North Yorkshire retailer stops a £48,000 invoice fraud attempt
A 90-staff North Yorkshire retailer deployed AI email security in five days and blocked a £48,000 invoice fraud attempt in month two, with 31 business email compromise attempts flagged and no fraudulent payments made in 12 months.
A supplier's mailbox was compromised and used to send a genuine-looking bank detail change against a real, outstanding £48,000 invoice. The message came from the supplier's actual domain and referenced a real purchase order.
Client: 90-staff independent retail group. Name withheld under our confidentiality terms.
At a glance
- Client
- 90-staff independent retail group
- Sector
- Retail
- Location
- Ripon, North Yorkshire
- Size
- 90 employees, 6 stores
- Services
- Email Security, Phishing Simulation, Cyber Awareness Training
- Timeline
- Deployed in 5 days; fraud attempt blocked in month 2
- Headline result
- £48,000 — Single fraudulent payment prevented
Measured results
- Single fraudulent payment prevented
- £48,000Single fraudulent payment prevented
- From order to full deployment
- 5 daysFrom order to full deployment
- Business Email Compromise attempts flagged in 12 months
- 31Business Email Compromise attempts flagged in 12 months
- Fraudulent payments made since deployment
- 0Fraudulent payments made since deployment
The challenge
- A previous near-miss had reached the point of payment approval before being caught by chance.
- Supplier invoices arrived by email with no verification step for changed bank details.
- The finance team of three processed high invoice volumes under month-end pressure.
- Standard filtering could not flag mail sent from a legitimate, compromised supplier account.
What we did
- 1
Deployed AI email security in front of Microsoft 365, analysing sender behaviour and relationship history rather than reputation alone.
- 2
Flagged first-time bank detail changes and unusual payment language with an inline warning banner visible to the recipient.
- 3
Introduced a mandatory callback verification for any bank detail change, using a number already on file rather than one in the email.
- 4
Ran targeted phishing simulations against the finance team using invoice-fraud scenarios.
- 5
Enrolled all staff in monthly awareness training covering Business Email Compromise specifically.
- 6
Set a two-person approval threshold for payments above an agreed value.
The outcome
- The fraudulent bank detail change was flagged, verified by callback and rejected.
- The supplier was alerted to their own mailbox compromise.
- Callback verification is now standard for every bank detail change, regardless of source.
- Finance staff receive scenario-based simulations rather than generic training.
“It came from their real email address, about a real invoice we owed. Without the warning banner we would have paid it.”
The concepts behind this engagement
Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.
Where this fits in what Complete Cyber Security does
FAQ
Questions about this engagement
The questions businesses in a similar position ask most often before starting.
How can email security flag a message sent from a genuine supplier address?
+
By judging behaviour rather than identity. When a supplier mailbox is compromised, the sender, domain, SPF and DKIM are all legitimate, so reputation-based filtering has nothing to object to. What changes is the pattern: this contact has never previously requested a bank detail change, the phrasing differs from their normal correspondence, the reply-to address is subtly different, and the message arrives outside their usual sending hours. Behavioural analysis scores those anomalies together and surfaces an inline warning to the recipient rather than silently quarantining a message from a real business relationship.
Is a callback verification process really necessary if you have email security?
+
Yes, because the technical control reduces the probability of an attack reaching a person, and the process control decides what happens when one does. No filter catches everything, and Business Email Compromise is specifically designed to look legitimate. A callback to a number already held on file — never a number supplied in the email itself — defeats the entire attack class in about ninety seconds, regardless of how convincing the message was. The two controls work as a pair: the banner prompts the doubt, the callback resolves it, and the two-person approval threshold catches anything that slips past both.
What is the difference between phishing and Business Email Compromise?
+
Phishing casts widely and usually wants credentials, typically through a link to a fake login page. Business Email Compromise is targeted, patient and wants money moved. It often involves no link and no attachment at all, which is why attachment scanning and link rewriting do not stop it. The attacker studies a real supplier relationship, waits for a genuine outstanding invoice, and asks for the payment destination to change. Losses per incident are far higher than commodity phishing, and UK SMEs are targeted heavily because approval chains are short and finance teams are small.
Related case studies
Professional Services
Harrogate accountancy practice cuts phishing click rate from 31% to 4%
Read moreHealthcare
North Yorkshire care provider trains 120 staff on cyber awareness with 94% completion
Read moreEducation

