Infrastructure
Invoice Redirection Fraud: Your Customer Paid, and You Never Got the Money

A commercial scaffolding hire firm in Longford issued the biggest invoice of its year and then heard nothing for three weeks. When the owner finally rang to chase it, the customer was baffled. They had paid it. They had the bank confirmation. They had even emailed back to confirm the new account details first, and someone at the scaffolding firm had replied to thank them for updating the records.
Nobody at the scaffolding firm had written that reply.
That is a composite, built from the pattern fraud awareness bodies here describe over and over. The sector changes. The county changes. The shape almost never does. Someone gets into an email conversation between a supplier and their customer, changes the bank details on an invoice, and the money lands in an account that belongs to neither of them.
Most coverage of this fraud is written for the business that pays. Almost none of it is written for the business that was supposed to be paid. That is the one I want to talk about, because if your firm invoices anyone by bank transfer, you are the supplier in somebody else's version of this story.
The scale of it, with the caveat attached
FraudSMART, the fraud awareness initiative run by Banking and Payments Federation Ireland, published figures on 27 March 2026 putting losses to Irish small and medium businesses from email-related scams at close to €19 million over two years, with an average loss north of €22,000 per affected firm [1]. Two thirds of the businesses surveyed said they had been targeted in the previous twelve months. Around half had no fraud awareness guidelines or training of any kind.
Now the caveat, because I would want one if I were reading this. That survey ran across 65 ISME members in February and March 2026. Sixty-five is a small sample, and a survey of business owners who agreed to answer questions about fraud is not a random slice of the economy. Treat the percentages as a direction of travel rather than a measurement. The euro figure comes from bank-reported losses, which is firmer ground, and even that only counts what got reported.
Niamh Davenport, who heads financial crime at BPFI, was direct about where these cases start. The majority, she said, are invoice-redirection scams that begin with "what appears to be, a legitimate email from a supplier known to the business, but which has been hacked or closely copied by fraudsters" [1].
Read that again from the supplier's side. Hacked or closely copied. Somebody's mailbox. Possibly yours.
What the criminal does first, and it is not what you would guess
There is a good piece of legal analysis from RDJ, the Irish law firm, published in October 2025, which sets out the mechanics from the inside of an actual incident response [2]. Reading it again during a morning operations review, the detail that stops me every time is the order of operations.
When somebody gains access to a business email environment, the first thing they go after is not the money that business owes to others. It is the money owed to that business. They read the sent folder, find the customers with open invoices, and write to them from inside a genuine thread asking for the account details to be updated. Only afterwards do they look at outgoing payments.
They also set up mailbox rules that quietly divert replies from those specific customers away from your inbox, so the conversation continues without you ever seeing a line of it. RDJ's authors make the point plainly: apart from watching for triggers like a request to change bank details, a sudden urgency, or a change in writing style, "there is no easy way for a recipient to identify that the email has not been prepared and sent by the legitimate individual or organisation" [2].
The other route needs no hacking at all. The criminal registers a domain that looks like yours, swapping .ie for .com or adding a letter, and runs the same conversation from an address that survives a quick glance. The website version of that trick is a known problem. The email variant is the same con with less effort and no site to build.
Three weeks of nothing
The delay is the cruellest part of the design.
Your customer believes the invoice is settled, so they stop thinking about it. You are waiting on payment, which is entirely normal, so you wait. Nobody in either building has a reason to raise an alarm. RDJ note that the victim usually finds out only when a reminder invoice arrives weeks later, and by then the funds have been moved through a chain of accounts and are effectively gone.
Twenty-one days of silence is enough time for a fraudster to launder a payment, close the account, and start on your next customer using the same thread. The fraud is over long before either of you knows it began. That is the whole business model.

The uncomfortable question: who is actually out of pocket?
Here comes the part nobody wants to be the first to raise on the phone.
Your customer has paid money to a criminal. You have not been paid. Legally, is the debt discharged?
On the weight of authority elsewhere, no. Payment to an account that was never yours does not settle what is owed to you. The RDJ analysis walks through it: no Irish court has ruled on the point yet, so we are reading across from other common law jurisdictions [2]. In the English case of J Brazil Road Contractors v Belectric Solar Ltd, a contractor's email was compromised and the customer paid a fraudulent account. The court held that although both parties were victims of a scam, the customer remained liable to pay the invoice again.
A 2019 Canadian decision, St. Lawrence Testing and Inspection Co. Ltd v Lanark Leeds Distribution Ltd, went further and set out a test. Where a fraudster takes over Victim A's email account and instructs Victim B to pay a different account, Victim A is not liable for the loss unless one of three things is true: a contract between them entitled Victim B to rely on emailed payment instructions and shifted the risk, there was wilful misconduct or dishonesty by Victim A, or there was negligence by Victim A. The court examined how the compromised firm had secured its email and how fast it acted once it knew, found nothing wanting, and the defendant paid again.
