A person typing on a laptop whilst sitting on a yellow chair, with a large padlock and digital security icons floating above, illustrating cyber security.

Email Fraud in Businesses: The Altered Invoice and the Urgent Order

3-minute read DataRoad

In summary

  • Most fraud doesn't exploit software — explores pressure, hierarchy and trust.
  • Invoice modification is the most profitable fraud in Portugal and leaves no technical trace whatsoever.
  • No technology can prevent a payment authorised by mistake. What is preventing it is a procedure.
  • The rule that resolves almost everything: bank detail changes are confirmed by telephone, at a number already known.

When talking about computer security, people think of firewalls and antivirus software. But most of the money that Portuguese companies lose to fraud does not go through a technical flaw — it goes through a transfer authorised by someone who believed what they were reading.

They are attacks that do not exploit software. They exploit haste, hierarchy and trust. And that is why no technology alone solves them.

The amended invoice

It is the most profitable scheme and the hardest to detect. This is how it works.

Someone compromises a supplier's mailbox — or the company's own — and watches in silence for weeks. They learn who invoices whom, the usual amounts, the tone of the messages, the deadlines.

When a real invoice arrives, intercept it and resend it with the IBAN changed. Everything else is authentic: the value, the reference, the conversation history, the signature. It frequently comes accompanied by a casual note — “we've changed bank, please update our details”.

Payment is made by someone who did their job correctly. The fraud is only discovered weeks later, when the real supplier asks about the overdue payment.

The rule that completely stops this fraud: Any change to a supplier's bank details is confirmed by phone, to a number they already had before — never to the number given in the email requesting the change. No exceptions, including for long-standing suppliers.

Dark DataRoad IT security banner with a Portuguese headline about email-based attacks and bullet points on anti-phishing, MFA, backups and team training.
The altered invoice fraud does not exploit a technical flaw – it exploits a process without verification.

The urgent request from management

A message from someone in management to the accounts or treasury department. It is urgent, confidential, the person is travelling and cannot answer the phone. They are requesting an immediate transfer.

The details vary, but the structure is always the same and it attacks three things at the same time: urgency, so there's no time to think; authority, to discourage questions; and confidentiality, to prevent verification with colleagues.

These attacks are quite convincing nowadays: they use the right name, the right signature, and sometimes refer to real internal matters gathered from previous emails.

Organisation is the defence, not technology: no transfer above a set amount is made without confirmation via a second channel — and management must explicitly tell the team that they will never be annoyed at being asked for confirmation.

Credential theft

The gateway for both of the previous schemes is almost always the same: someone typed their password into a page that looked legitimate.

Fake authentication pages are now faithful copies. What gives them away is the address — and that is precisely what nobody checks when they are in a rush.

Three measures drastically reduce this risk:

  • Two-factor authentication for everyone. It is the single measure with the best balance between effort and protection. A stolen password is no longer enough.
  • Password manager. As well as preventing reuse, it has an underestimated advantage: it doesn't autofill credentials on websites whose address doesn't match the real one. It spots the fraud before the person does.
  • Automatic forwarding alerts. Creating a rule to forward mail externally is the first step for anyone who compromises an account — and it goes unnoticed for months.

The procedures that work

Four simple rules, written down and known by everyone, that resolve the vast majority of cases:

  • IBAN changes are confirmed by telephone, to a previously known number.
  • Payments above a limit require two people. He who requests is not the one who approves.
  • No urgent request dispenses with verification. Urgency is the attacker's tool, not a reason to skip steps.
  • Anyone can stop a payment without having to justify mistrust. If the company culture punishes those who ask questions, no one asks.

And short, regular training with real examples. Not a two-hour session once a year that nobody remembers — fifteen minutes a quarter with concrete cases works better.

If it has already happened

Speed is everything. In the first few hours there is still a chance.

Contact the bank immediately to request the cancellation or recovery of the transfer — the sooner you do it, the higher the likelihood. Change the passwords of the accounts involved and end all active sessions. Check if any forwarding rules have been created in your mailbox. File a complaint with the authorities. And notify the supplier or client on the other end, because they are likely the ones who have been compromised — and other companies will be receiving the same invoices.

Then, and only then, figure out how they got in. Without that, it will happen again.

DataRoad helps companies implement IT security and strong authentication, within the managed IT services.

A chat before making a decision

Whether you’re tackling a specific problem, planning a move or simply looking for a second opinion, we always start in the same way: by understanding your situation before making any suggestions. No obligation, no jargon and no catalogues.

Book an assessment of your infrastructure

Read more articles ...

Find out about some of the companies that have already chosen and opted for our IT services

Contact us now

Contact Form

Request a quote from DataRoad. We’ll take care of the rest with a prompt and clear response to support your business’s needs.

Tell us what you need. IT support, network installation, cyber security, an office move or simply a second opinion on your IT infrastructure — we’re here to help.

Please fill in the form and a specialist technician will contact you on the same day.

    A reply on the same working day. No obligation.

    DataRoad — IT services for businesses
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.