Skip to main content
Security Culture7 min read

Payment Fraud in 2026: How Small Businesses Actually Get Hit - and How to Stay Safe

"Invoice swaps, CEO impersonation, supplier email takeover. The five payment fraud patterns hitting SMBs in Israel and across Europe - and the controls that stop them."

Author

Lior Refael

Published

Jun 27, 2026

Back to Articles

Why payment fraud is the #1 financial risk for SMBs in 2026

The scale is documented rather than anecdotal. The FBI's Internet Crime Complaint Center recorded USD 20.877 billion in reported losses across 1,008,597 complaints in 2025, up 26% year on year, with business email compromise alone accounting for USD 3.04 billion at an average of over USD 122,000 per reported incident[1].

Cybercrime losses reported to the FBI's IC3, by year

USD billions reported lost

Reported losses tripled in four years. Business email compromise accounts for about USD 3 billion of the 2025 total - the category that hits small businesses hardest, because it needs no malware at all.

Show the data
Line chart of cybercrime losses reported to the FBI IC3: USD 6.9 billion in 2021, 10.3 billion in 2022, 12.5 billion in 2023, 16.6 billion in 2024 and 20.9 billion in 2025.
USD billions reported lostReported losses
2021$6.9B
2022$10.3B
2023$12.5B
2024$16.6B
2025$20.9B

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report (2026)

Ransomware gets the headlines. Payment fraud quietly takes more money out of small businesses every quarter - usually without anyone noticing for weeks.

The reason is simple: payment fraud doesn't need to break anything. No malware, no encrypted files, no ransom note. Someone just convinces your finance person to send money to the wrong bank account. By the time the real supplier asks where their payment is, the funds have already been moved through 3-4 mule accounts and are gone.

For a 5-50 person business, a single successful incident is typically €8,000-€120,000. In the cases we have been called into, recovery through cyber insurance on social-engineering wire fraud lands well below half the loss - these are policy-dependent and not a published rate, so treat them as our experience rather than a benchmark.

The 5 patterns we actually see

1. Supplier email takeover (the most common)

An attacker compromises *your supplier's* mailbox - not yours. They sit quietly, read months of email, and learn the relationship: how invoices look, what amounts are normal, who approves what.

Then they wait for a real invoice to go out, intercept it, and resend the same PDF with one change: the IBAN. The email comes from the real supplier address. The signature, formatting, and PDF template are identical. Only the bank account is different.

> Red flag: A long-standing supplier sends you "updated bank details" by email - especially close to an existing invoice due date. The FBI's own guidance on this pattern is to verify through a channel and a number you already had, never one supplied in the request[2].

#### What this looks like in practice (anonymised, from a case we handled)

A 14-person design studio in central Europe had worked with the same print supplier for six years. In March the supplier's mailbox was compromised through a phished webmail password. The attacker read the thread quietly for five weeks.

When the studio's producer emailed to approve a €18,400 print run, the attacker replied *from the supplier's real address*, on the real thread, with the real invoice PDF - re-issued with a new IBAN and a one-line note: "we've moved banks this quarter, please use the details on the attached." No spoofed domain, no typos, no urgency. The studio paid the same day.

The fraud surfaced 19 days later when the supplier chased the invoice. €18,400 had already been split across three accounts. €2,900 was recovered. A single 40-second phone call to the supplier's known number would have stopped it - which is exactly why the UK's NCSC puts out-of-band verification of any bank-detail change at the centre of its business payment fraud guidance[3].

2. CEO / founder impersonation

A finance employee gets a message - email, WhatsApp, sometimes SMS - that looks like it's from the founder: *"I'm in a meeting, need you to push through an urgent transfer to this account today, will explain later."*

The domain is usually a lookalike (techsuit.io → techsuit-io.com, or techsuıt.io with a Turkish dotless ı). On WhatsApp, the profile photo is the real founder pulled from LinkedIn.

> Red flag: Urgency + secrecy + a payment request that bypasses normal approval flow. Always.

3. Invoice manipulation inside your own mailbox

The attacker compromises *your* mailbox first - usually through a phished Microsoft 365 password with no MFA. Once inside, they set up a mailbox rule that auto-forwards or deletes any email containing words like "invoice", "payment", "bank", or "IBAN".

Then they impersonate your finance team to your customers, and your customers to your finance team. Money flows out before anyone realises both sides are talking to a stranger.

4. Payroll redirect

Around payroll dates, HR receives an email from "an employee" requesting that their salary be paid to a new account. It's plausible - people switch banks. The change goes through, and one employee's monthly salary lands in a fraudulent account.

Small loss per incident, but trivially easy to execute and often repeated month after month before being discovered.

5. Fake invoice / fake supplier

A finance inbox receives an invoice from a supplier that *looks plausible* - domain-matched email, professional PDF, reasonable amount. It might reference a real project or a generic line item like "consulting services" or "domain renewal".

If no one strictly checks supplier onboarding, the invoice gets paid. We've seen €400-€2,000 invoices clear without anyone noticing the supplier didn't exist.

Why small businesses are the preferred target

Three reasons:

  1. Fewer controls. No dual-approval on wires. No callback verification. Often one person handling both the email and the bank.
  2. Faster money movement. SMBs need to pay quickly to keep operations running. Fraud relies on that speed.
  3. Lower scrutiny per transaction. A €15,000 wire at a 25-person company is normal. The same wire at a Fortune 500 triggers automated review.

The controls that actually stop it

You don't need an enterprise security stack. You need 6 specific controls.

