The email comes from a supplier you have paid many times. It arrives in the same thread as the last invoice, written in the same tone, signed by the same person. It says they have changed banks and gives new account details for this month's payment. Everything looks right.
It is not their email. Or it is their real email account, but somebody else is typing. And the money you send will be gone within hours.
This is payment redirection fraud, also called business email compromise, mandate fraud or payment diversion fraud. It does not look like hacking. It looks like normal business, which is exactly why it works. The good news is that one simple, cheap habit stops most of it.
This guide explains how the fraud works, the warning signs, the controls government and police bodies recommend, how to protect your customers from fraud in your name, and what to do in the first hour if money has already gone.
What is payment redirection fraud?
Payment redirection fraud is when a criminal persuades a business to send a genuine payment to the wrong bank account, usually by impersonating a supplier who has changed banks or a senior manager who needs an urgent transfer.
The FBI's Internet Crime Complaint Center defines business email compromise as a scam targeting businesses and individuals who work with suppliers or regularly make wire transfers, carried out by compromising email accounts and other forms of communication, such as phone numbers and virtual meeting applications, through social engineering or computer intrusion [1].
The UK's national fraud reporting service describes mandate fraud, also known as payment diversion fraud and business email compromise, as tending to affect businesses where electronic financial transactions take place, typically through a request for payment or a notice that bank account details have changed [2].
There are three common versions:
The supplier version. An email appearing to come from a supplier says their bank details have changed. Your next payment goes to the fraudster.
The boss version. An email appearing to come from the owner or a senior manager asks for an urgent, confidential transfer. Europol calls this CEO fraud: an employee authorised to make payments is tricked into paying a fake invoice or making an unauthorised transfer [3].
The payroll version. An email appearing to come from an employee asks for their salary to be paid into a new account.
The mechanics differ slightly. The defence is the same for all three.
How big is the problem?
The FBI recorded 24,768 business email compromise complaints in 2025, with reported losses of about 3.05 billion US dollars, making it the second most costly type of cyber-enabled fraud in its report, after investment fraud.
The exact figure reported to the FBI's Internet Crime Complaint Center was 3,046,598,558 US dollars. The equivalent figure for 2024 was 21,442 complaints and about 2.77 billion US dollars [4].
An FBI public service announcement in 2024 put exposed losses worldwide between October 2013 and December 2023 at about 55.5 billion US dollars across more than 305,000 incidents [5].
These are US figures, reported to a US agency. We did not find an official UAE figure for losses to this fraud, so we cannot tell you how common it is here in numbers.
But it is not a foreign problem. In 2020, Dubai Police announced the arrest of a gang, in an operation called Fox Hunt 2, whose methods included hacking corporate emails to deceive clients into transferring money to the gang's bank accounts [6]. Abu Dhabi Police's Aman service lists company email fraud among its current scam warnings, describing a fraudster sending an email that appears to come from a company manager asking for money to be transferred to a specific account [7]. And the FBI's 2024 announcement named the UAE among the countries where international banks were used as intermediate stops for stolen funds [5].
How the fraud actually works
The most effective versions do not rely on a fake email arriving out of nowhere; they rely on the fraudster reading real conversations and striking at exactly the right moment.
A typical sequence:
1. Getting in. The fraudster gains access to a mailbox, at the supplier or at your business, usually through a phishing email that collects a password. The UAE Cyber Security Council said in April 2026 that more than 75 per cent of cyber breaches begin with phishing emails or fraudulent messages [8]. Alternatively, they register a domain that looks almost identical to the real one.
2. Watching. They read the email quietly, sometimes for weeks. They learn who pays whom, how invoices are sent, what the people sound like and when payments are due. Some set up hidden forwarding rules so they keep receiving copies even after a password is changed.
3. Striking. When a real invoice is due, they send a message, often in the same thread, saying the bank details have changed. Because it concerns a real invoice, arrives at the right time and sounds like the right person, nothing feels wrong.
4. Moving the money. Once the payment lands, it is typically moved on quickly, often through several accounts and sometimes several countries.
