We’ve recently renewed our Cyber Essentials Certification.
We’re pleased to have it because it shows we’re continuing to follow recognised best practice when it comes to protecting our own systems and data, both for our businesses benefit and our customers. But if there’s one thing we’ve learnt over the years, it’s that good cybersecurity isn’t just about firewalls and software.
Many of the biggest financial losses start with an email.
The problem is that these emails are becoming harder to spot. They look more professional, they’re often based on genuine businesses, and they’re designed to catch people who are busy rather than careless.
Here are three frauds we’re seeing regularly, along with the warning signs that can save your business from making an expensive mistake.
1. Domain name renewal invoices that aren’t genuine
Your company website is an important business assets and you will be used to receiving renewal requests, so receiving an invoice reminding you that your domain name needs renewing doesn’t usually raise alarm bells.
That’s exactly what fraudsters rely on.
These emails often arrive looking remarkably convincing. They feature professional branding, invoice numbers, expiry dates and language that sounds similar to genuine domain registrars. They also create urgency by suggesting your website could disappear if payment isn’t made immediately.
The catch? The sender didn’t register your domain in the first place, and in many cases your domain isn’t even due for renewal.
Before paying anything, check:
- Is this the company you originally bought your domain from?
- Is your domain actually due for renewal?
- Does the invoice match previous renewal notices you’ve received?
- Have you logged into your registrar’s account to confirm the renewal date?
If you’re unsure, don’t pay first and ask questions later. Spend five minutes checking with whoever manages your website or IT. It could save hundreds of pounds and prevent your payment details ending up with criminals.
2. Cloned supplier invoices
This is one of the most convincing scams we come across.
A fraudster gets hold of a genuine supplier invoice, copies the layout, logos and branding, and sends what appears to be another perfectly legitimate invoice.
At first glance, everything looks normal. But there are usually small clues that something isn’t quite right.
Look out for:
- Invoice numbers that suddenly jump much higher than you’re used to seeing.
- Emails sent from free accounts such as Gmail rather than the supplier’s normal company domain.
- A change in the usual billing pattern. Perhaps you normally receive one invoice each month and suddenly there are two.
- Requests to change payment to a different bank account, standing order or direct debit.
- Monthly charges that have increased without explanation.
None of these signs automatically mean fraud, but they should always trigger a conversation before any money leaves your account.
The safest rule is also the simplest.
Never change supplier payment details based solely on an email or invoice.
Instead, telephone the supplier using a number you already know or one published on their official website. Never use the phone number printed on the suspicious invoice, as that may also belong to the fraudster.
A two-minute phone call is much cheaper than trying to recover money after it’s gone.
3. “CEO fraud” — urgent payment requests from your boss
Imagine someone in your finance team receives an email that appears to come from you.
It says you’re tied up in meetings, a payment needs making immediately, it’s confidential, and you’ll explain everything later.
It sounds plausible because that’s exactly how these scams are designed.
Criminals impersonate directors, managing directors or finance leaders using spoofed or lookalike email addresses. Sometimes they’ll replace a single letter in the email address. Sometimes they’ll simply display the correct name while hiding a different sending address underneath.
The message usually contains three ingredients:
- Urgency — “This needs paying within the next hour.”
- Authority — “I’m authorising this personally.”
- Secrecy — “Please don’t discuss this with anyone yet.”
Those three pressures are designed to stop someone following normal procedures.
Encourage your team to look for:
- Email addresses that aren’t quite right.
- Requests that fall outside your normal approval process.
- An unusual writing style or tone.
- Unexpected requests for large payments or gift cards.
Most importantly, create a culture where employees know it’s acceptable to pause.
Nobody should ever feel awkward about picking up the phone, walking to someone’s office or sending an email to verify an unusual request, even if it appears to come from the Managing Director.
In fact, directors should actively encourage it.
The best businesses don’t rely on trust alone. They rely on good processes that protect everyone.
Good cybersecurity is built into everyday habits
Renewing our Cyber Essentials Certification is one way we demonstrate our commitment to keeping our own systems secure, but technology is only part of the picture.
The right processes, regular staff awareness and a healthy level of scepticism are often what prevent these scams from succeeding.
If you’d like to see some of the practical steps we take ourselves, have a read of our earlier article, “What can you do to strengthen your cybersecurity?”, which covers straightforward measures every business can adopt to improve its security without making life more complicated. What can you do to strengthen your cybersecurity?
If you’re a business owner, there are two actions you can take today:
Introduce a simple verification policy for any change to supplier payment details or unexpected payment request.
Make sure everyone in your business knows that it’s always acceptable to stop, question and verify before money changes hands.
While scams like these often rely on human error, the right systems and processes can make them much harder to pull off. At Evergreen, we work with businesses to remove inefficiencies, improve visibility and build bespoke software that supports safer, smarter ways of working. Whether that’s creating approval workflows for supplier payments, giving finance teams better oversight, integrating business systems or replacing manual processes that leave room for costly mistakes, our software is designed around the way your business actually operates.
With more than 25 years’ experience, over 400 businesses helped and a technical team that takes the time to understand your organisation before writing a single line of code, we’re a trusted partner for companies looking to improve efficiency, reduce risk and achieve a genuine return on their software investment. If your current systems are no longer fit for purpose, we’d be delighted to have an informal conversation about how bespoke software could help your business.