How do builders avoid invoice redirection fraud?
With one unbreakable rule: any change to bank account details is verified by telephone to a number you already held, never a number supplied in the request. Construction is targeted deliberately because the payments are large, scheduled and expected, which is exactly the condition this fraud needs.
The scenario is not technically sophisticated and that is what makes it effective. Someone gains access to a mailbox, either yours or a supplier's, through a phished password. They do nothing conspicuous. They read: who pays whom, when progress claims fall due, how the business writes to its subcontractors, what a normal invoice looks like. Then at exactly the moment an amended payment detail would be unremarkable, it arrives, formatted correctly, from an address that looks right.
Construction is a favoured target for structural reasons rather than bad luck. The sums are large, so a single success is worth the effort. Payments are scheduled and expected, so nothing seems odd about one arriving. The chain is long, with clients, head contractors, subcontractors and suppliers all invoicing each other, which gives an attacker several mailboxes to compromise and several relationships to impersonate. And the industry runs on email, at pace, often from phones on site.
The verification rule is the control that works, and its power lies in being absolute. Any change to bank details, from anyone, for any reason, is confirmed by a phone call to a number you already had on file, before any payment is made. Not a reply to the email. Not the number in the signature or on the amended invoice, both of which the attacker controls. This costs one phone call and prevents the loss almost entirely, and the businesses that have been caught almost always had an informal version of the rule that was waived because someone was in a hurry.
That is the second half of it: urgency is the tell. Fraudulent requests arrive with pressure attached, because pressure is what stops people checking. The payment is needed today, the supplier is chasing, the settlement is this afternoon. Train your team to treat urgency around payment details as the signal to slow down rather than speed up, and make it explicit that nobody will ever be criticised for delaying a payment to make a phone call.
The technical half is protecting the mailbox so the reconnaissance never happens. Multi-factor authentication on every account is the highest-value control available and remains incomplete in a great many construction businesses, particularly for directors and estimators who find it inconvenient and who are exactly the accounts worth compromising. Beyond that, monitoring for the tell-tale signs of a compromised mailbox, unusual sign-in locations and forwarding rules quietly added, catches the ones that get through.
Forwarding rules deserve a specific mention because they are the standard technique. An attacker inside a mailbox will often create a rule that quietly copies or diverts messages containing words like invoice or payment, so they can watch without staying logged in. Checking for unexpected forwarding rules is a quick and revealing exercise, and it is worth doing across the business rather than only when something feels wrong.
Your own outbound side matters too, and it is often overlooked. If your invoices are being intercepted and amended after you send them, your clients pay a fraudster and the argument about who bears the loss is unpleasant regardless of where the compromise occurred. Telling clients plainly, in writing and on your invoices, that your bank details never change and that any notification to the contrary should be verified by phone, is cheap protection for both sides.
If it does happen, speed is the only thing that helps. Contact the bank immediately, because funds can sometimes be stopped in the first hours and rarely afterwards. Report it through ReportCyber. Check whether personal information was also exposed, since that may trigger obligations under the Privacy Act's notifiable breach scheme. And get the mailbox properly secured before communicating, because an attacker still reading your email will watch your response.
The honest caveats. No control makes this impossible, and a sufficiently patient attacker with access to a supplier's mailbox can be convincing. Multi-factor authentication and the verification rule together remove the overwhelming majority of realistic attempts, which is the achievable goal. And this is a habit rather than a product, so it needs restating periodically rather than being installed once. If you want the technical half handled and the habit set up, call 1800 456 567.
Protect the payments
We put multi-factor authentication and monitoring around your email, and help you set a verification habit that survives a busy week.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business