SardineCon SF/2026

Learn More
Fraud types4 min de leitura

O que é Invoice redirection?

SUBSCRIBE

Invoice redirection is changing the payment details on an otherwise real invoice so the money lands in an account the fraudster controls. Everything else about the invoice is genuine, which is exactly what makes the switch so easy to miss.

What is invoice redirection, in plain English?

Invoice redirection is a scam that takes a legitimate invoice and changes only one thing: the bank account the money should go to. The goods or services were really supplied, the amount is correct, and the vendor is real. The fraudster simply intercepts the payment instructions and swaps in an account they control, so a genuine payment for a genuine debt ends up in the wrong hands.

It almost always starts with compromised or spoofed email. The fraudster hacks into a vendor's mailbox, or impersonates it convincingly, and sends the customer a "change of bank details" notice. Because it arrives from what looks like a trusted supplier, and often near a real payment cycle, the accounts payable team updates the record and pays as normal.

Invoice redirection is the payment-side result of business email compromise and vendor-email compromise. Everything the AP team checks, the invoice, the amount, the vendor name, is authentic; only the destination is wrong. That is why it slips past controls aimed at fake invoices and why the defense has to focus specifically on verifying bank-detail changes.

How an invoice redirection attack works

The attack turns a real business relationship against itself:

  1. Compromise — Get inside the email. The fraudster hacks or spoofs the vendor's email account, gaining a trusted channel to the customer.
  2. Watch — Learn the payment cycle. They observe real invoices, amounts, and timing so their request lands when a payment is genuinely expected.
  3. Ask — Request a bank change. A message from the "vendor" asks the customer to update bank details, often with a nudge of urgency.
  4. Divert — Pay the wrong account. AP updates the record and pays the next invoice into the fraudster's account, who quickly moves the funds on.

Who is involved?

Who

Their role

The paying company

Receives the fake change request and sends a real payment to the wrong account.

The real vendor

Is owed the money, often unaware their email was compromised, and still expects to be paid.

The fraudster

Controls the compromised or spoofed email and the destination account that receives the funds.

The receiving bank

Hosts the mule or shell account the diverted payment lands in before it is swept away.

What it looks like in practice

In practice

A construction firm has paid the same subcontractor monthly for two years. One afternoon an email arrives from the subcontractor's usual address explaining they have "switched banks" and asking that the next payment go to a new account, please, before month-end. The message matches the subcontractor's tone and references the current project.

AP updates the record and pays the next invoice, around 40,000 dollars, to the new account. Weeks later the real subcontractor chases the overdue payment, and it becomes clear their email was compromised. The invoice, amount, and vendor were all real; only the bank account had been swapped, and the funds were long gone.

Why it matters to operators

Invoice redirection defeats the instincts of a careful AP team, because everything they normally verify is genuine. There is no fake vendor to spot and no inflated amount to question, so controls designed for invoice fraud simply do not trigger. The losses are often large single payments, and because the money moves fast through mule accounts, recovery is difficult once it leaves.

The defense has to target the one thing that changed: the bank details. Verify every change-of-account request by calling a known, previously held contact number, never a number or address supplied in the request itself. Require two approvers for bank-detail changes, and flag the first payment to any newly changed account for extra review. The classic tell is a change request that arrives near a real payment cycle with a hint of urgency, so treat that combination as a stop-and-verify trigger.

What to watch in the data

  • Change-of-bank requests. Any request to update vendor bank details, especially by email and especially near a payment date.
  • Urgency cues. Pressure to make the change quickly or before a deadline, a common social-engineering push.
  • First payment to a new account. The initial payment after a bank-detail change is the highest-risk moment and deserves extra scrutiny.
  • Subtle email differences. Look-alike domains, reply-to addresses that differ from the sender, or slight changes in tone or formatting.
  • Vendor chasing payment. A real supplier following up on an invoice you believe you already paid, a sign the money went elsewhere.

Quick questions

How is invoice redirection different from invoice fraud?

Invoice fraud covers fake, inflated, or duplicate invoices. Invoice redirection uses a completely real invoice and changes only the destination bank account, which is why standard invoice-fraud checks miss it.

How is it connected to business email compromise?

It is the payment-side outcome of BEC and vendor-email compromise. The fraudster gains a trusted email channel, then uses it to send a convincing bank-change request that redirects a genuine payment.

What is the single best control?

Calling a known, previously held contact to verify any bank-detail change before updating it, using a number you already have on file, never one supplied in the request. Voice verification breaks the email-only trust.

Why is the first payment to a new account risky?

Because if the change was fraudulent, that first payment is where the loss happens. Flagging and double-checking the initial payment to any newly changed account catches the scam before repeat losses.

Can the money be recovered?

Sometimes, if caught within hours, but often not. The funds usually land in mule accounts and are swept onward quickly, so prevention and fast detection matter far more than recovery.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

O que saber junto com Invoice redirection