How it actually happens
Somebody gets into a mailbox. Sometimes yours, more often your supplier’s, usually through a reused password rather than anything clever. Then they do nothing at all, which is the part people find hardest to believe.
For weeks they read. They learn who approves payments, what your invoices look like, how your supplier writes, when the monthly run goes out, and which of your people are travelling. They set a quiet forwarding rule so they keep seeing the thread even if the password changes.
Then a real invoice arrives, for a real amount, for work that was really done. Shortly after it, a short message: we have changed banks, please use the new account for this one. It comes from the supplier’s own address, or from a domain one character different from it. It is written in the supplier’s voice, because the attacker has been reading that voice for a month.
Somebody in finance updates the account and pays. Nothing looked wrong, because nothing was wrong except one line of the payment details.
Why your security software does not catch it
There is no attachment to scan, no link to block and no malicious code anywhere in the message. When the mailbox is genuinely compromised, the email really is from your supplier. Every technical control you own is being asked to judge a business decision, and it cannot.
The FBI’s Internet Crime Complaint Centre recorded just under USD 3.05 billion in verified losses to business email compromise in 2025, from 24,768 complaints. That is an average of roughly USD 123,000 per reported incident, and it is only the reported ones, from one country, where reporting is comparatively normal. In this region most of these never get reported at all.
Why mid-sized companies in Jordan are the easy target
Not because of anything technical. Because of how the finance function is arranged.
- Supplier communication runs on email and WhatsApp, and neither authenticates anybody.
- A supplier changing bank details is a normal event, so the request does not feel strange.
- The same person often enters the supplier record and releases the payment.
- The approval is verbal, or a forwarded message, or a nod in a corridor.
- Everything moves fastest at month end, which is exactly when the request arrives.
Four controls that stop it
1. Call back on a number you already had
Any change to a supplier’s bank details is confirmed by phone, on the number already in your supplier master, to a person you already know. Never the number in the email, and never a number in the signature block, because the attacker wrote both.
This one control stops most of these attacks on its own. It only works if it is written into the payment procedure as a step, because left to judgement it gets skipped on the day it matters — the day everyone is busy, which is the day it is sent.
2. Two people on any bank detail change
One person makes the change, a second confirms it, and the supplier master records the date, the new details and both names. It takes two minutes and it creates the record you will want if it ever goes wrong.
3. Separate who creates the supplier from who pays
If one person can add a supplier and release a payment to it, no software will save you. In a small team this feels bureaucratic. It is the single most effective control in the list, and it costs nothing but a habit.
4. The technical half: multi-factor authentication and forwarding rules
Multi-factor authentication on every mailbox, without exceptions for senior people, since those are the mailboxes worth taking. Then alerting on mailbox forwarding rules, because a rule quietly copying mail to an outside address is the clearest sign you have a reader, and almost nobody is watching for it.
If it has already happened, the first hour matters
- Call your bank’s fraud desk immediately and ask for a recall. Speed here is the only thing that decides whether the money comes back.
- Do not delete anything. Preserve the mailbox exactly as it is, including the message headers.
- Check every mailbox in the company for forwarding and redirect rules, not only the one you think was involved.
- Reset passwords and enable multi-factor authentication, in that order, on every account that shares a password.
- Call the supplier on a known number. If the compromise is on their side, other customers are being targeted right now.
- Report it, and write down the sequence of events while people still remember it.
The point
This is not an IT problem and it is not a finance problem. It sits between them, which is precisely why it works so often. IT assumes the payment controls belong to finance. Finance assumes email security belongs to IT. The attacker only needs that assumption to hold for one afternoon.
Closing that space is the whole reason we built the firm the way we did — and it is why the payment controls and the mailbox settings get looked at by the same team. More on that under Technology & Security.
Source for the figure quoted: FBI Internet Crime Complaint Centre, 2025 Annual Report. No client of ours is described in this article.