July 20, 2026

Imagine this. It's Tuesday morning. Your bookkeeper opens an email from a supplier you've used for years. The logo is right. The signature is right. Even the way they sign off, "Thanks so much!", is exactly how they always write.
The message says they've switched banks, and could you please use the new account details for the invoice due Friday.
So you do. Because why wouldn't you?
Two weeks later the real vendor calls asking where their money is. That's when your stomach drops. The payment went to a criminal's account, it was withdrawn within hours, and your bank tells you there's almost nothing they can do.
This scam is called Business Email Compromise, and the FBI consistently ranks it as one of the most expensive crimes hitting American businesses, costing victims billions of dollars every year. Not by hacking firewalls. By hacking trust.
Here's the Part Most Business Owners Get Wrong
When people hear "cybercrime," they picture someone breaking into THEIR computers. But in most of these cases, your systems are never touched.
Instead, the criminals compromise your VENDOR'S email account. Then they do something surprisingly patient: nothing. They sit and read. For weeks. They learn who invoices whom, for how much, and in what tone of voice. Then, at exactly the right moment, they slide into a real conversation with fake banking details.
That's why this scam works on smart, careful people. There's no misspelled email address to catch. No sketchy attachment. It's a real email thread with one poisoned detail.
Three Red Flags Hiding in Plain Sight
- A change to payment details, of any kind. New bank, new account number, "please pay by wire this time instead of check." This is the single biggest tell. Legitimate banking changes happen, but rarely, and never casually.
- Urgency plus secrecy. "This needs to go out today" or "the owner asked me to handle this quietly." Criminals manufacture time pressure because rushed people skip steps.
- A reply-to address that's slightly off. Sometimes the email comes from the vendor's real, compromised account, but sometimes it's a lookalike domain with one letter changed. Worth a glance, but don't rely on this alone.
The Call-Back Rule (Write This Down)
Here is the entire defense, in plain English, because protecting your money shouldn't require a computer science degree. No Geek-Speak, remember?
Any request to change how or where you send money gets verified by phone, at a number you already had on file BEFORE the request arrived.
Not the phone number in the email. Not the number in the signature block. Criminals control those. Use the number in your contacts, on an old invoice, or on the vendor's official website.
Give your bookkeeper this exact script: "Hi, this is [name] at [your company]. We received a request to update your banking details and we verify all payment changes by phone as a matter of policy. Can you confirm whether this request came from you?"
If the vendor says "what request?" then you just saved yourself a very bad month. And if a vendor ever gets annoyed that you verified? A good vendor never will. They'll thank you, because it's their reputation on the line too.
Make It a Policy, Not a Memory
The Call-Back Rule only works if it's automatic. Put it in writing. Tell everyone who touches payments that there are zero exceptions. Not for the "CEO," not for urgent requests, not for long-time vendors. The moment you allow one exception, you've told the criminals exactly which door to knock on.
This is what Peace of Mind actually looks like: not a magic gadget, but a simple habit your whole team follows without thinking.
Want to Know If Your Team Would Fall for It?
Most owners are confident their people would catch a fake email, right up until we test it. We run friendly phishing simulations for businesses across the Lehigh Valley and beyond: no shaming, no gotchas, just a clear picture of where you're exposed and quick training to close the gaps.
It starts with a 20-minute conversation. Book a time that works for you here. And in the meantime, go tell your bookkeeper about the Call-Back Rule. Today.
Big U Computers, LLC. Personal Service, Peace of Mind, No Geek-Speak, and We Won't Hold You Hostage. That's the promise.



