Friday afternoon fraud: how invoice scams actually unfold, and the first hour after money leaves
The invoice fraud that empties an SME’s bank account doesn’t look like a scam. It looks like a supplier you know, on a thread you recognise, with a plausible reason their bank details have changed, and it lands at 4:45pm on a Friday because the criminal chose that moment deliberately. We take the calls that follow, so here’s how it actually unfolds, and what to do in the first hour if money has already gone.
How the scam really works
Forget the misspelt emails from strangers. Business email compromise is patient, and it usually starts weeks before any money moves.
Step one: get into a mailbox. A phishing email harvests someone’s password, somewhere in your payment chain: your firm, a supplier, a client. Without multi-factor authentication, that password is the whole game.
Step two: watch quietly. The criminal doesn’t announce themselves. They read. They learn who raises invoices, who approves payments, what the amounts look like, which deals are close to completing. They set inbox rules to hide replies so the real mailbox owner notices nothing.
Step three: strike at the pressure point. When a genuine payment is due, the email arrives: “Please note our bank details have changed for this invoice.” It quotes the real invoice number and the real people, either from the hijacked thread itself or from a lookalike domain one character off. It’s urgent, it’s Friday afternoon, the person who could verify has gone home, and everyone wants the payment done before the weekend.
Step four: move the money on. Funds land in the mule account and are gone within hours. This is why the first hour after discovery matters more than anything else you do.
Why law firms, and anyone in a payment chain
The legal sector gave this fraud its name because completion funds are large, deadlines are immovable and Fridays are completion day. The scale is documented: 83% of cybercrime reported to the SRA involves email, and in one SRA review, 23 of 30 firms targeted by this fraud lost money, over £4m of it client funds. Our legal sector page covers the regulatory weight law firms carry here.
But the same mechanics apply to anyone who sits in a chain of payments: accountants, brokers, construction firms paying subcontractors, any business with an accounts payable inbox. Invoice and mandate fraud cost UK businesses £41m in 2025. Criminals don’t care what you do; they care that money moves on instructions received by email.
The layered fix
No single control stops this, because the scam attacks technology and people at once. The layers that work:
- MFA on every mailbox. This is the single highest-value control, because it turns a stolen password from a catastrophe into a non-event. If you do one thing after reading this, do this.
- Email security that spots impersonation. Advanced filtering, lookalike-domain detection and DMARC authentication so spoofed and near-miss emails get caught or flagged before a human has to judge them. This is core to our email and endpoint security service.
- Detection and response, watching around the clock. A compromised mailbox gives off signals: logins from odd places, new inbox rules, forwarding set up to external addresses. Managed detection and response catches intrusions in the quiet watching phase, before the strike.
- Verification callbacks, as a process with no exceptions. Any change of bank details gets verified by phoning the supplier on a number you already hold on file, never a number from the email. Written into the process, applied every time, immune to urgency and seniority.
- Staff awareness. Train people on this specific scam, not just generic phishing, and make it explicit that urgency on a Friday afternoon is a reason for more suspicion, not less checking.
The process layer deserves emphasis because it’s the one that works even on the day everything else fails. Technology can be bypassed; a colleague who always phones the known number cannot.
The first hour, if money has gone
- Phone your bank immediately. Ask for the fraud team and request an urgent recall of the payment. Minutes genuinely matter; recovery odds fall fast as funds are moved on.
- Report to Action Fraud, at actionfraud.police.uk or 0300 123 2040. If you’re a regulated firm, your reporting duties to your regulator may apply too.
- Contain the mailbox. Assume the attacker is still inside and reading. Reset the password, revoke active sessions, check for rogue inbox rules and forwarding, and enforce MFA. This is where you call us.
- Preserve everything. Don’t delete the emails, however tempting. Headers, rules and login records are the evidence for the bank, the police and any insurance claim.
- Warn the other party. If a supplier’s or client’s mailbox was the compromised one, they’re about to defraud someone else with it.
Make yourself the hard target
Criminals running this fraud are volume operators: they compromise widely and strike where it’s easy. A business with MFA everywhere, monitored mailboxes and a callback rule that everyone actually follows isn’t worth their Friday. If you’re not certain that describes you, book a consultation and we’ll check the gaps before someone else does, or if the worst has already happened, call the service desk first and we’ll help you lock it down.