The main types
- Payment redirection: a genuine invoice is intercepted and the bank details are swapped. The most common and most costly form.
- Business email compromise: an attacker gets into a real mailbox and sends payment instructions from it.
- Fake supplier invoices: an invoice for goods or services that were never supplied, often for a plausible small amount.
- Impersonation of a director or boss: an urgent request to pay something quickly and quietly, timed for when the real person is unreachable.
- Duplicate or inflated invoices: real supplier, real work, wrong amount or billed twice.
How the attack usually runs
It is patient, not opportunistic. The typical sequence looks like this:
- A mailbox is compromised, at your business or your supplier's.
- The attacker reads quietly for weeks, learning who pays what and when.
- A lookalike domain is registered, one character off the real one.
- A genuine invoice is copied and the bank details changed.
- It is sent at the moment a payment is expected, often with mild urgency.
- The money is withdrawn and moved on within hours.
Why it works on careful people
Because nothing about it looks like a scam. The supplier is real, the invoice is real, the work was done, the amount is right. Only the destination is wrong, and that is the one detail nobody re-reads.
What actually stops it
Checks that run before money moves, every single time: verifying bank details out of band, comparing payee details against payment history, requiring a second approver on any change, and holding the pay run when something does not match.
RILLA Shield runs those checks automatically across invoices, payees and payment files, so the protection does not depend on anyone remembering.