The newer twist is that the fraud no longer has to be email. The FBI's 2025 report notes that businesses reported losses of over 30 million US dollars to business email compromise scams involving artificial intelligence, and that voice cloning can be used to request wire payments [4]. A phone call in a familiar voice is no longer proof of anything if you did not dial the number yourself.
A worked example
Here is how a typical case unfolds, step by step, and the single point at which it could have been stopped. The business and people are illustrative; the pattern is the one official warnings describe.
A Dubai trading company has bought packaging from the same supplier for three years. Invoices arrive monthly by email from the supplier's accounts manager, and the company pays by bank transfer at the end of each month.
In March, somebody at the supplier clicks a convincing link and enters their email password. Nobody notices. The fraudster now has quiet access to the accounts manager's mailbox and spends several weeks reading it: who the customers are, how invoices are worded, when payments are due, how the accounts manager signs off.
At the end of April, the genuine invoice goes out as usual. Two days later, a follow-up arrives in the same thread, from the same address, in the same style: the supplier has moved banks following an audit, please update the details before paying this month's invoice. A new IBAN is attached on a letterhead copied from a real one.
At the trading company, the accounts clerk sees nothing wrong. It is the right person, the right thread, the right amount, the right week. The clerk updates the details and the payment goes out.
The supplier chases payment three weeks later. By then the money has long gone.
Where it could have been stopped: at one point only, the moment the bank details changed. A call to the accounts manager on the number already held in the company's records would have taken two minutes and ended the fraud, because the real accounts manager knew nothing about a new bank.
Every other part of the story was out of the trading company's control. The supplier's mailbox was compromised. The email was genuinely from their address. The timing was perfect. That is the point: you cannot rely on spotting a fake, because the best ones are not fake in any way you can see. You can only rely on the callback.
The warning signs
Official warnings repeatedly name the same four signs: new bank details, urgency, secrecy, and a request to skip the normal process.
Europol lists pressure and a sense of urgency, requests for absolute confidentiality, and unusual requests that contradict internal procedures [3]. It describes typical language such as "confidentiality", "the company trusts you" and "I am currently unavailable" [3].
Abu Dhabi Police's Aman service says scams share urgency, a request for sensitive data and an offer that seems illogically attractive [7].
The UK fraud reporting service highlights fraudulent emails providing altered bank account details to redirect payments intended for legitimate transactions [9].
The combination that should always trigger a check:
Any change to bank details, however ordinary the explanation.
Any payment request marked urgent or confidential, especially from somebody senior.
Any request to skip or shorten the usual approval, for whatever reason.
Any message from a sender address you have not read in full, particularly on a phone, where the full address is often hidden. The FBI advises verifying the email address used to send messages, especially on mobile devices, and watching for links with misspellings of the real domain [5].
None of these proves fraud. Each is a reason to pick up the phone before any money moves.
The one control that stops most of it
Call the supplier back on a phone number you already had before the request arrived, speak to somebody you know, and confirm the change before paying. The FBI, CISA, the UK NCSC and the UK fraud reporting service all recommend this in some form.
The FBI advises using secondary channels or two-factor authentication to verify requests for changes in account information [10]. The UK fraud reporting service says to contact the supplier directly using their official and verifiable contact details to confirm any request to move money into a new account [2]. The UK National Cyber Security Centre recommends verifying all important email requests through a second type of communication, such as a phone call [11].
The US Cybersecurity and Infrastructure Security Agency adds the detail that makes it work: the phone number should not come from the email itself, but from a known contact list for that supplier. It suggests keeping that list in non-electronic form [12].
Why the detail matters. If the email is fraudulent, then everything in it is controlled by the fraudster: the reply address, the phone number in the signature, the number on the new invoice. Call any of those and the fraudster answers and confirms. Verification only works through a channel the fraudster cannot reach, which means contact details you held before the request arrived.
A printed list of supplier contacts, with the names and numbers of the people authorised to confirm payment changes, is the simplest tool in this whole article. An attacker in your email cannot edit a piece of paper.
