Retail Ripon, North Yorkshire 90 employees, 6 stores Deployed in 5 days; fraud attempt blocked in month 2

North Yorkshire retailer stops a £48,000 invoice fraud attempt

A 90-staff North Yorkshire retailer deployed AI email security in five days and blocked a £48,000 invoice fraud attempt in month two, with 31 business email compromise attempts flagged and no fraudulent payments made in 12 months.

A supplier's mailbox was compromised and used to send a genuine-looking bank detail change against a real, outstanding £48,000 invoice. The message came from the supplier's actual domain and referenced a real purchase order.

Client: 90-staff independent retail group. Name withheld under our confidentiality terms.

At a glance

Client
90-staff independent retail group
Sector
Retail
Location
Ripon, North Yorkshire
Size
90 employees, 6 stores
Services
Email Security, Phishing Simulation, Cyber Awareness Training
Timeline
Deployed in 5 days; fraud attempt blocked in month 2
Headline result
£48,000 — Single fraudulent payment prevented

Measured results

Single fraudulent payment prevented
£48,000Single fraudulent payment prevented
From order to full deployment
5 daysFrom order to full deployment
Business Email Compromise attempts flagged in 12 months
31Business Email Compromise attempts flagged in 12 months
Fraudulent payments made since deployment
0Fraudulent payments made since deployment

The challenge

  • A previous near-miss had reached the point of payment approval before being caught by chance.
  • Supplier invoices arrived by email with no verification step for changed bank details.
  • The finance team of three processed high invoice volumes under month-end pressure.
  • Standard filtering could not flag mail sent from a legitimate, compromised supplier account.

What we did

  1. 1

    Deployed AI email security in front of Microsoft 365, analysing sender behaviour and relationship history rather than reputation alone.

  2. 2

    Flagged first-time bank detail changes and unusual payment language with an inline warning banner visible to the recipient.

  3. 3

    Introduced a mandatory callback verification for any bank detail change, using a number already on file rather than one in the email.

  4. 4

    Ran targeted phishing simulations against the finance team using invoice-fraud scenarios.

  5. 5

    Enrolled all staff in monthly awareness training covering Business Email Compromise specifically.

  6. 6

    Set a two-person approval threshold for payments above an agreed value.

The outcome

  • The fraudulent bank detail change was flagged, verified by callback and rejected.
  • The supplier was alerted to their own mailbox compromise.
  • Callback verification is now standard for every bank detail change, regardless of source.
  • Finance staff receive scenario-based simulations rather than generic training.
It came from their real email address, about a real invoice we owed. Without the warning banner we would have paid it.
Finance Manager, retail group, North Yorkshire

The concepts behind this engagement

Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.

FAQ

Questions about this engagement

The questions businesses in a similar position ask most often before starting.

How can email security flag a message sent from a genuine supplier address?

+

By judging behaviour rather than identity. When a supplier mailbox is compromised, the sender, domain, SPF and DKIM are all legitimate, so reputation-based filtering has nothing to object to. What changes is the pattern: this contact has never previously requested a bank detail change, the phrasing differs from their normal correspondence, the reply-to address is subtly different, and the message arrives outside their usual sending hours. Behavioural analysis scores those anomalies together and surfaces an inline warning to the recipient rather than silently quarantining a message from a real business relationship.

Is a callback verification process really necessary if you have email security?

+

Yes, because the technical control reduces the probability of an attack reaching a person, and the process control decides what happens when one does. No filter catches everything, and Business Email Compromise is specifically designed to look legitimate. A callback to a number already held on file — never a number supplied in the email itself — defeats the entire attack class in about ninety seconds, regardless of how convincing the message was. The two controls work as a pair: the banner prompts the doubt, the callback resolves it, and the two-person approval threshold catches anything that slips past both.

What is the difference between phishing and Business Email Compromise?

+

Phishing casts widely and usually wants credentials, typically through a link to a fake login page. Business Email Compromise is targeted, patient and wants money moved. It often involves no link and no attachment at all, which is why attachment scanning and link rewriting do not stop it. The attacker studies a real supplier relationship, waits for a genuine outstanding invoice, and asks for the payment destination to change. Losses per incident are far higher than commodity phishing, and UK SMEs are targeted heavily because approval chains are short and finance teams are small.

Related case studies

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way