Invoice Fraud: What to Do in the First 48 Hours
Updated 5 October 2026 by Investigation Bureau
If your business has just paid money into fraudulent bank details, speed matters more than understanding. The order is this. Phone your bank at once. Report to Report Fraud today. Keep every email untouched. Say nothing that could alert the fraudster, because the mailbox they compromised is very likely still being read. Diverted funds can be recovered, and whether they are depends overwhelmingly on how quickly those first calls are made.
Payment-diversion fraud, also known as business email compromise or BEC, is among the most damaging frauds aimed at UK companies. Below is the checklist for the first 48 hours. After it comes what happens next: how the money is traced, whether it comes back, and how the fraudster got into your correspondence to begin with.
The first 48 hours, in order
- Phone your bank's fraud team now. Ask them to attempt a recall and to alert the receiving bank, so that the destination account is frozen before the money is layered onwards. Mule accounts are emptied in hours and days, not weeks. This call is the biggest single factor in whether anything is recovered.
- Report to Report Fraud (the national reporting service that replaced Action Fraud). It is the UK's fraud reporting centre. Keep the reference number, because banks, insurers and later legal steps all refer back to it.
- Preserve the evidence untouched. Do not delete, forward or tidy the fraudulent thread, and do not reply to it. The complete emails, with their headers, are where the investigation lives. They show whether the fraud came from a compromised mailbox or a lookalike domain, and when the intrusion began.
- Do not tip off the fraudster. If a mailbox on either side has been compromised, the criminal is reading in real time. Take any sensitive discussion of the incident off email, to the phone or a separate clean channel, until you know whose account was breached.
- Verify before any further payment moves. Today, every pending payment to every supplier gets a callback check on a number you already know. A fraudster who succeeds once often runs a second invoice while the first is still undiscovered.
- Consider your data-protection duties. If a mailbox in your own business was compromised, personal data may have been exposed, and that can start a 72-hour regulatory clock for reporting. Assess it early and with advice, not once the dust has settled.
How the fraud works
The mechanics are worth understanding because they decide where the evidence sits. In most cases the criminal has been reading a genuine email conversation for weeks. They get there through a compromised mailbox at your supplier or at your own business, or they work from a lookalike domain one character away from the real one. They wait until an invoice is truly due. Then they send "updated bank details" inside the established thread, in the established voice, often on the real letterhead. Accounts teams pay because everything about the request is authentic except the account number. This is not carelessness. It is a professional crime built on patience.
Can the money be recovered?
The honest answer is sometimes, and the odds are set in the first few days. Banks can recover funds that are frozen before they leave the mule account, which is why the immediate phone call outranks everything else. Once money has moved on, the options narrow but they do not disappear. Reimbursement schemes for authorised push payment fraud can apply, depending on the banks and the circumstances. Traced funds can support civil action against identified recipients, including freezing steps. Money converted to cryptocurrency is not gone either. On-chain movements can be traced to the exchanges where criminals cash out, and that is where legal recovery steps attach. What no honest adviser will promise is guaranteed recovery. Treat anyone who does promise it, especially for an upfront fee, as the second wave of the fraud.
What an investigation adds
The bank recall and the Report Fraud report are necessary. They are also where most victims stop, without ever learning how it happened or whether it is still happening. A fraud investigation answers the questions that process leaves open:
- Whose mailbox, and since when. Header analysis and account forensics establish which side was compromised, when the intrusion began and what else was read. That decides where liability sits, what you tell your other counterparties and whether the door is now shut.
- Where the money went. Tracing through accounts and, where relevant, cryptocurrency movements builds the picture that recovery action, insurers and litigation all depend on.
- Who received it. Mule accounts belong to identifiable people, and somebody registered the lookalike domain. Identification turns a write-off into a claim.
- Evidence packaged for use. The bank dispute, the insurance claim, the civil claim and the police file each need it, with continuity preserved throughout.
Preventing the next one
The fixes that work are procedural, cheap and dull. Verify any change of bank details by calling back on a number you already hold, never one taken from the email announcing the change. Require dual authorisation for payments above a set threshold. Treat email security as a finance control and not an IT nicety: modern authentication and two-factor access on mailboxes, and protection against domain spoofing. Vetting a new counterparty before money moves helps as well. Our guide to checking whether a company is legitimate covers the ten-minute version.
Frequently asked questions
Will our bank refund the money?
It depends on speed, on the circumstances and on the scheme rules that apply to the payment. Reimbursement frameworks for authorised push payment fraud exist, but eligibility and caps vary, and business payments are treated differently from consumer payments. Three things reliably strengthen your position: immediate reporting, a clean evidence trail, and being able to show that verification procedures were in place. One thing reliably weakens it: delay.
Should we tell the supplier whose email was hacked?
Yes. Do it promptly, by phone first and then in writing. Their compromised mailbox may be defrauding other customers right now, and the written record protects your position on where responsibility lies. Expect some defensiveness. The header evidence usually settles whose systems were breached.
The money went to cryptocurrency. Is it gone?
Not necessarily. Public ledgers make the movement of crypto traceable in a way cash never was. Funds are typically followed to the exchange where they are cashed out, and exchanges respond to the right legal steps. Tracing is investigation work, and recovery is then a legal process. We do the first, and give the people handling the second the evidence they need.
Do we need to report this to the ICO?
If personal data was exposed when your systems were compromised, a report may be required within 72 hours of your becoming aware of it. That is a very short clock. Not every incident meets the threshold, but the assessment should be made in the first day or two, with advice, and documented whichever way it goes.
Just discovered a diverted payment? Ring your bank first. Then tell us what happened in confidence and say that it is urgent. A free first conversation will map what is recoverable and what needs preserving.
Related reading: Fraud investigations · Cyber investigations · How to check if a company is legitimate