The email is polite, correctly formatted, and addressed to the right person. It's from a supplier you actually use — the logo is right, the account number is right, the sender's name matches the rep you've talked to. The message: we've changed banks; please update our payment details before settling the attached invoice. The invoice is real, or close enough to real that nobody would squint at it. The bank account is the only lie in the entire email, and it's the only detail nobody verifies.

This is payment-diversion fraud — business email compromise, in the FBI's ledger — and it is not a big-company problem. It's a multi-billion-dollar-a-year category, and small businesses are its preferred target for a structural reason: the same person who reads the email can often send the wire. No approval chain, no second signature, no treasury department — the entire control environment is one busy human's attention span on a Tuesday afternoon. The criminals know this. Their emails are timed for month-end, invoice-shaped, and urgent in the specific way that discourages a phone call.

Why spotting fakes is the wrong plan

The standard advice — train everyone to spot suspicious emails — quietly fails against this attack, because the better the fraud, the fewer signals it emits. Sometimes the email isn't even fake: when a vendor's real mailbox is compromised, the fraudulent payment-change request arrives from the genuine address, mid-thread, quoting your actual correspondence. No misspelling, no odd domain, no urgency theater. A detection strategy asks your least-technical employee to out-analyze a professional whose full-time job is being undetectable. You will lose that contest eventually, and it only takes once — wires don't come back.

The plan that works doesn't depend on detection at all. It's a rule: certain requests are never actionable by email, no matter how legitimate the email looks. The email's job is to be information. The verification's job is to be the decision.

The callback rule

Here is the entire control, and it fits on an index card taped to the monitor of anyone who pays invoices:

That's it. No software, no training curriculum, no judgment calls about whether this particular email seems off. The rule's power is precisely that it ignores how the email seems — the $200 invoice and the $42,000 one, the clumsy fake and the perfect one, all route through the same thirty-second call.

Make the rule survive contact with a busy office

A rule that lives in one person's head is a rule that leaves on their vacation, so give it the two supports every durable control needs. Write it down and post it where payments happen — the index-card version above, verbatim, plus one line for scope: this applies to everyone, including requests that appear to come from the owner. That last clause matters, because the other flavor of this fraud is the fake internal email — "it's Tom, I'm in a meeting, wire this now, don't call" — and the employees most vulnerable to it are the conscientious ones who don't want to bother the boss. Say the sentence out loud to the team: anyone here who delays a payment to verify it will be thanked, every time, even when the request was real and even when it was mine. The fraud's main weapon is the victim's fear of being slow or annoying; that sentence disarms it.

Second, pre-collect the callback numbers. The rule fails quietly if, at the moment of verification, nobody has a known-good number and the path of least resistance is the one in the email signature. When a vendor is onboarded — or this week, for the vendors you already have — capture the phone number for payment questions in your vendor record. Ten vendors, twenty minutes, done. Now the rule costs almost nothing to follow, which is the property that determines whether rules get followed.

If money already moved

Speed is the only variable that matters. Call your bank immediately and ask for a recall on the wire and their fraud team — recalls succeed sometimes in the first hours and almost never after a few days, because the receiving account drains fast. File at ic3.gov, the FBI's complaint center, the same day; their recovery asset team has clawed funds back, but every metric they publish says the same thing: the window is measured in hours. Then call the real vendor — if their mailbox was compromised, other customers of theirs are receiving the same email this week, and you may be the one who ends the campaign.

The bottom line

You cannot train a front desk to out-spot professional fraud, and you don't need to. Payment-diversion attacks — however sophisticated their emails — all share one chokepoint: the money only moves if nobody makes a thirty-second phone call to a number the fraudster doesn't control. Put the callback rule on paper, scope it to everyone including you, pre-load the numbers, and thank people for using it. It's the highest return-on-effort control in small-business finance: one index card, versus the invoice that almost cost you $4,200 — or the one next year that would try for ten times that.

— Tom

Put the controls on rails

The ByDesign platforms wire routines like the callback rule into how your team already works — documented, assigned, and audit-ready — without adding headcount to run them.

See the suite →

About the author

Tom Christian is the founder of TranscendByDesign, an AI-native operations suite built for SMBs and lean teams.

He built four production AI SaaS products from zero as a solo founder. Twenty years of practitioner work in CX, L&D, and operations at Guardian Life, Horizon Blue Cross Blue Shield, ConnectiveRx, LiveProcess, and TMP Direct before that. He writes about AI-native architecture, the SMB software stack, build vs buy decisions, and the operating discipline of solo founders shipping at scale.