Fake Invoice and Wire Transfer Scams: How Central Florida Businesses Lose Money by Email
Most business owners picture a cyberattack as something loud. Screens go dark, files get locked, a ransom note appears. The scam that actually drains the most ...
Most business owners picture a cyberattack as something loud. Screens go dark, files get locked, a ransom note appears. The scam that actually drains the most money from small businesses is far quieter than that. Nothing gets hacked, nothing breaks, and no alarm goes off. An email shows up that looks completely normal, someone in your office pays it, and the money is gone before anyone notices anything was wrong.
This category of fraud is called business email compromise, and the FBI consistently ranks it as the costliest cybercrime in the country by dollars lost. It works because it targets your process instead of your technology. We help businesses across Orlando, Lake County, Clermont, Mount Dora, Eustis, Tavares, Winter Garden, and Apopka put guardrails around the way money leaves the building, and the fix is usually simpler and cheaper than owners expect. Here is what these scams look like and how to shut them down.
1. The Fake Vendor Invoice
This is the most common version by far. A vendor you genuinely work with sends an invoice, except the email did not really come from them. The attacker either spoofed the sending address or, worse, actually got into that vendor’s mailbox and is replying inside a real conversation thread. The invoice amount is believable, the logo is right, the format matches what you always get. The only thing that changed is the bank account on the remittance page. Your bookkeeper pays it exactly the way she pays every other invoice, and it clears. By the time the real vendor calls asking where their money is, the funds have been moved through two or three accounts and are effectively unrecoverable.
2. The Urgent Request From the Boss
The second flavor targets the relationship between an owner and whoever handles the checkbook. An email arrives that appears to be from the owner, often sent late in the day or right before a holiday weekend. The tone is short and a little stressed: “I am in a meeting, can you get this wire out today? I will explain later.” The pressure is deliberate. The scammer is counting on the fact that a good employee does not want to bother the boss with a question when the boss just said they are busy. In smaller offices the attacker may even use a lookalike domain, swapping one letter in your company name so the reply address passes a quick glance.
3. The Payroll and Direct Deposit Redirect
A cheaper version of the same trick goes after employees instead of vendors. Someone emails HR or the office manager claiming to be a staff member who just switched banks and needs their direct deposit updated before Friday. There is no wire transfer involved, no unusual dollar amount, nothing that looks like fraud. One paycheck goes to the attacker, and the affected employee usually does not find out until payday. It is a smaller hit than a fake invoice, but it is easy to repeat, and it tends to expose how casual the approval process really is.
4. Why Your Spam Filter Does Not Catch These
Spam filters are very good at spotting malware attachments, sketchy links, and mail blasted from known bad servers. A business email compromise message contains none of those things. It is plain text, sent from a real mailbox or a freshly registered domain with no bad reputation yet, and it asks for something a normal coworker might ask for. There is nothing technical for the filter to flag. That said, proper email authentication does close one big door: it stops criminals from sending mail that claims to come from your exact domain. If you have not set that up, start with our guide to SPF, DKIM, and DMARC records, because it is free to configure and it eliminates the easiest version of the impersonation.
5. The One Rule That Stops Almost All of It
If you take one thing from this article, make it this: any change to banking details gets verified by phone, on a number you already had on file, before a single dollar moves. Not a number from the email. Not a reply to the email. A number from your own records or an invoice from six months ago. That single habit defeats the fake vendor invoice, the urgent wire request, and the payroll redirect all at once, because every one of those scams depends on the conversation staying inside the channel the attacker controls. Write the rule down, put it in your onboarding paperwork, and make it clear that nobody will ever be in trouble for taking two minutes to confirm.
6. Build a Second Set of Eyes Into the Process
Rules only hold up when the process supports them. Require a second approver on any payment over a threshold that actually stings your business, whether that is two thousand dollars or twenty thousand. Set up new vendors through a form and a phone call rather than an email exchange. Ask your bank what dual control and callback verification options they offer on outgoing wires, because most business accounts include tools owners never turn on. And make sure your team knows these scams by sight, which is exactly what regular employee security training is for. The person holding the checkbook is your last line of defense, so give them permission to be skeptical.
7. Lock Down the Mailboxes Behind the Money
Behind a lot of these scams is one compromised email account, often belonging to a vendor, an accountant, or an assistant. Multi-factor authentication on every business mailbox is the single highest value control you can deploy, and it costs nothing on Microsoft 365 or Google Workspace. Beyond that, watch for the tells of a mailbox that has already been breached: forwarding rules nobody created, inbox rules that quietly move messages from your bank into an obscure folder, and sign ins from places your staff has never been. A good managed IT provider monitors for exactly that and catches it long before it turns into a fraudulent invoice.
The Bottom Line
Fake invoice and wire transfer fraud is not a technology problem with a technology solution. It is a con, and it succeeds because it slips into a routine that everybody trusts. The businesses that get hit are rarely careless, they are just busy, and the attacker knows exactly which busy moment to aim for. Verify banking changes by phone, require a second approver on meaningful payments, turn on multi-factor authentication everywhere, and get your email authentication records in order. That combination takes an afternoon to put in place and it protects the one thing no backup can restore, which is money that already left your account.
Not sure whether your business could stop a fake invoice today? Think Tech Support helps local companies lock down email, turn on multi-factor authentication, and build payment approval processes that hold up under pressure for businesses across Central Florida. Call us at (423) 486-6711 or reach out through our contact page for a free quote.
