Invoice Fraud: What to Do in the First 48 Hours
Updated 27 August 2026 by K3K Investigations
If your business has just paid money to fraudulent bank details, speed matters more than understanding. The order is: your bank immediately, by phone; Action Fraud today; preserve every email untouched; and say nothing that tips off the fraudster — because the mailbox they compromised is very likely still being read. Recovery of diverted funds is genuinely possible, and it is overwhelmingly a function of how fast the first calls happen.
Payment-diversion fraud — also called business email compromise, or BEC — is one of the most damaging frauds hitting UK companies, and among the most common we investigate. Here is the first-48-hours checklist, then what happens after: how the money is traced, whether it comes back, and how the fraudster got inside your correspondence in the first place.
The first 48 hours, in order
- Phone your bank's fraud team now. Ask them to attempt recall and to alert the receiving bank so the destination account is frozen before the money is layered onwards. Mule accounts are emptied in hours and days, not weeks — this call is the single biggest factor in whether anything is recovered.
- Report to Action Fraud (the UK's fraud reporting centre) and keep the reference number. Banks, insurers and later legal steps all key off it.
- Preserve the evidence untouched. Do not delete, forward, "tidy" or reply to the fraudulent thread. The full emails — with their headers — are where the investigation lives: they show whether the fraud came from a compromised mailbox or a lookalike domain, and when the intrusion began.
- Do not tip off the fraudster. If a mailbox on either side is compromised, the criminal is reading in real time. Move sensitive discussion of the incident off email — phone, or a separate clean channel — until you know whose account is breached.
- Verify before any further payment moves. Every pending payment to every supplier gets a callback check on a known number today. Fraudsters who succeed once frequently run a second invoice while the first is still undiscovered.
- Consider your data-protection duties. If a mailbox in your business was compromised, personal data may have been exposed — which can start a 72-hour regulatory clock for reporting. Assess this early with advice, not after the dust settles.
How the fraud works
The mechanics are worth understanding because they decide where the evidence sits. In most cases the criminal has been reading a genuine email conversation for weeks — through a compromised mailbox at your supplier, at you, or via a lookalike domain one character adrift from the real one. They wait for the moment an invoice is genuinely due, then send "updated bank details" in the established thread, in the established voice, often on the real letterhead. Accounts teams pay because everything about the request is authentic except the account number. This is not carelessness; it is a professional crime built on patience.
Can the money be recovered?
Honestly: sometimes — and the odds are set in the first days. Banks can recover funds that are frozen before they leave the mule account, which is why the immediate phone call outranks everything else. Where money has moved on, options narrow but do not vanish: reimbursement schemes for authorised push payment fraud can apply depending on the banks and circumstances involved; traced funds can ground civil action, including freezing steps, against identified recipients; and money converted to cryptocurrency is not gone — on-chain movements can be traced to the exchanges where criminals cash out, which is where legal recovery steps attach. What no honest adviser will promise is guaranteed recovery — and you should treat anyone who does promise it, especially for an upfront fee, as the second wave of the fraud.
What an investigation adds
The bank recall and the Action Fraud report are necessary — and they are also where most victims stop, never learning how it happened or whether it is still happening. A fraud investigation answers the questions the process leaves open:
- Whose mailbox, since when. Header analysis and account forensics establish which side was compromised, when the intrusion began and what else was read — which decides whose liability it is, what you tell other counterparties and whether the door is now shut.
- Where the money went. Tracing through accounts and, where relevant, cryptocurrency movements — building the picture that recovery action, insurers and litigation all depend on.
- Who received it. Mule accounts belong to identifiable people; lookalike domains are registered by someone. Identification converts a write-off into a claim.
- Evidence packaged to be used — for the bank dispute, the insurance claim, the civil claim, and the police file, with continuity preserved throughout.
Preventing the next one
The fixes that actually work are procedural, cheap and boring: callback verification of any change to bank details, using a number you already hold — never one from the email announcing the change; dual authorisation on payments above a threshold; and email security (modern authentication and two-factor access on mailboxes, domain-spoofing protection) treated as a finance control rather than an IT nicety. Vetting new counterparties before money moves helps too — our guide to checking whether a company is legitimate covers the ten-minute version.
Frequently asked questions
Will our bank refund the money?
It depends on speed, circumstances and the scheme rules that apply to the payment — reimbursement frameworks for authorised push payment fraud exist, but eligibility and caps vary, and business payments are treated differently from consumer ones. What consistently strengthens the position: immediate reporting, a clean evidence trail, and being able to show verification procedures existed. What consistently weakens it: delay.
Should we tell the supplier whose email was hacked?
Yes — promptly, by phone first, and then in writing. Their compromised mailbox may be defrauding other customers at this moment, and the written record protects your position on where responsibility sits. Expect defensiveness; the header evidence usually settles whose systems were breached.
The money went to cryptocurrency — is it gone?
Not necessarily. Crypto's public ledgers make movement traceable in a way cash never was; funds are typically tracked to an exchange off-ramp, and exchanges respond to the right legal steps. Tracing is investigation work; recovery is then a legal process — we do the first and hand you to the right people for the second, with the evidence they need.
Do we need to report this to the ICO?
If personal data was exposed in a compromise of your systems, a report may be required within 72 hours of becoming aware — a genuinely short clock. Not every incident meets the threshold, but the assessment itself should happen in the first day or two, with advice, and be documented either way.
Just discovered a diverted payment? Ring your bank first — then call us. A free, confidential consultation will map what is recoverable and what needs preserving today. 020 3343 7007 (24 hours) or book a call.
Related reading: Fraud investigations · Cyber investigations · How to check if a company is legitimate