← All researched cases
Current multi-source warningThis is not a user complaint. It synthesises the linked public record and was last reviewed 25 August 2026.
Active high-loss patternGSR-R-014

Business email compromise and invoice diversion

Compromised mailboxes and convincing lookalike messages continue to redirect supplier, property and payroll payments into criminal accounts.

Business fraud · Account compromiseInternational
Editorial artwork of an invoice payment route being diverted from a secure account
Original editorial illustration — not evidence or a photograph of the case.

Summary

What the record shows

An offender studies a payment relationship, then sends altered banking instructions from a compromised mailbox or a near-match domain. The request may appear in an existing email thread and use genuine invoice details.

FBI reporting continues to treat business email compromise as a major loss category. Controls are most effective when payment changes are verified through a known second channel before funds move.

Key findings

What is established and what is not

  • A familiar display name and accurate invoice do not authenticate changed bank details.
  • Use dual approval and call a previously known contact number—not one included in the change request.
  • If funds were sent, contact both banks and law enforcement immediately; recall opportunities shrink quickly.

Response and denials

The other side of the record

The reviewed material describes a distributed pattern using changing accounts, numbers and sites. No single identifiable operator or attributable operator denial was located.

Some approaches misuse the identity of suppliers, executives, employees, conveyancers or banks. Those impersonated organisations are not treated as participants; verify any contact through an independently located official channel.

Global Scam Report evaluation

Summary assessment

Active, high-loss payment-diversion pattern — very high confidence. Responsibility in a particular case can involve account security and process failures across several parties and should not be assumed without evidence.

Scope qualificationThis profile does not determine contractual liability for a misdirected payment. Preserve full message headers, access logs and verification records for specialist review.

Reference record

Sources reviewed

  1. GovernmentFederal Bureau of Investigation · Current guidanceBusiness email compromiseOpen source ↗
  2. GovernmentFederal Bureau of Investigation · Current field guidanceBuilding a digital defence against business email compromiseOpen source ↗
  3. GovernmentFederal Bureau of Investigation · Case overviewBusiness email compromiseOpen source ↗
  4. GovernmentFederal Bureau of Investigation · Current private-sector guidanceEmail compromise prevention guideOpen source ↗
  5. GovernmentFederal Bureau of Investigation · 20262025 Internet Crime ReportOpen source ↗
  6. GovernmentUS Federal Trade Commission · February 2025Consumer Sentinel Network Data Book 2024Open source ↗
  7. GovernmentUS Federal Trade Commission · May 2025How to avoid a scam — fraud handbookOpen source ↗