A fraudulent invoice does not always look suspicious. It may use a genuine supplier’s name, a copied conversation and a plausible amount. Spam filtering is only part of the answer: a message can arrive from a compromised account. For a small business, one useful habit makes a real difference: verify a change to where money goes independently of the message requesting it.
Check the request, not just its appearance
A logo and a professional signature are easy to copy. Read the full sender address and the domain behind a link, rather than the displayed name alone. An extra letter or an unfamiliar domain is a reason to stop. A correct address still does not prove the request is genuine. Ask whether you expected the invoice, whether it matches your agreement and whether the unusually short deadline makes sense.
Confirm changes through a known channel
When a supplier asks you to use a new bank account, call the number already held in your contract or business records. Do not use a new number in that same email. Confirm the invoice, the beneficiary and the account change. For significant payments, separate preparation from approval. A rule that applies to every supplier is easier to follow than a judgement made under pressure.
Open your account directly
For hosting or domain invoices, open the account from a bookmark or type the address you already know. Check whether the invoice and service status appear there. Do not enter a password on a page reached through a threatening message. Treat archives and documents asking you to enable macros with caution. An ordinary invoice should not require you to switch off your computer’s protection before reading it.
If someone already followed the link
A click does not automatically mean a compromise. Record what happened: was a password entered, a file downloaded or a login approved? If a password was disclosed, change it from a trusted device, revoke active sessions and check recovery methods. If money was transferred, contact your bank immediately. Preserve the message for investigation instead of forwarding the attachment around the team and asking everyone to open it.
Make the rule easy to follow
Write down three steps: pause the payment, verify separately and report to the designated person. Enable multifactor authentication for email and protect financial accounts. Make it clear that quick reporting is welcome, including after a mistake. If people fear speaking up, the business loses valuable time to contain the damage. Verification should be a routine process rather than an accusation.
Sources and further reading
A CloudCity editorial guide informed by the documentation below. Check the official source for rules and procedures that may change.