Control 1 - MFA on every mailbox (no exceptions)

The single highest-ROI security control for an SMB. Microsoft measured MFA cutting the risk of account compromise by 99.22%, and by 98.56% even where the password had already leaked[4] - and a compromised mailbox is how the invoice-manipulation pattern above starts. Microsoft 365 Conditional Access can enforce this for every user in one policy.

Control 2 - Mailbox rule auditing

Most BEC attacks set up forwarding or deletion rules. Microsoft Defender for Office 365 alerts on any new external forwarding rule. Without this, you can be compromised for weeks and never know.

Control 3 - Out-of-band callback verification

A non-negotiable rule for finance: any bank detail change, or any new wire over a threshold (€2,000-€5,000), is verified by phone - using the phone number you already have on file, not one from the email.

Print this on a card. Put it on the finance person's monitor. It will stop more fraud than any software.

Control 4 - Dual approval for wires

Two people must approve any outbound payment above a threshold. Most banks (across Israel and the EU) support this natively in the business portal. Enable it.

Control 5 - Supplier onboarding checklist

New suppliers don't get paid until: (a) someone has spoken to them on the phone using a number from their official website, (b) bank details are received via that verified channel, (c) a manager has approved the supplier record.

Control 6 - Domain protection (SPF, DKIM, DMARC)

Properly configured DMARC at p=reject prevents attackers from sending email *as your domain* to your customers. Without it, your customers are an attack surface you don't control.

What to do in the first 60 minutes after a fraudulent transfer

Speed matters more than anything else.

  1. Call your bank's fraud line - not the branch. Request an immediate recall (in the EU, SEPA recall; in Israel, ask for "החזרת זיכוי דחופה"). Funds can sometimes be frozen if the receiving bank hasn't released them.
  2. File a police report immediately. Your bank often won't act on a recall request without one.
  3. Reset every password and revoke every active session on the compromised mailbox. Don't assume the attacker is gone.
  4. Notify your insurer. Most cyber policies have a 24-72 hour notification window.
  5. Check mailbox rules for forwarding and deletion - and audit the last 90 days of sent items.

The 30-minute mark is roughly when funds typically leave the first receiving account. Past that, recovery rates fall sharply.

The first hour after a fraudulent transfer

Minutes from discovery

Timeline of the first hour after a fraudulent transfer: bank recall within ten minutes, receiving bank by twenty, password reset and session revocation by thirty, mailbox rule check by forty, police and cybercrime report by fifty-five, insurer notification by sixty.

  1. Call your bank's fraud line and request a recall0-10 min

    The single action with the highest chance of getting the money back. Ask explicitly for a recall, not a note on the file.

  2. Call the receiving bank if you have the details10-20 min
  3. Reset the mailbox password and revoke active sessions20-30 min

    Assume the mailbox is still open to the attacker until sessions are killed.

  4. Check for and remove hidden mailbox forwarding rules30-40 min
  5. File the police and national cybercrime report40-55 min

    Required by most insurers, and the route through which cross-border recalls actually get actioned.

  6. Notify your insurer and brief the finance team55-60 min

Recall odds fall away by the hour, which is why this belongs in a written runbook the finance team can reach in thirty seconds - not in someone's judgement on the worst morning of their quarter.

TechSuit incident runbook, aligned to FBI IC3 guidance on recall requests for business email compromise.

What this costs to implement

For a 10-person business, the full stack - MFA, Defender for Office 365, mailbox rule alerting, DMARC, documented dual-approval and callback procedures - runs about €15-25/user/month on top of standard Microsoft 365 licensing.

A single prevented incident pays for the entire program for 5-10 years.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. 2025 Internet Crime Report (opens in a new tab)

    FBI Internet Crime Complaint Center (IC3) · 2026

    USD 20.877 billion in reported losses across 1,008,597 complaints in 2025; BEC losses of USD 3.04 billion; five-year loss trend.

  2. Business Email Compromise: The $55 Billion Scam (opens in a new tab)

    FBI Internet Crime Complaint Center (IC3) · 2024

    How BEC schemes are executed and the recommended response, including recall requests.

  3. Business payment fraud: guidance for organisations (opens in a new tab)

    UK National Cyber Security Centre · 2025

    National-authority guidance on invoice fraud and out-of-band verification of bank detail changes.

  4. How effective is multifactor authentication at deterring cyberattacks? (opens in a new tab)

    Microsoft · 2023

    MFA reduced compromise risk by 99.22%, and by 98.56% where the password had already leaked - the control that closes the compromised-mailbox route into payment fraud.

  5. Microsoft Digital Defense Report 2025 (opens in a new tab)

    Microsoft · Oct 2025

    Growth in AI-driven forgeries and deepfakes used to bypass verification checkpoints.

  6. Mail flow rules in Exchange Online (opens in a new tab)

    Microsoft Learn · 2026

    External-sender warnings and rules that flag lookalike domains before a person reads the message.

  7. Anti-phishing policies in Microsoft 365 (opens in a new tab)

    Microsoft Learn · 2026

    Impersonation protection for your own domain and named users, and where it has to be enabled explicitly.

  8. Payment fraud and cyber-enabled financial crime reporting (opens in a new tab)

    Europol · 2025

    European law-enforcement guidance on payment fraud patterns and reporting routes.

Figures last checked 28 July 2026

Worried your finance flow could be tricked?

Book a free 30-minute call. We'll walk through your current payment approval and supplier onboarding process, and tell you honestly where the gaps are - no pressure to hire us.