Skip to content
NewHost
Menu

Invoice Fraud and Email Compromise - How SA Businesses Stay Safe

How invoice fraud and business email compromise work, the warning signs, the controls that stop them and what to do in the first hour if it happens.

By NewHost team · · 6 min read

Invoice fraud, also called business email compromise, is when a criminal sends your customer (or your accounts team) a genuine-looking email asking for payment into a different bank account. The email may come from your real mailbox after a password was stolen, from a lookalike domain one letter off from yours, or from a forged address on a domain without email authentication. The defence is a combination of a simple business rule, never change bank details on the strength of an email, and a few technical controls that make your domain hard to impersonate.

This guide explains how the scam works, how to spot it and what to do in the first hour if it happens to you.

How the scam works

There are three common variations, and they often combine.

1. A real mailbox is taken over

Someone at your business enters their email password on a fake sign-in page, or reuses a password that leaked from another site. The attacker signs in quietly, reads mail for days or weeks to learn who pays whom, and waits for an invoice to go out. Then they reply in the same thread, from the real address, with "please note our banking details have changed". Attackers often add a forwarding or filter rule first, so replies from the customer go to them or are hidden from the real owner.

2. A lookalike domain

The attacker registers a domain that looks like yours at a glance: examp1e.co.za instead of example.co.za, example-co.za.com, or your name on a different extension. They copy your signature and logo and write to your customers. Nothing on your systems was touched, but your customers still lose money.

3. A forged From address

Email was designed without sender verification. If your domain has no SPF, DKIM and DMARC policy, some receiving servers will still accept a message that claims to be from [email protected] but was sent from somewhere else entirely.

Warning signs

Train everyone who sends or pays invoices to stop and check when they see:

  • a request to change bank details, or to pay "just this once" into a different account;
  • urgency or secrecy ("the auditors are here, please pay today", "don't call, I'm in meetings");
  • a reply-to address that differs from the sender's, or a domain that is almost but not exactly right;
  • a PDF invoice with different formatting, fonts or bank details from the previous one;
  • a message in an old thread that suddenly changes tone or asks about payments.

Process controls: the ones that actually stop losses

Technology reduces the risk; process removes it. These cost nothing:

  1. Verify every bank detail change by phone, using a number you already had. Never use a number from the email asking for the change. Call the person you normally deal with.
  2. Put a notice on your invoices saying that your bank details will never change by email, and that customers must phone you to confirm before paying a new account.
  3. Use two people for new beneficiaries. One person loads a new bank account at the bank; a second approves it after the phone check.
  4. Pay a small test amount first for new suppliers, and confirm by phone that it arrived.
  5. Keep a written record of who confirmed each change, when and on which number.

Technical controls

Protect the mailboxes

  • Use a unique, long password for every mailbox, kept in a password manager. Reused passwords are one of the easiest ways in.
  • Turn on two-factor authentication wherever it is offered: your email if your provider supports it, your bank, your accounting software and your hosting dashboard. The NewHost dashboard supports two-factor sign-in with an authenticator app; see two-factor authentication with an authenticator app.
  • Check forwarding and filter rules on mailboxes that handle money every month. In the NewHost dashboard, a mailbox's settings show whether copies are forwarded elsewhere. Anything you don't recognise should be removed and investigated.
  • Reset passwords immediately when someone leaves, and when a device is lost.

Make your domain hard to forge

Publish SPF, DKIM and DMARC records for your domain. With a DMARC policy of quarantine or reject, receiving servers can bin mail that claims to be from your exact domain but wasn't sent by your servers. Start with monitoring and tighten the policy once your legitimate mail passes. Our guide to SPF, DKIM and DMARC explained has example records, and why emails go to spam helps if legitimate mail starts failing.

DMARC can't stop lookalike domains, because those are different domains with their own records. For those, you rely on the process controls above and on alert staff.

Consider registering obvious lookalikes

If your business is example.co.za, owning example.com and an obvious misspelling makes it slightly harder for someone else to use them against you. You can redirect them to your main site. See one website, several domains for how to set that up, and choosing a domain name for picking names that are hard to imitate in the first place.

If it happens: the first hour

Speed matters, because banks can sometimes stop or recall a payment if they are told quickly.

  1. Call your bank's fraud line immediately if your business paid money. If a customer paid a fraudster, ask them to call their bank straight away.
  2. Change the password of every affected mailbox, from a clean device, and sign out other sessions where your email client allows it.
  3. Remove unknown forwarding rules, filters and auto-replies.
  4. Warn your customers and suppliers by phone or from a known-good channel that fraudulent invoices may be circulating.
  5. Keep the evidence. Don't delete the fraudulent emails. Save them with full headers.
  6. Open a case with the South African Police Service and keep the case number for the bank and your insurer.
  7. Consider POPIA. If personal information was accessed, for example customers' details in the compromised mailbox, section 22 of the Protection of Personal Information Act requires you to notify the Information Regulator and the people affected. The Information Regulator's website explains the process. For your specific situation, take professional advice.

Afterwards, work out how the attacker got in, fix that, and run a short refresher with your team. Our website security checklist for small businesses is a good place to continue.

Frequently asked questions

Can my bank get the money back?

Sometimes, if the bank is told quickly and the money hasn't moved on. That is why calling the bank's fraud line comes first. There is no guarantee, which is why prevention matters more.

Does using a free email address make it worse?

Free addresses are easy to imitate, because anyone can create a similar one in seconds, and you can't publish DMARC for a domain you don't own. Business email on your own domain, with SPF, DKIM and DMARC, is easier for customers to trust and harder to forge. See business email in South Africa.

Is antivirus enough to stop this?

No. Most invoice fraud involves no malware at all, just a stolen password or a convincing email. Process controls and email authentication do more than antivirus here.

Who is responsible if a customer pays the wrong account?

That depends on the facts and the agreements involved, and it is a legal question. Take advice from your attorney or your bank. A clear notice on every invoice about bank details helps everyone.

Want business email that you control end to end? NewHost email hosting gives you mailboxes on your own domain, with SPF, DKIM and DMARC records editable in the same dashboard as your website and domains.

Related guides

Ready to launch on NewHost?

Choose a plan and go live today, or tell us what you need and we'll recommend the right setup.