The direction of travel got firmer this year. On 29 April 2026 the Court of Appeal of England and Wales decided Logix Aero Ireland Ltd v Siam Aero Repair Company Ltd, where fraudsters sat inside an email negotiation between a buyer and a seller and redirected roughly 824,900 US dollars. The buyer sued the seller. The appeal was dismissed, the court holding that even if the seller had breached a confidentiality clause, "any such breach did not cause Logix's loss", and that the seller's conduct "provided the opportunity for the loss rather than its cause" [3].
Two things follow, and they pull against each other.
The first is reassurance. If your mailbox is breached and your customer pays a fraudster, the prevailing view across comparable jurisdictions is that they still owe you. The second is the condition attached to it. Negligence by you reopens the whole question. Weak or absent multi-factor authentication, no training, a shared login on a shared laptop, a slow and disorganised response after you find out: every one of those is evidence somebody can point at. Your legal position is not a fixed asset. It is something your operational housekeeping either protects or erodes.
And a caveat I want stated clearly: these are English, Canadian and Australian decisions. They are persuasive in an Irish court, not binding. An Irish judgment could land differently. If real money is involved, this is a conversation with your solicitor, not with a blog.
The second bill: a compromised mailbox is a data breach
This is the part that catches people who thought they had contained the problem.
If an unauthorised person had access to a mailbox containing personal data, and business mailboxes almost always do, that is a personal data breach under GDPR, not merely a fraud. Article 33 requires notification to the Data Protection Commission within 72 hours of becoming aware, where the breach presents a risk to the people whose data was exposed. Where the risk to them is high, they have to be told too.
Not every incident meets that threshold, and I am not going to pretend otherwise. The duty is triggered by a risk assessment, and a genuinely empty mailbox with no personal data in it is a different case from one holding customer contact details, bank information and correspondence. But the assessment has to be made, documented, and made quickly. Guessing is not a defence, and neither is deciding after the fact that it probably was not that serious.
The Data Protection Commission published its final decision on an inquiry into the University of Limerick on 2 March 2026, with fines totalling €98,000 [4]. Six of the twelve breaches involved staff email accounts accessed through phishing. Among the findings: three notifications were not made without undue delay under Article 33(1). Late reporting was its own finding, separate from the security failings that let the attackers in.
A university is not a six-person trade firm, and the fine scale reflects that. The obligation, though, has no headcount threshold. The 72 hours starts when you become aware, and awareness is not something you can defer by not looking. For the wider picture on what Irish business sites get wrong here, our guide to GDPR failures on Irish business websites covers the ground.
The first hour after you find out
Speed is genuinely the variable that matters. An Garda Síochána's guidance is unambiguous that "fraudulent transactions of this nature can move very quickly and it is important that immediate efforts are made to stop the transactions being completed" [5]. Work the list in this order.
- Ring your bank, and have the customer ring theirs. The receiving bank can sometimes freeze what has not yet moved. Hours matter more than paperwork here, and the customer's bank is the one holding the recall lever.
- Report it to your local Garda station. Bring copies of the fraudulent emails including the full header information, and the account details that were used. Report attempts that failed as well: the Gardaí note that the bogus account is often being used for other incidents, and reporting it may prevent the next one.
- Lock the mailbox down before you investigate it. Reset the password, force a sign-out of every active session, and remove any forwarding or filing rules the intruder left behind. Rules left in place mean the intruder is still reading your post.
- Verify who else was contacted. Go through the sent folder and the deleted items for every customer who received a message you did not write. Ring each one on a number you already hold.
- Start the data protection clock deliberately. Note the date and time you became aware, assess whether personal data was exposed, and take advice on notification rather than defaulting to silence.
Then, and only then, deal with the invoice. The commercial conversation is easier when you can tell the customer exactly what happened, what you have already done, and who you have reported it to.
What actually reduces the odds
Nothing on this list is exotic. That is rather the point.
Multi-factor authentication on every mailbox is the single highest-value control, where your email provider supports it, and every mainstream one does. RDJ specifically identify weak or absent multi-factor authentication as a predominant cause [2].
A payment process that does not bend for urgency comes next. Any change to bank details gets verified by a phone call to a number you already had on file, never a number in the email itself. Fraudsters will happily answer a call to a number they supplied and confirm their own details. Write the rule down, apply it without exception, and make sure the newest person in the office knows it. RDJ describe criminals deliberately targeting staff within days of starting, before onboarding has caught up with them.
Tell your customers, in advance, what you will never do. A single line at the foot of every invoice saying your bank details do not change and any notice claiming otherwise should be verified by phone costs nothing and gives the person about to pay you a reason to pause.

Where your website does work that email cannot
Email is a channel anyone can imitate. Your website, on your own domain, is not.
