HomeTypologyIQ
Fraud

Business Email Compromise & Invoice Redirection

Business email compromise and mandate or invoice redirection fraud. Attackers impersonate suppliers, executives, or counterparties to redirect legitimate payments to fraudster-controlled accounts using altered bank details, often followed by rapid layering through mule accounts to extract funds.

Firm typesBank / Credit InstitutionE-Money Institution (EMI)Payment Institution (PI)Neobank / Digital Bank
ProductsDomestic PaymentsCross-Border PaymentsFX TransfersE-Money Accounts
CustomersCorporatesSMEsIndividualsAgents & Intermediaries
Key terms:

What it is

Business email compromise and mandate or invoice redirection fraud. Attackers impersonate suppliers, executives, or counterparties to redirect legitimate payments to fraudster-controlled accounts using altered bank details, often followed by rapid layering through mule accounts to extract funds.

Control objective

Detect and disrupt invoice and mandate redirection driven by business email compromise, including payments to newly amended beneficiary details and the receipt and onward layering of fraud proceeds through mule accounts.

Data required

  • Beneficiary bank details and recent changes to existing payees
  • Payment instruction channel and any change in usual instruction source
  • Payer and supplier relationship and historical payment pattern
  • Confirmation of Payee (name and account) match result
  • Receiving account age, profile, and prior activity
  • Speed and pattern of onward transfers from the receiving account
  • Device, IP, and email-origin indicators where available
  • Beneficiary jurisdiction and cross-border routing

Related typologies (Fraud)

Unusual Business Activity vs Declared Profile

Transaction activity that is materially inconsistent with the customer's declared business profile, sector, or expected turnover, potentially indicating front company activity, invoice fraud, or undisclosed business changes.

Authorised Push Payment (APP) Fraud

Social engineering schemes where victims are manipulated into authorising real-time payments to accounts controlled by fraudsters. Includes impersonation of banks, HMRC, solicitors, and romance scams, with losses often irrecoverable once funds are moved through mule networks.

Insurance & Claims Fraud

Fraudulent insurance claims including staged or fabricated losses, inflated or exaggerated claim values, duplicate claims across insurers, and organised claims rings operating across multiple policyholders. Proceeds are extracted as claim settlements and may be laundered through linked bank accounts.

Romance & Investment Scams

Romance and investment scams, including pig-butchering, where victims are manipulated over time into sending payments to scam-controlled bank accounts or crypto wallets. Payments are often escalating, made to fake investment platforms, and rapidly layered or converted to crypto by the receiving network.

Account Takeover Fraud

A fraudster gains control of a genuine customer's account through credential theft, phishing, or SIM-swap, then changes device, contact, or beneficiary details before rapidly draining funds to mule accounts. Speed and post-compromise profile changes distinguish takeover from normal customer behaviour.