SCAM WARNING: Be alert to fraudulent communications that misuse the name of MYwealthRecovery.

Invoice Fraud and Business Email Compromise: How to Recover

A single altered bank detail can move a six-figure payment to a fraudster. These losses are recoverable more often than people assume — but only where the first 24 hours are handled correctly.

Last reviewed: August 2026

The first 24 hours

  • Phone the bank's fraud team and request an immediate recall
  • Ask the receiving bank, via yours, to freeze the account
  • Report to Action Fraud (UK), ReportCyber (AU) or PNP-ACG (PH)
  • Preserve email headers and server logs before anything is deleted
  • Notify cyber and crime insurers, and any professional involved in the payment
  • Force password resets and review mailbox forwarding rules across the business

Establish where the compromise happened

Either your mailbox, your supplier's, or an intermediary's was accessed, and the answer drives liability. Email headers usually reveal whether the fraudulent message originated externally, was sent from a lookalike domain, or came from a genuinely compromised account with forwarding rules set to hide replies. Get this analysed properly and early.

Who bears the loss

Where your systems were compromised and you paid without verification, the loss typically sits with you and the supplier remains unpaid. Where the supplier's systems were compromised, the position is arguable and often settles on shared terms. Where a solicitor, accountant or agent held funds or transmitted the details, a professional negligence claim against them and their insurers may recover the full sum.

The claim against the bank

Banks owe duties around monitoring and, in some circumstances, must pause payments that display clear indicators of fraud. Where an unusual, large payment to a brand-new payee passed without any intervention, that is worth examining — including through the ombudsman for smaller businesses that qualify.

Preventing the next one

  • Verify every change of bank details by phone on a previously known number
  • Enforce dual authorisation above a set payment threshold
  • Enable multi-factor authentication and monitor forwarding rules
  • Train finance staff on urgency and secrecy as the two core red flags

Free assessment

Send us the payment records, the email chain and details of anyone who handled the instruction. We will identify who is likely liable and which recovery routes remain open.

Common questions

We paid a supplier invoice that turned out to be fraudulent. Who is liable?

It depends on whose systems were compromised and who failed to verify. Liability may sit with the payer, the supplier, or be shared — and where a professional such as a solicitor or accountant handled the payment instruction, they may bear responsibility along with their insurers.

Can the bank recover the payment?

Sometimes, if reported fast. Banks can attempt recall while funds remain in the receiving account, and mule accounts are often emptied within hours. Report by phone the moment you suspect it, and follow up in writing the same day.

Does the invoice still have to be paid?

Frequently yes, which is what makes this fraud so damaging — the genuine supplier remains unpaid. Whether the debt survives depends on the contract terms, how the bank details were communicated, and each side's conduct.

Will insurance cover it?

Cyber and crime policies may respond, but wordings vary sharply and social-engineering losses are often carved out or sub-limited. Notify insurers immediately regardless — late notification is a common reason cover is declined.

Free, no-obligation case assessment

Tell us what happened and we will tell you honestly whether your loss is realistically recoverable. If it is not, we say so — there is no charge and no obligation to proceed.

Start your free assessment

Related guides