The bank-details switch: how a transfer gets stolen from a business

No virus required. Just an email that looks like your usual supplier announcing a change of account number. How it works, why it works and the two-minute control that stops it.
· Security
The fraud that takes the most money from small businesses does not come in through a virus or an exotic vulnerability. It comes in through email, it is written in correct language and it has impeccable commercial logic. Depending on the variant it is called CEO fraud or invoice redirection fraud, and the average amount is not small.
How it works, step by step
1. Observation. The attacker gets into a mailbox — usually that of somebody in administration, through a reused or leaked password — and does nothing. They just read. They learn who your suppliers are, how often they invoice, what amounts are normal and how each one writes.
2. Waiting. They may spend weeks in there. They wait for a large invoice, a notable payment, or for the manager to go away.
3. The strike. An email arrives from your usual supplier. Same format, same signature, same tone. It says they have changed bank and attaches the invoice with the new account number. Everything else is correct: the amount, the invoice number, the order reference.
4. Collection. It gets paid. The money moves within minutes across several accounts and leaves the country. When the real supplier chases their invoice, weeks later, there is nothing left to recover.
Why it works
Because it does not exploit a technical flaw: it exploits the fact that paying a known supplier's invoice is a routine task. Nobody is suspicious of what they do every month. And the classic fraud signals — spelling mistakes, odd senders, absurd urgency — do not appear here, because the attacker has been reading your email for a month and knows how to imitate you.
The CEO variant is the same idea in a different disguise: an email from the director, on a Friday afternoon, asking for an urgent and confidential transfer for a deal in progress. It appeals to hierarchy and to haste.
The control that stops it
Just one, and it takes two minutes:
Every change of account number is verified by phone, calling the number you already had beforehand, never the one in the email.
That is all. That rule, applied without exceptions, stops virtually all of these frauds, because the attacker controls the email but not the phone line you have had on file for three years.
The rule has to belong to the company, not the person. If it depends on whoever pays having a good day, it fails on the day they are in a hurry.
The other four controls
- Dual authorisation for payments above an amount you define. Making a large transfer need two people is inconvenient for exactly long enough to think.
- Second factor on email, no exceptions. The fraud nearly always starts with a compromised mailbox; with a second factor, the leaked password is not enough.
- Check the mailbox rules. The attacker usually creates a rule moving the real supplier's emails to a hidden folder, so you never see the chase. It is a trace you can check in a minute and almost nobody looks at.
- No urgency skips the procedure. Say it out loud to the team: nobody in management will ever ask for an urgent, confidential transfer by email. If one arrives, it is fake.
If it has already happened
The first hours are decisive and the order matters:
- Call your bank immediately and ask for a recall. If the money has not left the destination account, it is sometimes recovered.
- Report it. Without a police report there is no investigation and no insurance cover.
- Change the passwords of the affected mailbox and review the rules and recent logins.
- Warn the real supplier: the compromised mailbox is probably theirs, and you are not their only customer.
- Check whether personal data is affected. If the attacker had access to the email, they had access to your customers' data, and that can trigger the duty to notify a security breach, with short deadlines in both Spain and Chile.
That last point is always forgotten and it is the one that turns a money problem into a compliance problem.
If this sounds like you
The controls on this list go in over an afternoon and depend on buying nothing. Setting them up and leaving the procedure written down is security and compliance; the basics any business should have are in the minimum you need to have, and the personal data side is in using AI with customer data within the law.
And there is an indirect defence that works surprisingly well: having the cash position in view. When somebody knows which payments are due this week and for how much, a payment that does not fit gets spotted the same day. That is the treasury dashboard.
We are Mindset & Code: automation, data and development for small businesses. You can see what we do and what it costs.
Sources: INCIBE, alerts and guidance on CEO fraud and invoice impersonation; CSIRT of the Government of Chile, email fraud alerts. General guidance; if a fraud has been completed, report it to the relevant police force.