
Illustrative scenario · Business email compromise
A company pays a regular supplier’s invoice — to new bank details sent by email. Days later, the supplier asks why they haven’t been paid.
Illustrative scenario: a composite example of a common case type — not a real client, and no real outcome is implied.
The situation
In this scenario, a finance team receives an email from a long-standing supplier, inside an existing email thread, explaining that their bank details have changed. The invoice looks exactly like previous ones. The payment is made.
When the supplier chases the unpaid invoice, both companies realise something is wrong — and each suspects the other’s email was hacked.
The client contacts their bank immediately to request a recall, supported by a short evidence summary.
Original email files and headers are analysed to establish where the fraudulent message really came from.
Sign-in history, forwarding rules and permissions are reviewed for signs of compromise.
Practical controls are recommended: phone verification of bank-detail changes, MFA and monitoring for suspicious rules.

Confidential case review
Confidential case review
Your message is read by an investigator, not a sales team. We'll reply with an honest assessment of what can be done.
Have a question first? Read our FAQ →
Prefer email? info@gfirglobal.com