Turning the habit into a process
A callback that depends on one careful person remembering is a habit; a callback built into who can change bank details, and how, is a control.
Limit who can change bank details. The UK fraud reporting service recommends that only designated employees should be able to make changes to payment arrangements [2].
Use two people. It also recommends a verification process involving multiple individuals before executing any fund transfer or sensitive transaction [9]. In practice: one person records the change with evidence of the callback, a second person approves it, and the system logs both, along with the old and new details.
Use a test payment for large first-time transfers. The UK fraud reporting service suggests sending a small amount first and confirming it has been received before sending the full amount [2]. This does not replace the callback, since a fraudster will confirm receipt too if you call the wrong number, but with a callback to a known contact it adds a second check.
Apply the rule to everybody, including the owner. The CEO version of the fraud relies on staff feeling unable to question a senior request. Europol's advice to employees is to apply payment security procedures strictly, not skip any steps and not give in to pressure [3]. That only works if the owner has said, in advance and in writing, that nobody is exempt. A genuine urgent payment survives a two-minute phone call. A fraudulent one does not, which is exactly why fraudsters ask for speed and secrecy.
Use your software's controls. Many accounting and procurement systems can restrict who edits supplier bank details, require a second approval, keep a log of changes, and flag payments to details that changed recently. Those controls only work if they are switched on and nobody shares logins. Our guide on procurement software covers building this into a supplier approval workflow.
Treat new suppliers the same way. Onboarding is a common entry point, because nothing looks unusual yet. Collect bank details through the same verified process as changes, confirm them by phone with a contact you have verified independently, and record who confirmed them and when.
When finance is one person
A two-person rule still works in a small business; the second person is usually the owner, and the bank can enforce it for you.
Many small businesses have a single bookkeeper or accountant, and the advice to "use two people" can feel impossible. It is not, because the second person does not need to be in finance. They need to be somebody other than the person entering the change.
The owner as approver. The simplest arrangement is that the bookkeeper records any bank detail change, with a note of the callback, and the owner approves it before the next payment run. It takes a minute and it means one person being fooled is not enough.
Use your bank's controls. Many business banking platforms allow a payment or a new beneficiary to require approval by a second user before it is released. If your bank offers it, switch it on. It enforces the two-person rule even when nobody remembers to.
Separate adding a beneficiary from paying one. Where possible, set things up so that adding or editing a beneficiary and releasing a payment to it are separate steps, ideally done by different people or on different days. Fraud depends on speed, and a pause between the change and the payment is a cheap defence.
If you genuinely work alone, the rule becomes a pause instead of a second person: never pay changed bank details on the same day you receive them, and always call first. A night's delay and a phone call are enough to stop most of these frauds.
Put the rule in your contracts
Agree in writing, with each regular supplier, how bank detail changes will be communicated and verified.
At minimum, the agreement should say that bank details will never be changed by email alone, how a change will be communicated, and how it will be verified, for example by a callback to a named contact. Some businesses also require a change to arrive on signed letterhead in addition to the call.
This does three useful things. Both sides know the rule. A request that ignores it is immediately suspicious. And if a dispute ever arises about who should bear a loss, there is a written process to point to.
On liability generally: when a fraud starts in one party's compromised mailbox and the loss falls on the other, the question of who pays can become a dispute. We cannot give a general answer, because it depends on the facts and the contracts, and it is a question for a lawyer. The practical protection is agreeing the process before anything goes wrong.
Protecting your customers from fraud in your name
Fraudsters who get into your email will target your customers too, by sending them fake invoices with your bank details changed. You can make that much harder.
Tell customers, in advance and repeatedly, that your bank details will not change by email. The UK NCSC suggests telling customers that your bank details will not change at any point [11]. Put it on every invoice and in your email footer. Then, if a fraudster ever writes to your customers pretending to be you, they already know to phone you first.
