lab5280
JournalCybersecurityInvoice fraud

The fake-invoice email: how business email compromise hits Denver businesses

No virus, no ransom note. Just an ordinary-looking email asking you to pay the usual bill to a new account.

Lab 5280 — Denver, CO
The short version

Business email compromise is a scam where someone poses as a vendor, your boss or a client and gets you to send money to their account. The FBI logged $3.05 billion in reported losses to it in 2025. One habit stops most of it: never change payment details on the strength of an email. Call a number you already had.

Business email compromise in Denver looks nothing like the hacking you see in films. Nothing gets locked, nothing flashes red. A bookkeeper at a contractor in Englewood, a title office in Cherry Creek or a clinic in Lakewood gets a polite email from a supplier they've paid for years: "We've changed banks. Please use the new account details on the attached invoice." The invoice looks right. The payment goes out. Two weeks later the real supplier calls asking where their money is.

That's the whole scam. Because it relies on a person doing their job rather than on malicious software, a good antivirus program won't catch it. A few simple office rules will.

How big the problem is

The FBI's Internet Crime Complaint Center (IC3) collects fraud reports nationwide. Its 2025 annual report, released in April 2026, recorded $3,046,598,558 in losses from business email compromise, from 24,768 complaints. Among the fraud types the report tracks, only investment scams cost more. Total reported cybercrime losses for the year were $20.877 billion.

Those are only the cases people reported. One law firm's summary of the report also notes more than $30 million in business email compromise losses with a confirmed link to AI, so a clumsy, misspelled message is no longer a reliable giveaway.

How business email compromise works

IC3 defines it as "a sophisticated scam targeting both businesses and individuals performing a transfer of funds." It usually arrives in one of a few forms:

The email comes either from a lookalike address (one letter off, or a different ending) or from a real mailbox the criminal has already broken into. The second kind is the dangerous one, because the address is genuine and the criminal has read the earlier conversation.

Warning signs worth teaching everyone

Five controls that stop most of it

  1. A call-back rule. Any new or changed payment details get confirmed by phone, using a number you already have on file, never one from the email. IC3's advice is to verify account changes through a second channel. Write the rule down and make it apply to the owner too.
  2. Two people on large payments. One person sets up a payment, another approves it. Pick a dollar amount that fits your business, and ask your bank whether its online banking can require a second approver.
  3. Multi-factor authentication on every mailbox. That's the code or phone prompt on top of a password. It makes it far harder for a criminal to get into your own email and write to your customers as you.
  4. Email authentication for your domain. The FTC recommends using an email provider that supports it, so receiving servers can confirm a message really came from your company. The settings are known as SPF, DKIM and DMARC, and whoever manages your email can turn them on.
  5. Short, regular training and a daily glance at the bank account. The FTC's line is that security is only as strong as your least vigilant employee. IC3 adds: monitor financial accounts regularly for anything irregular.

None of this needs expensive software. If you're choosing an IT provider, ask how they'd set up items 3 and 4 for you. If you're automating invoices and reminders, keep a person approving anything that changes where money goes.

If the money has already gone: the first hour

Speed matters more than anything else here. IC3's steps:

  1. Call your bank immediately. Ask for a recall or reversal of the payment, and for a Hold Harmless Letter or Letter of Indemnity. Use the bank's fraud line, not a general inbox.
  2. File a complaint at ic3.gov. Include every detail it asks for, especially the banking information for the transfer.
  3. Save everything. The emails, the invoice, the payment confirmation. Don't delete the message out of embarrassment.
  4. Check your own mailboxes. Change passwords, and have someone look for forwarding rules you didn't create. A break-in can leave behind a hidden rule that copies your mail to the criminal.
  5. Tell the real vendor or client. If their mailbox was the one compromised, their other customers are next.

If it's your business being impersonated, the FTC advises reporting it to law enforcement, IC3 and the FTC, and telling your customers promptly that you will never ask for bank details by email.

Common questions

What is business email compromise?

The FBI's Internet Crime Complaint Center describes it as a sophisticated scam targeting businesses and individuals performing a transfer of funds. In practice, someone poses as a vendor, your boss or a client by email and gets you to send a payment to an account they control.

What should I do first if my business paid a fake invoice?

Call your bank immediately and ask for a recall or reversal of the payment. Then file a detailed complaint at ic3.gov, including the banking information for the transfer.

Does multi-factor authentication stop business email compromise?

It helps keep criminals out of your own mailboxes, but it can't stop a convincing email sent from someone else's account or a lookalike address. Pair it with a rule that bank-detail changes are confirmed by phone.

Make it a habit, not a project

The call-back rule costs nothing and takes two minutes each time. The rest is a few settings and a short conversation with your team. At Lab 5280 we work with your team, not just for you, and our focus is on automating how the business runs, which includes building the approval steps into your payment process so the safe way is also the easy way.

Want your payment process checked?

Walk us through how a vendor invoice gets paid at your business today, and we'll show you where a fake one could slip through.

Talk to Lab 5280