Hacked-Email Invoice Fraud: Protecting Your Money When Importing
Oct 01, 2025
Picture a scenario that plays out with Gulf importers every single week: you negotiate with your Chinese supplier for weeks, the final invoice arrives by email from the exact address you have been writing to for months, you wire fifty thousand dollars, and days later the supplier calls asking where the payment is. The bitter truth: the supplier's mailbox was compromised, and the fraudster watched the conversation patiently until payment time, then sent an invoice with different bank details. This scheme, known globally as business email compromise, costs companies billions of dollars a year, and an importer wiring money across continents is its ideal target.
How the Scam Works from the Inside
The attacker compromises the supplier's mailbox, or yours, through a leaked password or a phishing message, then does nothing but watch. He reads the negotiation, learns the deal value, the payment date and each side's writing style. At the decisive moment he steps in: a revised invoice with a new account, justified by a tax issue or a bank audit on the old account. Sometimes he registers a lookalike domain differing by a single character and quietly moves the conversation onto it. The message feels completely authentic because it is built on your real correspondence.
Red Flags That Must Stop Any Transfer
- A last-minute change of bank account before payment, however convincing the excuse.
- A beneficiary name that differs from the contracted supplier's company name, especially personal accounts or third-country accounts, often in Hong Kong, unconnected to the supplier.
- Unusual urgency or pressure to pay within hours.
- A subtly different email address or domain, such as a doubled letter or a different extension.
- Grammar slips or a sudden change in the familiar writing style of your sales contact.
- Requests to split the amount across several accounts or pay outside banking channels.
The Verification Protocol Before Every Transfer
Real protection is procedural more than technical. Adopt these rules as fixed company policy:
- Second-channel verification: any change in account details is confirmed by phone or video call with your known contact, using a number saved previously, never one provided in the suspicious email itself.
- Beneficiary name matching: transfer only to an account in the name of the contracted company as it appears on its business licence and your contract; any exception requires a signed and stamped official letter, independently confirmed.
- Bank details locked in the contract: record the account in the signed contract from day one, with an explicit clause that changes are valid only via an official letter confirmed by phone.
- Test transfer: on a first transaction or after any change, send a token amount and have the supplier confirm receipt before releasing the full payment.
- Four-eyes principle: every transfer above a threshold you define, say SAR 20,000, requires approval by two people in your company.
Harden Your Own Mailbox Too
The breach may be on your side rather than the supplier's, letting the fraudster send instructions to your suppliers in your name or intercept your invoices. Enable two-factor authentication on every mail account, use unique passwords, review your mailbox forwarding rules regularly since hidden forwarding is the first thing attackers plant, and train staff to recognise phishing.
Golden rule: email alone is never an acceptable source for bank account details or changes to them, no matter how genuine the message looks. Voice or video confirmation on a previously known number is the one defence a fraudster cannot compromise.
If the Money Has Already Gone
Speed is everything. Call your bank immediately and request a recall of the transfer; the first hours, before funds are drained from the receiving account, are your real window of hope. Report the incident to the Saudi authorities responsible for cybercrime through official channels, alert the supplier so they secure their mailbox and document the breach, and preserve every message and receipt as evidence. Then review your internal procedures and close the gap the fraud came through.
The Bottom Line
Invoice fraud does not only catch the careless; it hunts the busy and the confident. The companies that survive are not the most technical, but the ones that made verification a mandatory habit with no exceptions for anyone.
One reason traders work with Terrace International is that our field team in Guangzhou and Shenzhen verifies suppliers and their official corporate bank accounts face to face before any payment moves, and runs negotiation, inspection and shipping through a single trusted channel that shuts fraudsters out. Get in touch and transfer your money with confidence.