Make your domain harder to impersonate. The NCSC recommends the email authentication controls known as SPF, DKIM and DMARC to make it harder for email from your domains to be spoofed [11]. Our guide on email authentication explains what each does and how to set them up.
Secure the mailboxes themselves. Turn on multi-factor authentication for every mailbox, starting with finance and management. The UK fraud reporting service recommends two-factor authentication on email accounts and financial systems [9], and the UAE Cyber Security Council has advised enabling multi-factor authentication when warning about phishing [8].
Check for forwarding rules. Periodically review mailboxes, especially finance mailboxes, for forwarding rules and filters nobody created. Attackers use them to keep reading after a password is changed.
Reduce what fraudsters can learn. The UK fraud reporting service notes that criminals use social media to research staff and decision-makers [9]. Knowing who approves payments and who is travelling this week helps a fraudster time and word a request. That does not mean hiding your team. It means thinking about what your public profiles reveal about how payments work.
Instant payments and the speed problem
Instant payments are convenient for business and unforgiving of mistakes, because there is very little time to catch a wrong payment before it lands.
Aani, the UAE's instant payments platform, was launched in 2023 by Al Etihad Payments, a subsidiary of the Central Bank of the UAE, allowing payments to be processed instantly around the clock [13]. The operator states that payments take less than ten seconds, with a maximum of AED 50,000 per transaction, and that Aani is for domestic transfers [14].
The operator's own guidance reminds users to make sure they are initiating payments to the right beneficiaries, and to report immediately to their bank if they believe a payment was made without authorisation [15].
Two things we could not confirm, and so will not claim: we found no official source saying Aani shows the recipient's name before you confirm a payment, and no official source describing whether an Aani payment can be recalled. Some countries run account-name checks on payments; the UK, for example, has a service called Confirmation of Payee [16]. Do not assume an equivalent protects you here. Ask your bank what checks it applies.
The practical conclusion is simple. The faster the payment, the more the verification has to happen before you press send, because there may be no opportunity afterwards.
If you have already paid: the first hour
Call your bank's fraud line immediately and ask it to stop or recall the payment; everything else comes second. The FBI states that time is of the essence and advises contacting your financial institution immediately to request a recall of the funds [4]. The UK NCSC advises contacting your bank directly using its official website or phone number [17].
In order:
1. Call your bank. Use the number on its official website or your card, not any number in the fraudulent email. Explain that you have been the victim of payment fraud, give the payment details, and ask for the payment to be stopped or recalled. Ask what else they need from you.
2. Report to the police. The UAE government portal lists the Ministry of Interior's eCrimes platform, the Dubai Police eCrime service, the Abu Dhabi Police Aman service, and the Federal Public Prosecution's My Safe Society app, along with local police stations and 999 [18]. Dubai Police's eCrime service lists the business sector among its users, is free, and has a 901 call centre, for incidents within Dubai [19]. Abu Dhabi's Aman service lists 8002626 and SMS 2828 [7]. The Central Bank of the UAE also advises reporting fraud to your local law enforcement authority [20].
3. Preserve the evidence. Keep the emails, including full headers if your IT support can export them, the invoices and the payment records. Do not edit or delete anything.
4. Check your own mailbox. If the fraud came through your email or used information only your email held, assume your mailbox may be compromised. Change the password, turn on multi-factor authentication, sign out all sessions and check for forwarding rules. Our guide on what to do if you have been hacked covers this in more detail.
5. Warn the real supplier by phone. Their email may be compromised, in which case other customers are at risk too.
6. Notify your insurer, if you have a policy that might cover it.
How much difference speed makes: the FBI reports that in 2025, through its fast-track process for US-reported cases, it froze about 679 million US dollars of 1.16 billion dollars in attempted theft, a 58 per cent success rate [4]. That is a US process and not a UAE recovery rate, but it shows that fast action can work. The money is moved on quickly, and every hour reduces the chance.
Will you get the money back?
Sometimes, if you act very quickly, but you should not assume it.
We did not find an official UAE source describing a recall process for domestic bank transfers or instant payments, or setting out recovery rates. SWIFT offers banks a stop and recall service for international payments still in flight [21], which is one reason speed matters for international transfers too.
