Stop Future BEC and Invoice Fraud

    Stop the same trick from working again on you or your team.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Stop the same trick from working again on you or your team.

    What to do

      • Adopt a written 'verify any change of bank details by phone' rule using a number from prior records, never the email
      • Enable authenticator-app 2FA and disable legacy auth / app passwords on the mailbox
      • Turn on DMARC / SPF / DKIM enforcement on your domain and ask suppliers to do the same
      • Use accounts-payable approval workflows that flag any change of supplier bank details
      • Run a phishing-awareness refresher with anyone who can authorise payments

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Financial Recovery