That distinction is worth something practical. A customer who has been told their supplier changed banks needs somewhere to check that is not the email in front of them, and a payments or accounts page on your own site is exactly that. State plainly that your bank details are unchanged, that you will never notify a change by email, and give the phone number you want used for verification. When a fraudster is mid-conversation with your customer, the one thing they cannot edit is a page you control.
Verification of Payee gives them a second reference point at the moment of transfer, and we wrote about why real invoices now get flagged by the payer's bank when that came in.
Be clear about what a hosting platform can and cannot do here. Web60 does not run your mailbox, and no website product does the work your email provider should be doing. What it does provide is the trustworthy half of the pair: a site on your own domain, on Irish-hosted infrastructure with SSL, nightly backups and server-level hardening included, which is the reference point your customers check when something in their inbox looks off. If you want the wider operational picture, our WordPress security and backup guide for Irish websites is the fuller treatment.
Sync reality check, because this one matters. A page stating your bank details never change does nothing unless somebody looks at it. Verification of Payee has a gap too: business payers can opt out of the scheme, and a "close match" warning is easy to click past when you are in a hurry. These controls reduce the odds. They do not close the door.
When this genuinely is not your problem
If your business takes card at the till or through a checkout and never issues an invoice payable by bank transfer, this fraud barely touches you. No transfer to redirect, no account details to change. Read the data protection part, keep multi-factor authentication switched on, and get on with your day.
And a fair concession on the other end of the scale. If you are running a finance function of fifteen people inside a corporate email tenancy with conditional access policies, device compliance rules and a security operations retainer, a dedicated IT security provider handles this class of risk better than any hosting platform will, and you should be paying one. That is a different business from the firm with four people, one shared laptop and a mailbox on a plan somebody set up years ago. Most trading businesses in this country are the second one.
Conclusion
The thing that decides how this ends is not clever technology. It is whether a payment instruction that arrives by email is allowed to change where money goes without a human being picking up the phone.
Two habits do most of the work. Multi-factor authentication on every mailbox, and a verification call to a number you already had, every single time, no exceptions for urgency. Tell your customers both of those things so they know what a real message from you looks like.
If it does happen, you are very probably still owed the money. Whether you can hold that position depends on what you can show about how you secured the account and how fast you moved once you knew. Both of those are decided long before the phone call.
Frequently Asked Questions
If my customer paid a fraudster, do they still owe me the money?
Very probably, yes, though no Irish court has ruled on the point. In comparable common law cases, including the English decision in J Brazil Road Contractors v Belectric Solar Ltd, the paying party remained liable to pay the legitimate supplier again. That protection can be lost if there is evidence of negligence on your side, such as no multi-factor authentication or a slow response after discovery, or if your contract terms entitled the customer to rely on emailed payment instructions. Take legal advice before you rely on it.
Do I have to report a hacked email account to the Data Protection Commission?
If the mailbox contained personal data and the breach presents a risk to the people concerned, yes, within 72 hours of becoming aware. Business mailboxes almost always contain personal data. Not every incident crosses the threshold, but the assessment has to be made and documented promptly. The DPC's 2 March 2026 decision on the University of Limerick found late notification to be a breach in its own right, separate from the security failings behind it.
How do I verify a request to change bank details?
Phone the business on a number you already held before the request arrived, from your own records or their website, and speak to a named person. Never use a number in the email or its signature. Criminals answer those calls and confirm their own details. Apply the rule to every request, including ones that look routine.
Should I put my bank details on my website?
Publishing them is optional, but publishing your policy is worth doing either way. A short statement that your bank details do not change, that you will never notify a change by email, and a phone number for verification gives a customer somewhere independent to check. Your own domain is a channel a fraudster cannot edit mid-conversation.
Does Verification of Payee stop invoice redirection fraud?
It helps and it does not solve it. Since October 2025 payment service providers must offer a free check that the account name matches the IBAN before a transfer is authorised, so a mismatch surfaces a warning. Business payers can opt out of the scheme, though, and a warning that appears while somebody is rushing is easy to dismiss. Treat it as one layer, not the answer.
How quickly do I need to act to have any chance of recovering the funds?
Immediately. An Garda Síochána warn that these transactions move very quickly and that immediate efforts are needed to stop them completing. Ring your own bank, get the customer to ring theirs, and report it to your local Garda station the same day. Report failed attempts too, since the same account is usually being used against other businesses.
Sources
Ian oversees Web60's hosting infrastructure and operations. Responsible for the uptime, security, and performance of every site on the platform, he writes about the operational reality of keeping Irish business websites fast, secure, and online around the clock.
More by Ian O'Reilly →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
The Website Succession Plan Your Business Does Not Have
Six weeks in hospital and nobody could log into the website. The business website succession plan most Irish owner-run firms have never written down.
Somebody in Your Business Is Pasting Customer Data Into ChatGPT
Using ChatGPT with customer data makes your business the data controller, not the AI company. What the Irish DPC expects, and a four-step fix for staff AI use.