On refunds: do not assume your bank will reimburse you. A payment you authorised, even one you were tricked into making, may be treated differently from a payment somebody made without your permission. Ask your bank whether any reimbursement rules cover business accounts, and do not assume they do.
Beware the second fraud. People who have just lost money are targeted again, by callers claiming they can recover it for a fee or in exchange for details. The UK fraud reporting service warns to hang up on anybody who claims they can get your money back [2]. Deal only with your bank and the police, using contact details you find yourself.
After an incident: fix the route in
Once the immediate response is done, find out exactly how the fraud got in and close that route.
Was a mailbox compromised, and whose? Was a lookalike domain used? Was the callback skipped, or made to a number from the email? Was the second approval rubber-stamped?
Each answer points to a specific control to tighten. Then brief everybody who handles payments on what happened, without naming or blaming the person who made the payment. People who fear punishment delay reporting, and delay is what turns a recoverable loss into a permanent one.
Europol advises contacting the police about fraud attempts even when no money was lost [3]. Reporting near misses helps authorities build a picture and warn others.
Training the people who pay
Train everybody who can pay, approve payments or change payment details, and train them on your process, not just on spotting suspicious emails.
That means finance and accounts payable, payroll, executive assistants, and senior managers. The UK NCSC recommends making sure staff are familiar with the normal ways of working for key tasks, such as how payments are made [11]. When everybody knows the normal process, anything different stands out.
The single sentence worth everybody remembering: never act on changed bank details, or an urgent payment request, without first calling a number you already had.
Our guide on phishing awareness training covers building this into a wider programme, and our guide on cybersecurity for small businesses covers the surrounding baseline.
What it costs to put controls in place
A review of your payment verification process, covering who can change bank details, how changes are verified and how your systems enforce it, starts from around AED 2,500 with us. Setting up email authentication with SPF, DKIM and DMARC starts from around AED 1,500. An awareness programme for a small team starts from around AED 3,000 a year. No official body publishes rates for this work, so these are our own figures. Final pricing depends on scope.
Or start this week, for nothing:
- Write down the callback rule and give it to everybody who can pay or change payment details.
- Require a second approver for any bank detail change.
- Print a contact list for your main suppliers, with the names of the people who can confirm payment changes.
- Add a line to your invoices telling customers your bank details will not change by email.
- Turn on multi-factor authentication for every finance and management mailbox.
That is an afternoon of work, and it closes the route through which some of the most expensive fraud in the world is committed.
References
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report, Appendix B
- UK Report Fraud, mandate fraud
- Europol, CEO/BEC fraud
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- FBI Internet Crime Complaint Center, Business Email Compromise: The $55 Billion Scam
- Dubai Government Media Office, Dubai Police operation Fox Hunt 2
- Abu Dhabi Police, Aman service, latest scams
- WAM, UAE Cyber Security Council: 75% of cyberattacks start with phishing
- UK Report Fraud, payment diversion fraud
- FBI Internet Crime Complaint Center, business email compromise
- UK National Cyber Security Centre, phishing attacks: defending your organisation
- CISA, business email compromise continues to swindle and defraud US businesses
- Central Bank of the UAE, Al Etihad Payments launches Aani
- Al Etihad Payments, about Aani
- Al Etihad Payments, Aani help
- Pay.UK, Confirmation of Payee
- UK National Cyber Security Centre, business payment fraud
- The Official Portal of the UAE Government, cyber safety and digital security
- Dubai Police, eCrime service
- Central Bank of the UAE, fraudulent reporting
- Swift, Swift GPI
- SKIMBOX, procurement software in the UAE
- SKIMBOX, email deliverability, SPF, DKIM and DMARC
- SKIMBOX, security awareness training and phishing
This article summarises published guidance from government and law enforcement bodies and is not legal or financial advice. Loss figures are from US reporting and are not UAE statistics. Ask your bank what verification and recall options apply to your account.



