Skip to main content
CentraPoint

Invoice fraud and banking detail scams: how to protect your customers

How invoice fraud and 'change of banking details' scams work in South Africa, the warning signs, and practical steps that stop customers paying a fraudster instead of you.

Published
Reading time
6 min read
By
CentraPoint Team
On this page
  1. How banking detail scams work
  2. Warning signs to teach your customers
  3. What you can do to protect your customers
  4. If it happens: a response plan
  5. A quick checklist
  6. How CentraPoint helps
  7. Frequently asked questions

Invoice fraud in South Africa usually looks ordinary. A customer receives an email that appears to come from you, with your logo and an invoice number they recognise, saying your banking details have changed. They update their records and pay. The money goes to a fraudster's account, you never receive it, and both of you are left arguing about who should carry the loss.

These "change of banking details" scams, a form of business email compromise, work because they exploit trust between businesses that already deal with each other. This guide explains how they happen, the warning signs, and the steps that make your business a much harder target.

How banking detail scams work

There are a few common patterns:

  1. A compromised mailbox. A fraudster gets into an email account at your business (often through a phishing link or a reused password), watches real conversations, and sends a genuine-looking message from the real address at the right moment.
  2. A spoofed or look-alike domain. The email comes from an address that looks like yours, for example with one letter changed or a different ending, or it fakes your address outright where the domain isn't protected.
  3. An intercepted invoice. A real invoice is altered, often only the bank details on the PDF, and sent on.
  4. A compromised customer mailbox. The fraudster is inside your customer's email instead, and intercepts your invoice there.

In each case the invoice, amount and reference are believable. Only the account number changes.

Warning signs to teach your customers

  • A request to pay into a new or different account, especially with urgency ("our old account is being audited").
  • Bank details that are in another name or at a different bank from usual.
  • An email address that is slightly different from yours, or a reply-to that points elsewhere.
  • Requests to keep the change confidential or not to call.
  • PDF invoices that look slightly different from your usual format.
  • A request that arrives just before a large payment is due.

What you can do to protect your customers

1. Say clearly that your bank details won't change by email

Put a short statement on every invoice and in your email signature: "We will never change our banking details by email. If you receive such a request, call us on our published number before paying." It costs nothing and it is one of the most effective defences.

2. Protect your email accounts

  • Turn on multi-factor authentication for every mailbox, starting with finance and directors.
  • Use unique, strong passwords and remove access for people who have left.
  • Watch for mailbox rules you didn't create, such as rules that forward or hide emails. Fraudsters use them to stay hidden.

3. Protect your domain

Publish SPF, DKIM and DMARC records for your domain so receiving servers can reject emails that pretend to come from you. Our guide to invoice emails going to spam explains these records and how to introduce DMARC safely. Consider registering obvious look-alike domains of your own name.

4. Give customers a way to pay that doesn't depend on bank details

The scam works by changing the account number on an invoice. A secure online payment option on every invoice means customers can pay by card or instant EFT through a hosted payment page, without ever typing in an account number. Payment links are an easy way to add this.

5. Let customers check invoices at the source

A customer portal where customers sign in to see their genuine invoices and balances gives them an independent way to verify an email. If an invoice isn't in the portal, it isn't yours. See what to include in a self-service billing portal.

6. Keep invoices and references consistent

Use one invoice format, one numbering sequence and a unique payment reference per invoice. Inconsistent documents make fake ones harder to spot. Our guide to payment references helps here.

7. Verify any change to your own suppliers' details

The same scam targets your accounts payable. Before you change a supplier's bank details, phone them on a number you already had, not one in the email. Many banks offer business clients a way to check that an account number belongs to the expected account holder before paying; ask yours.

If it happens: a response plan

Speed matters, because the chance of stopping or recovering a payment drops quickly.

  1. Contact your bank and your customer's bank immediately with the payment details, and ask them to try to stop or recall the payment.
  2. Report the crime to the South African Police Service and keep the case number.
  3. Secure the compromised mailbox: reset passwords, end active sessions, review mailbox rules and turn on multi-factor authentication.
  4. Warn other customers who may have received similar messages.
  5. Consider POPIA. If personal information was accessed through a compromised account, you may need to notify the Information Regulator and the people affected. See our POPIA guide for payment data and take advice.
  6. Keep records of emails, headers, payment details and every action taken.

Who carries the loss in these cases depends on the facts and can take a long time to resolve, which is why prevention is far cheaper than recovery. Take legal advice for your own situation.

A quick checklist

  • "We never change bank details by email" on every invoice and signature
  • Multi-factor authentication on all mailboxes
  • SPF, DKIM and DMARC published for your domain
  • A secure online payment option on every invoice
  • A customer portal or another way to verify genuine invoices
  • A phone-back rule for any bank detail change, in both directions
  • A written response plan your team knows about

How CentraPoint helps

Every CentraPoint invoice includes a pay-by-link, so customers can pay by card, instant EFT or another enabled method on a hosted payment page without typing in your bank details. Links are signed, so the amount and reference can't be altered. Where customers do pay by bank transfer, CentraPoint's EFT payer page shows the bank details from your own settings and a unique deposit reference for that order.

The customer self-service portal lets customers sign in with a one-time code sent to the email address on their account and see their genuine invoices and balances. Customer emails are sent either by CentraPoint, under your company name with authentication handled for you, or by your own mail server. On your side, two-factor authentication protects every team sign-in, and on plans that include it, the audit log shows who changed what and when. See security at CentraPoint.

Frequently asked questions

What is a change of banking details scam?

A fraudster pretends to be a supplier and tells a customer that the supplier's bank account has changed, so the customer pays the fraudster instead. It often starts with a hacked or spoofed email account.

How can my customers verify that an invoice is genuine?

Ask them to phone you on a number they already have, or to check the invoice in your customer portal. Never rely on contact details in the suspicious email itself.

It removes the step fraudsters usually change, the bank account number. Customers should still check that the payment page shows your business name and comes from a source they trust.

Who is liable if a customer pays a fraudster?

It depends on the circumstances and agreements involved, and these disputes can be complex. Prevention is the best protection; take legal advice if it happens.

  • #invoice fraud
  • #business email compromise
  • #security
  • #eft