticized for making the call, including when the request appears to come from the senior pastor. In a small church, the person most likely to be defrauded is the one who feels least entitled to question leadership.

    Hardening the email side

    The procedure is the main defense. Three technical measures reduce how often you’re tested.

    Multi-factor authentication on every mailbox. This is the extra step after your password — a code from an app, or a tap on your phone. It’s what prevents version two of this attack, where an account is genuinely taken over. Microsoft’s research finds MFA blocks more than 99.2% of account compromise attacks. It’s free on Microsoft 365 and Google Workspace.

    External sender warnings. Ask whoever manages your email to enable the banner reading “This message came from outside your organization.” When a message claiming to be from your executive director carries that banner, the contradiction is visible immediately.

    Check for mail rules you didn’t create. After any suspected compromise — and once a quarter regardless — look in each mailbox’s settings for forwarding rules and filters. Attackers routinely add a rule that forwards everything to an outside address, or that files messages containing “invoice” or “payment” into an obscure folder. It’s the most common thing left behind, and it’s the thing people forget to check after changing a password.

    If it already happened

    Speed is nearly everything. The recall window on a fraudulent transfer is measured in hours.

    Call your bank’s fraud line first. Before you investigate, before you email anyone, before you’re certain. Ask them to attempt a recall. If you have the number ready in advance rather than searching for it, that alone can be the difference.

    Report to the FBI at ic3.gov immediately, and say the words business email compromise and fraudulent wire transfer. This is not a formality. The FBI’s Recovery Asset Team can initiate what’s called the Financial Fraud Kill Chain — a process to freeze funds before they’re moved onward. In 2025 it ran 3,574 domestic cases and froze $507,042,623. It works far better within the first 24–72 hours.

    Don’t reply to the fraudulent thread, and don’t delete anything. The mailbox is evidence.

    Change passwords from a different device and revoke active sessions — in Microsoft 365 and Google Workspace there’s a “sign out everywhere” option. Changing a password alone doesn’t kick out someone who’s already signed in.

    Then check the mail rules, as above.

    And tell your insurer. Many cyber liability policies cover funds transfer fraud, and most impose short notification deadlines.

    What to do this week

    Write down the verification rule and circulate it to everyone who can initiate or approve a payment. One paragraph. Then find your bank’s fraud number and put it somewhere that doesn’t require logging into a computer — taped inside a cabinet door is fine.

    That’s an afternoon’s work against the single most expensive attack aimed at organizations your size.

    When you’re ready to see where else you stand, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of priorities.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.